---
title: "UK Representative Service | UK GDPR Article 27"
url: "https://www.engagecompliance.co/uk-representative-service"
type: "service"
date: "2026-07-23"
---

# UK Representative Service

Companies outside the United Kingdom that target or monitor people in the UK need a UK representative under UK GDPR Article 27. It is a separate appointment from the EU one, and having an EU representative does not cover it.

**The short answer: if your company has no establishment in the UK, and you offer goods or services to people in the UK or monitor their behavior there, UK GDPR Article 27 requires you to appoint a representative established in the UK, mandated in writing and named in your privacy notice.** The exemption is the same narrow one the EU regulation carries, and most companies reaching for it do not qualify.

Engage Compliance provides the UK representative role for companies outside the United Kingdom, with a written mandate, a published UK contact point, and the record of processing held and available to the Information Commissioner's Office on request.

## Key takeaways

- UK GDPR Article 27 is a separate obligation from EU GDPR Article 27. Meeting one does not meet the other.
- It applies to controllers and processors with no UK establishment that target or monitor people in the UK.
- The representative must be established in the UK, mandated in writing, and published in your privacy notice.
- The exemption requires occasional processing, no large-scale special category data, no criminal offense data, and low risk, all at once.
- The regulator is the Information Commissioner's Office, and non-appointment sits in the standard maximum penalty tier.
- Engage Compliance takes the UK appointment and the EU one as separate mandates, because clearing Article 27 in one regime does nothing for the other. The UK appointment is €550 a year at the smallest band, and the two together are €1,103, because the second mandate on an order is charged at 75 percent of its own price.

## What a UK representative is

Article 27 of the UK GDPR requires a controller or processor that is not established in the United Kingdom, but is caught by Article 3(2), to designate in writing a representative in the UK.

The representative is mandated to be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects on all issues relating to processing. In practice that means three things: the representative is named and contactable in your privacy notice, the representative holds a copy of your record of processing and makes it available to the ICO on request, and the representative receives correspondence from people in the UK exercising their rights and routes it to you.

The role does not transfer liability. Recital 80 of the retained regulation is clear that the representative acts on behalf of the controller or processor and can be subject to enforcement proceedings in the event of non-compliance, while the controller or processor remains responsible for the processing itself.

## Who needs one

Three conditions, and all three have to hold.

**No UK establishment.** Establishment is functional rather than formal. A UK sales office that signs UK customers is an establishment involved in the processing. A UK company registration with no activity behind it is not, and it will not carry the obligation for you.

**Targeting or monitoring people in the UK.** Offering goods or services to people in the UK, whether or not payment is required, or monitoring their behavior where that behavior takes place in the UK. Pricing in pounds, a .uk domain, UK shipping options, UK-targeted advertising, or a UK country selector all point at targeting. Analytics, advertising pixels, fraud scoring, and session recording on UK traffic all count as monitoring.

**No exemption.** Article 27(2) exempts processing that is occasional, does not include large-scale special category data, does not include criminal offense data, and is unlikely to result in a risk to people's rights and freedoms. Processing that is part of how your product works is not occasional, whatever the volume.

Two groups are caught more often than they expect. EU companies selling into the UK, which were covered by their EU position before the transition period ended and have not revisited it since. And US companies that appointed an EU representative in 2018, treated the UK as covered by it, and never made the second appointment after 2021.

## What we do

- **Appointment in writing**, with a mandate that meets the Article 27 requirement rather than a letterhead.
- **A published UK contact point**, in a form you can paste into your privacy notice under Articles 13 and 14.
- **Record of processing held and produced.** We hold your Article 30 record and make it available to the ICO on request, which is the representative's own obligation under Article 30(1).
- **Handling of contacts from people in the UK**, routed to your named internal owner with the statutory clock flagged.
- **Handling of ICO correspondence**, with the substance passed to you within one business day.
- **Annual review**, because the appointment stops being accurate the moment your processing footprint changes.

Where a company needs a named DPO as well, the [DPO for UK companies](/dpo-for-uk-companies) service covers the Article 37 role, and we offer both as separate products and scope them together.

## How it works

None of this is complicated, and it is the sort of task that stalls for months because nobody owns it rather than because it is hard.

1. **Scope.** A short review of where your users are, what you process, and whether you have a UK establishment. If you do, we tell you the appointment is unnecessary and stop there.
2. **Mandate.** The written appointment is signed. This is the step Article 27 actually requires, and an informal arrangement does not satisfy it.
3. **Publication.** You add the representative's identity and contact details to your privacy notice. We supply the wording.
4. **Record.** We take a copy of your record of processing, or build one where it does not exist yet.
5. **Live.** Contacts and ICO correspondence route through the representative from that point.

## What it costs

The appointment is €550 a year at the smallest band, for a company with 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold, charged once, up front, with no setup fee. Whichever of headcount, revenue or the number of people whose data you hold puts you highest sets the band.

| Company size | UK Representative |
| --- | --- |
| 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold | €550 |
| 11 to 50 people, or €2m to €10m revenue, or 5,000 or more people in the EU and UK whose data you hold | €790 |
| 51 to 250 people, or €10m to €50m revenue | €1,830 |
| 251 or more people, or over €50m revenue | From €3,590 |

The smallest band is for very small organizations only: 1 to 10 people, under €2m in global annual revenue, and under 5,000 people in the EU and UK whose personal data you hold. All three must be true. If any one of them is not, the next band up applies.

Commercial pricing bands based on familiar market-size and market-pricing thresholds. They are not a statutory size test.

Every appointment you hold is a separate mandate, and only the highest-priced one in the basket is charged in full. Every other appointment is charged at a share of its own price, and for this one that share is three quarters of its own price. So adding this to an appointment you already hold costs €413 at band 0, €593 at band 1, €1,373 at band 2, €2,693 at band 3, rather than a second full price.

Two extras are optional, and each is charged once per order rather than once per appointment. Higher-risk processing, which covers special category data and criminal offense data, is €250 at band 0, €500 at band 1, €750 at band 2, €1,000 at band 3. Same-business-day response is a service level on authority and data subject correspondence rather than substantive advice, and is €1,200 a year.

Every band is published and buyable, so you can [see your price and appoint online](/representative-services/start) without talking to anyone first. The full table for every mandate is on [representative services](/representative-services).

The appointment issues in seconds. After payment you answer a short form about your company and who we should send correspondence to, about three minutes of typing, and the appointment document, the certificate, the public verification link and the wording you need all issue automatically at that moment. Nobody at Engage has to approve anything.

## Why Engage Compliance

Experience across 100+ startups and enterprises including Amazon, Coinbase, and Robinhood. The same privacy expert stays on your account, so the person who scoped the appointment is the person who handles the first ICO letter.

Where you need both the representative and a DPO, we offer both as separate products and scope them together.

Every engagement carries professional indemnity and cyber insurance. For companies whose obligations run wider than the UK and the EU, [global privacy compliance](/global-privacy-compliance) covers the whole footprint under one point of contact.

## Sources and references

- [UK GDPR, Article 27](https://www.legislation.gov.uk/eur/2016/679/contents), legislation.gov.uk
- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents), legislation.gov.uk

## Frequently asked questions

### What is a UK GDPR representative?

It is a person or company established in the United Kingdom, appointed in writing by a controller or processor outside the UK, to be the point of contact for the Information Commissioner's Office and for people in the UK whose data is processed. The role comes from Article 27 of the UK GDPR, which is the retained and amended version of the EU regulation brought into UK law after the transition period.

### Does an EU representative cover the UK?

No. The UK left the EU regime, so UK GDPR and EU GDPR are now two separate laws with two separate Article 27 requirements. A company targeting both markets and established in neither needs an appointment in each. If your company is established in the UK and sells into the EU, that is the reverse case, covered on [EU Representative for UK companies](/eu-representative-for-uk-companies). Some providers offer both, though they are two mandates and two published contact points, not one.

### Do we need a UK representative if we already have a UK subsidiary?

If the subsidiary is an establishment involved in the processing, UK GDPR applies to you directly and the representative requirement drops away, in the same way Article 3(1) works under EU GDPR. A dormant entity that plays no part in the processing does not remove the obligation.

### Does an EU company need a UK representative?

Yes, where it offers goods or services to people in the UK or monitors their behavior there and has no UK establishment. This catches a large number of EU companies that were compliant before Brexit and did nothing afterwards, because before the transition ended the UK was covered by their EU position.

### What can the ICO do if we have not appointed one?

Failure to appoint is an infringement of UK GDPR Article 27, which sits in the standard maximum tier under section 157 of the Data Protection Act 2018: up to £8.7 million or 2 percent of worldwide annual turnover, whichever is higher. The ICO's practice on this has been to raise it during a wider inquiry rather than to sweep for it.

### What has to appear in our privacy notice?

The identity and contact details of the UK representative, alongside your own, under Articles 13 and 14 of the UK GDPR. A representative appointed but never published does not do the job, because the entire point of the role is that a person in the UK can find someone to contact.

### Can the same provider act as our UK representative and our DPO?

The representative and the outsourced DPO are two separate products. If you need both, tell us and we will scope them together.
