- UK GDPR, Article 27
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations 2003
Who has to appoint one
Any controller or processor not established in the United Kingdom that offers goods or services to people in the UK or monitors their behaviour there. Since Brexit this includes companies established in the European Union, which is the point most EU businesses miss: an EU establishment does not cover the UK, and a UK establishment does not cover the EU.
Thresholds and exemptions
The exemption mirrors the EU one and is equally narrow: occasional processing, no large-scale special-category or criminal-offence data, and unlikely to result in a risk. Regular analytics on UK visitors does not qualify. Public authorities are exempt.
What must appear on the label
The representative's identity and contact details must be given to data subjects in the privacy notice, in the same way as under the EU GDPR, and must be readily accessible to the Information Commissioner's Office.
Marketplace fields
UK-facing marketplaces and enterprise buyers ask for the UK representative in due diligence. It is also the first thing the ICO looks for when handling a complaint about a company with no UK establishment.
Documentation you must hold
The written designation. The record of processing activities relating to UK processing, which the representative must maintain and make available to the ICO. Transfer documentation, which since Brexit means the UK International Data Transfer Agreement or the UK Addendum to the EU standard clauses, not the EU clauses alone.
Standards and testing
Not applicable. What is assessed is documentation and the ability to answer the ICO and data subjects.
Language requirements
English.
When it applies
Before the processing that triggers UK jurisdiction begins. Appointing after a complaint does not cure the earlier period.
How long records are kept
The designation and the UK processing records for the duration of the representation plus evidence of the period covered.
What happens if you do not comply
Up to £17.5 million or 4% of global turnover under the UK regime. The ICO has been less aggressive than several EU authorities on the representative requirement specifically, but it treats the absence as an aggravating factor when investigating anything else.
Who enforces it
The Information Commissioner's Office.
Where the boundary lies
Two separate appointments are needed to cover both territories, and one provider can hold both but must be designated separately for each. The UK also diverges in detail: the transfer paperwork differs, the cookie rules are enforced by the ICO under PECR, and the UK has its own age-appropriate design code for services likely to be accessed by children.
Questions we are asked
- We are an EU company — do we need a UK representative?
- If you target UK users or monitor their behaviour and have no UK establishment, yes. Brexit made the UK a third country for this purpose, in both directions.
- Can the EU representative also act for the UK?
- The same provider can, but the designation must be made separately under the UK GDPR and the representative must be established in the United Kingdom.
Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom