Companies outside the United Kingdom that target or monitor people in the UK need a UK representative under UK GDPR Article 27. It is a separate appointment from the EU one, and having an EU representative does not cover it.
The short answer: if your company has no establishment in the UK, and you offer goods or services to people in the UK or monitor their behavior there, UK GDPR Article 27 requires you to appoint a representative established in the UK, mandated in writing and named in your privacy notice. The exemption is the same narrow one the EU regulation carries, and most companies reaching for it do not qualify.
Engage Compliance provides the UK representative role for companies outside the United Kingdom, with a written mandate, a published UK contact point, and the record of processing held and available to the Information Commissioner’s Office on request.
Key takeaways
- UK GDPR Article 27 is a separate obligation from EU GDPR Article 27. Meeting one does not meet the other.
- It applies to controllers and processors with no UK establishment that target or monitor people in the UK.
- The representative must be established in the UK, mandated in writing, and published in your privacy notice.
- The exemption requires occasional processing, no large-scale special category data, no criminal offense data, and low risk, all at once.
- The regulator is the Information Commissioner’s Office, and non-appointment sits in the standard maximum penalty tier.
- Engage Compliance takes the UK appointment and the EU one as separate mandates, because clearing Article 27 in one regime does nothing for the other.
What a UK representative is
Article 27 of the UK GDPR requires a controller or processor that is not established in the United Kingdom, but is caught by Article 3(2), to designate in writing a representative in the UK.
The representative is mandated to be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on all issues relating to processing. In practice that means three things: the representative is named and contactable in your privacy notice, the representative holds a copy of your record of processing and makes it available to the ICO on request, and the representative receives correspondence from people in the UK exercising their rights and routes it to you.
The role does not transfer liability. Recital 80 of the retained regulation is clear that the representative acts on behalf of the controller or processor and can be subject to enforcement proceedings in the event of non-compliance, while the controller or processor remains responsible for the processing itself.
Who needs one
Three conditions, and all three have to hold.
No UK establishment. Establishment is functional rather than formal. A UK sales office that signs UK customers is an establishment involved in the processing. A UK company registration with no activity behind it is not, and it will not carry the obligation for you.
Targeting or monitoring people in the UK. Offering goods or services to people in the UK, whether or not payment is required, or monitoring their behavior where that behavior takes place in the UK. Pricing in pounds, a .uk domain, UK shipping options, UK-targeted advertising, or a UK country selector all point at targeting. Analytics, advertising pixels, fraud scoring, and session recording on UK traffic all count as monitoring.
No exemption. Article 27(2) exempts processing that is occasional, does not include large-scale special category data, does not include criminal offense data, and is unlikely to result in a risk to people’s rights and freedoms. Processing that is part of how your product works is not occasional, whatever the volume.
Two groups are caught more often than they expect. EU companies selling into the UK, which were covered by their EU position before the transition period ended and have not revisited it since. And US companies that appointed an EU representative in 2018, treated the UK as covered by it, and never made the second appointment after 2021.
What we do
- Appointment in writing, with a mandate that meets the Article 27 requirement rather than a letterhead.
- A published UK contact point, in a form you can paste into your privacy notice under Articles 13 and 14.
- Record of processing held and produced. We hold your Article 30 record and make it available to the ICO on request, which is the representative’s own obligation under Article 30(1).
- Handling of contacts from people in the UK, routed to your named internal owner with the statutory clock flagged.
- Handling of ICO correspondence, with the substance passed to you and a recommended response.
- Annual review, because the appointment stops being accurate the moment your processing footprint changes.
Where a company needs a named DPO as well, the DPO for UK companies service covers the Article 37 role and we keep the two mandates with separate entities.
How it works
Appointment is quick, and it is the sort of task that stalls for months because nobody owns it rather than because it is hard.
- Scope. A short review of where your users are, what you process, and whether you have a UK establishment. If you do, we tell you the appointment is unnecessary and stop there.
- Mandate. The written appointment is signed. This is the step Article 27 actually requires, and an informal arrangement does not satisfy it.
- Publication. You add the representative’s identity and contact details to your privacy notice. We supply the wording.
- Record. We take a copy of your record of processing, or build one where it does not exist yet.
- Live. Contacts and ICO correspondence route through the representative from that point.
Most appointments complete inside a week once the scoping questions are answered.
What it costs
The UK representative appointment is priced on the same basis as the Article 27 EU representative service, From €59 per month, scaling with company size. Companies needing both the UK and the EU appointment take two mandates, and the second is priced as an addition rather than at full rate.
Where the appointment sits inside a wider program, the outsourced DPO cost guide sets out how the DPO tiers are priced separately from it.
Why Engage Compliance
Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same senior privacy expert stays on your account, so the person who scoped the appointment is the person who handles the first ICO letter.
We keep the representative and DPO roles independent, on the European Data Protection Board’s own reasoning about the conflict between them, rather than bundling both because it is easier to sell. Where you need both, one comes from us and the other from a partner entity, and we say which is which in writing.
Every engagement carries professional indemnity and cyber insurance. For companies whose obligations run wider than the UK and the EU, global privacy compliance covers the whole footprint under one point of contact.
Sources and references
- UK GDPR, Article 27, legislation.gov.uk
- Data Protection Act 2018, legislation.gov.uk