Companies outside the United Kingdom that target or monitor people in the UK need a UK representative under UK GDPR Article 27. It is a separate appointment from the EU one, and having an EU representative does not cover it.

The short answer: if your company has no establishment in the UK, and you offer goods or services to people in the UK or monitor their behavior there, UK GDPR Article 27 requires you to appoint a representative established in the UK, mandated in writing and named in your privacy notice. The exemption is the same narrow one the EU regulation carries, and most companies reaching for it do not qualify.

Engage Compliance provides the UK representative role for companies outside the United Kingdom, with a written mandate, a published UK contact point, and the record of processing held and available to the Information Commissioner’s Office on request.

Key takeaways

  • UK GDPR Article 27 is a separate obligation from EU GDPR Article 27. Meeting one does not meet the other.
  • It applies to controllers and processors with no UK establishment that target or monitor people in the UK.
  • The representative must be established in the UK, mandated in writing, and published in your privacy notice.
  • The exemption requires occasional processing, no large-scale special category data, no criminal offense data, and low risk, all at once.
  • The regulator is the Information Commissioner’s Office, and non-appointment sits in the standard maximum penalty tier.
  • Engage Compliance takes the UK appointment and the EU one as separate mandates, because clearing Article 27 in one regime does nothing for the other.

What a UK representative is

Article 27 of the UK GDPR requires a controller or processor that is not established in the United Kingdom, but is caught by Article 3(2), to designate in writing a representative in the UK.

The representative is mandated to be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on all issues relating to processing. In practice that means three things: the representative is named and contactable in your privacy notice, the representative holds a copy of your record of processing and makes it available to the ICO on request, and the representative receives correspondence from people in the UK exercising their rights and routes it to you.

The role does not transfer liability. Recital 80 of the retained regulation is clear that the representative acts on behalf of the controller or processor and can be subject to enforcement proceedings in the event of non-compliance, while the controller or processor remains responsible for the processing itself.

Who needs one

Three conditions, and all three have to hold.

No UK establishment. Establishment is functional rather than formal. A UK sales office that signs UK customers is an establishment involved in the processing. A UK company registration with no activity behind it is not, and it will not carry the obligation for you.

Targeting or monitoring people in the UK. Offering goods or services to people in the UK, whether or not payment is required, or monitoring their behavior where that behavior takes place in the UK. Pricing in pounds, a .uk domain, UK shipping options, UK-targeted advertising, or a UK country selector all point at targeting. Analytics, advertising pixels, fraud scoring, and session recording on UK traffic all count as monitoring.

No exemption. Article 27(2) exempts processing that is occasional, does not include large-scale special category data, does not include criminal offense data, and is unlikely to result in a risk to people’s rights and freedoms. Processing that is part of how your product works is not occasional, whatever the volume.

Two groups are caught more often than they expect. EU companies selling into the UK, which were covered by their EU position before the transition period ended and have not revisited it since. And US companies that appointed an EU representative in 2018, treated the UK as covered by it, and never made the second appointment after 2021.

What we do

  • Appointment in writing, with a mandate that meets the Article 27 requirement rather than a letterhead.
  • A published UK contact point, in a form you can paste into your privacy notice under Articles 13 and 14.
  • Record of processing held and produced. We hold your Article 30 record and make it available to the ICO on request, which is the representative’s own obligation under Article 30(1).
  • Handling of contacts from people in the UK, routed to your named internal owner with the statutory clock flagged.
  • Handling of ICO correspondence, with the substance passed to you and a recommended response.
  • Annual review, because the appointment stops being accurate the moment your processing footprint changes.

Where a company needs a named DPO as well, the DPO for UK companies service covers the Article 37 role and we keep the two mandates with separate entities.

How it works

Appointment is quick, and it is the sort of task that stalls for months because nobody owns it rather than because it is hard.

  1. Scope. A short review of where your users are, what you process, and whether you have a UK establishment. If you do, we tell you the appointment is unnecessary and stop there.
  2. Mandate. The written appointment is signed. This is the step Article 27 actually requires, and an informal arrangement does not satisfy it.
  3. Publication. You add the representative’s identity and contact details to your privacy notice. We supply the wording.
  4. Record. We take a copy of your record of processing, or build one where it does not exist yet.
  5. Live. Contacts and ICO correspondence route through the representative from that point.

Most appointments complete inside a week once the scoping questions are answered.

What it costs

The UK representative appointment is priced on the same basis as the Article 27 EU representative service, From €59 per month, scaling with company size. Companies needing both the UK and the EU appointment take two mandates, and the second is priced as an addition rather than at full rate.

Where the appointment sits inside a wider program, the outsourced DPO cost guide sets out how the DPO tiers are priced separately from it.

Why Engage Compliance

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same senior privacy expert stays on your account, so the person who scoped the appointment is the person who handles the first ICO letter.

We keep the representative and DPO roles independent, on the European Data Protection Board’s own reasoning about the conflict between them, rather than bundling both because it is easier to sell. Where you need both, one comes from us and the other from a partner entity, and we say which is which in writing.

Every engagement carries professional indemnity and cyber insurance. For companies whose obligations run wider than the UK and the EU, global privacy compliance covers the whole footprint under one point of contact.

Sources and references

  • Same-business-day response
  • Professional indemnity and cyber insurance
  • Named DPO notified to the supervisory authority

FAQ

Frequently asked questions

What is a UK GDPR representative?

It is a person or company established in the United Kingdom, appointed in writing by a controller or processor outside the UK, to be the point of contact for the Information Commissioner's Office and for people in the UK whose data is processed. The role comes from Article 27 of the UK GDPR, which is the retained and amended version of the EU regulation brought into UK law after the transition period.

Does an EU representative cover the UK?

No. The UK left the EU regime, so UK GDPR and EU GDPR are now two separate laws with two separate Article 27 requirements. A company targeting both markets and established in neither needs an appointment in each. Some providers offer both, though they are two mandates and two published contact points, not one.

Do we need a UK representative if we already have a UK subsidiary?

If the subsidiary is an establishment involved in the processing, UK GDPR applies to you directly and the representative requirement drops away, in the same way Article 3(1) works under EU GDPR. A dormant entity that plays no part in the processing does not remove the obligation.

Does an EU company need a UK representative?

Yes, where it offers goods or services to people in the UK or monitors their behavior there and has no UK establishment. This catches a large number of EU companies that were compliant before Brexit and did nothing afterwards, because before the transition ended the UK was covered by their EU position.

What can the ICO do if we have not appointed one?

Failure to appoint is an infringement of UK GDPR Article 27, which sits in the standard maximum tier under section 157 of the Data Protection Act 2018: up to £8.7 million or 2 percent of worldwide annual turnover, whichever is higher. The ICO's practice on this has been to raise it during a wider inquiry rather than to sweep for it.

What has to appear in our privacy notice?

The identity and contact details of the UK representative, alongside your own, under Articles 13 and 14 of the UK GDPR. A representative appointed but never published does not do the job, because the entire point of the role is that a person in the UK can find someone to contact.

Can the same provider act as our UK representative and our DPO?

We keep the two apart. The representative can be addressed by the regulator on behalf of the company, and the DPO's job is to monitor that same company's compliance, so one organization holding both creates a conflict the European Data Protection Board has warned against. Where we act as DPO we arrange the representative through a partner entity.