Appoint us
EU representative under Article 27 GDPR for companies established in the United Kingdom

REP27 · EU representative · United Kingdom

Article 27 GDPR · United Kingdom

EU representative for United Kingdom companies, signed in 24 hours.

If your company is established in the United Kingdom and you offer goods or services to people in the European Union — or you monitor their behaviour — Article 27 of the GDPR requires you to designate, in writing, a representative inside the Union. We are that representative: named in your privacy notice, reachable by all 27 supervisory authorities, and verifiable by anyone holding the code on your certificate.

€290Base — designation, certificate, live badge, 10 requests a year
€490Standard — unlimited requests, Article 30 records held, desk in 8 languages
€890Multi — Article 27 + GPSR responsible person + CE authorised representative

Get appointed in 24 hours   Check your privacy notice free

Why UK companies fall under Article 27

Since Brexit the UK is a third country under the GDPR. If you reach people in the EU you need an EU representative — and separately, companies outside the UK reaching British users need a UK representative under the UK GDPR. The two roles are independent and one never covers the other.

Article 27(5)The designation does not shield you. Actions can still be brought against your company directly. Anyone selling a representative as protection is selling something the regulation does not contain.

Who typically needs it here

London fintech, agencies with EU clients, D2C brands selling into Ireland, France and Germany, and SaaS spun out of the UK market.

Any recurring European revenue

One sale might be occasional. A product that European customers can buy today, tomorrow and next month is not, and Article 27(2)(a) does not apply.

A European user base you did not plan for

Many files start with a product built for a home market that quietly acquired European users. Intent is not the test; the presence of the users is.

Being in someone else's supply chain

European controllers are audited on their processors. That is why the designation appears in questionnaires before it appears in enforcement.

Your regulator at home, and why it does not help here

The ICO enforces the UK GDPR and the Data Protection Act 2018 inside the United Kingdom. Since 1 January 2021 it has no authority over EU matters, and no EU authority answers to it.

Who supervises you locally

the Information Commissioner's Office. None of them can receive a request under Article 27(4) on your behalf, and none of them appears in your privacy notice for European purposes.

How EU customers reach you

British companies usually reach the Union through Irish and Dutch customers, through EU subsidiaries that were kept after Brexit, and through marketplaces that ship into the single market. Many discover the duty when a German customer asks for the representative's details.

What actually changes

One designation, published in your notice, verifiable by anyone with the code. Requests logged and forwarded within two business days, with the GDPR deadline already counted for you.

What you receive

Everything a regulator asks for

The designation letter, the records under Article 30(4), the log of every request received and when it was forwarded. Assembled as you go, not reconstructed under pressure.

A certificate that expires honestly

Valid until a date, verifiable by code, and it stops showing as active the day it lapses. That is what makes the status worth something.

One contract, three roles if you need them

Article 27 alone, or with the GPSR responsible person and the CE authorised representative on the Multi plan. One renewal date for all of it.

Questions from UK companies

We already have a UK representative. Does that cover the EU?

No, and the confusion is common. A UK representative exists under Article 27 of the UK GDPR and answers to the ICO. An EU representative exists under Article 27 of the EU GDPR and answers to the 27 supervisory authorities. Two regimes, two designations.

We have an Irish subsidiary. Do we still need a designation?

If the Irish entity is the one that contracts with EU customers and decides the processing, the group is established in the Union and Article 27 does not apply to that activity. If the UK entity is the contracting party, the duty attaches to it.

Which EU country should we be designated in?

Article 27(3) points to a member state where your data subjects are. We designate in Czechia and cover all 27 through a single desk, which is what supervisory authorities in practice address.

How fast can we be covered?

The designation letter and certificate are issued within 24 working hours of the form and payment, after a person reviews the file. Higher-risk sectors take up to five business days.

What does it cost, and what happens at renewal?

From €290 a year, billed annually in advance and renewing automatically until you cancel before the renewal date. No fee per request from the Standard plan up.

Are you our data protection officer?

No. Under EDPB guidance one entity cannot be both. We are the contact point under Article 27(4): we receive, log and forward, hold your Article 30 records, and never answer on the merits or give legal advice.

Two regimes since Brexit: what a UK company actually needs

Since 1 January 2021 the United Kingdom has been a third country for EU GDPR purposes. Domestically it applies the UK GDPR alongside the Data Protection Act 2018, supervised by the Information Commissioner's Office, and the Data (Use and Access) Act has since introduced further divergence from the EU text.

The UK holds an adequacy decision from the European Commission, extended in 2025. As with Japan, adequacy solves transfers and not contactability. A UK company that offers goods or services to people in the EU, or monitors their behaviour, needs a representative established in a Member State under Article 27 of the EU GDPR. Adequacy does not remove that duty, and the ICO has no role in it.

The mirror obligation runs the other way too. Article 27 of the UK GDPR requires companies outside the UK that target UK individuals to appoint a UK representative. A single business selling into both markets therefore needs two designations, one in the Union and one in Britain, and they cannot be combined into a single appointment.

This catches more UK businesses than expected. An online retailer shipping to Ireland, a consultancy with clients in Germany, a publisher whose newsletter has French subscribers, an agency running campaigns aimed at European audiences: all are within Article 3(2). The volume of data does not matter, and there is no minimum threshold. What matters is whether the offering is directed at people in the Union, which is judged on evidence such as language options, currency, shipping destinations and paid advertising targeting.

Cover your EU customers from United Kingdom

Brexit turned a domestic obligation into two. The companies that handled it early are the ones whose European clients stopped asking.

Free check first: we read your public privacy notice and tell you in ten seconds whether a representative is named. If one is, we say so and you close the tab.

Run the free check

See also