CHAPTER IV . Section 1
UK GDPR Article 27: Representatives of controllers or processors not established in the United Kingdom
1. Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the United Kingdom.
2. The obligation laid down in paragraph 1 of this Article shall not apply to:
(a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
(b) a public authority or body.
3. Omitted.
4. The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, the Commissioner and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.
5. The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.
What this article means in practice
Written by Engage Compliance. The text above is the article itself, reproduced from its official source and unchanged. Everything in this section is ours, and last read against the current text on 2026-09-07.
UK GDPR Article 27 is the United Kingdom's own representative requirement, and it works the way the EU one does: if the UK GDPR reaches you under Article 3(2) and you have no UK establishment, you designate a representative in the United Kingdom in writing. A company serving both the EU and the UK from outside both needs two appointments, not one.
Who it binds
- Controllers and processors with no establishment in the United Kingdom whose processing falls under Article 3(2), meaning they offer goods or services to people in the UK or monitor their behavior.
- It does not bind a public authority or body (Article 27(2)(b)).
- It does not bind you where the processing is occasional, does not include large-scale processing of special category data or criminal conviction data, and is unlikely to result in a risk to rights and freedoms (Article 27(2)(a)). All three limbs have to hold together.
- An EU establishment does not satisfy it. After the UK left the EU these are two separate territorial regimes, and an EU representative is not a UK one.
What it makes somebody do
- You, the controller or processor. Designate the representative in writing (Article 27(1)).
- You, the controller or processor. Place them in the United Kingdom (Article 27(3)), which is the whole territory rather than a choice among several as it is in the EU.
- You, the controller or processor. Mandate them to be addressed in addition to or instead of you by the supervisory authority and by data subjects, on all issues related to processing (Article 27(4)).
- The representative. Maintain a record of processing activities under Article 30(1), which is the representative's own obligation.
- The representative. Make that record available to the supervisory authority on request (Article 30(4)).
What it does not say
- It does not stop anything being brought against you. Article 27(5) says the designation is without prejudice to legal actions that could be initiated against the controller or processor themselves.
- It does not make the representative your Data Protection Officer. Article 37 is a separate appointment with a different test and different tasks.
- It is not satisfied by a UK postal address. Article 27(4) requires a mandate to be addressed on all issues related to processing, which is a party that answers.
- The Article 27(2) exemption is not a size test. It turns on occasional processing, special category data and risk, so a small company monitoring behavior regularly is caught.
- One appointment does not cover both regimes. The EU and UK versions of Article 27 are separate obligations owed to separate supervisory authorities.
How it sits beside the other mandates
- The EU and the UK have each said different things in public about whether an Article 27 representative can be pursued for the controller's own breaches. A company holding both appointments is holding them under two regulators that do not agree on that point, which is a reason to read each appointment's terms rather than to assume they mirror.
- Article 30 is what makes this appointment operational. The record is yours to write and keep current; the representative holds one and is who the supervisory authority can ask.
- A company caught by both regimes runs two records, two published contact points and two appointments, and the two are commonly confused in privacy notices, which is where an authority looks first.
Source text: legislation.gov.uk, the UK statute book (EU-retained Regulation 2016/679). The parser was validated against the UK Article 27 verified in REP-08.