gdprrepresentative
Home · UK representative · India

Article 27 UK GDPR · India

UK representative for Indian companies

Indian companies meet this requirement through contracts more often than through regulators. A British client sends a data processing agreement, and somewhere in it is a clause naming the UK representative. The clause is not boilerplate: Article 27 of the UK GDPR applies to processors as well as controllers, which is what makes it relevant to the entire services sector.

Processors are caught too, and that is the sector

It is widely assumed that Article 27 is a controller obligation. It is not: a processor established outside the United Kingdom that processes the personal data of people in Britain is subject to the same requirement. For an Indian IT services firm, BPO or engineering supplier working for British clients, that is the whole business model, and the designation is the thing the client's auditor will ask to see.

TWO ROLES, ONE REQUIREMENTIndian company as controllerArticle 27 appliesIndian company as processorArticle 27 appliesClient’s representativecovers the client only
A request desk operating in British hours for an Indian services supplier
Processors are caught by Article 27 in the same terms as controllers.
A client audit checking that a named representative is established in Britain
What the auditor verifies is the code, not the letterhead.

The DPDP Act runs alongside, not instead

India's Digital Personal Data Protection Act governs processing in India and creates its own duties. It does not discharge a British requirement, and compliance with it is not visible to the ICO. The two regimes coexist: one is your domestic obligation, the other is the price of holding data about people in Britain.

Transfers from the UK still need a mechanism

The United Kingdom has not made an adequacy finding for India. Personal data flowing from a British client to an Indian supplier generally moves under the IDTA or the addendum, agreed as part of the same contract that names the representative. Companies that put the designation in place at the same time as the transfer paperwork avoid renegotiating both later.

What the auditor actually verifies

A British client's auditor does not read your designation letter closely. They check that a representative is named, that the entity is established in the United Kingdom, and that the code resolves. Ours names REP27 LTD, company number 17385889, in Suffolk, and the code carries the UK27 prefix and resolves publicly while they are looking at it.

The clause your client will send you

It usually appears in the data processing agreement, near the transfer clauses, and asks you to name your representative in the United Kingdom and to keep the appointment current for the term. Signing it without a designation in place creates a contractual obligation you cannot evidence. The designation closes it the same day, and the code is what the client's auditor checks at renewal.

Controller or processor, the same requirement

Indian company as controllerIts own customers in BritainArticle 27 applies
Indian company as processorData of a British client’s customersArticle 27 applies
The client’s own representativeCovers the clientDoes not cover you
DPDP ActIndiaSeparate domestic obligation
Transfers UK → IndiaNo adequacy findingIDTA or addendum required

Audit season, and what fails it

The failures we see repeat. A designation that names an Indian entity, which is not established in Britain. A letter with no verifiable code, which the auditor cannot check. And an appointment that lapsed quietly at renewal, which is worse than never having had one because the contract already promised it. A public register answers all three, because it shows the state of the mandate at the moment somebody looks.

Questions from Indian companies

We are a processor, not a controller. Does Article 27 apply?

Yes. The UK GDPR applies the requirement to processors outside the United Kingdom on the same terms as controllers.

Does the DPDP Act cover this?

No. It governs processing in India. The British requirement is separate and enforced by the ICO.

Our client says their own representative covers us.

It covers them. A processor caught by Article 27 needs its own designation, and auditors increasingly check for exactly that.

How fast can we produce evidence for a client audit?

The designation is issued the same working day, and the verification code is live from that moment.

Appointed today, verifiable today

One annual fee, no charge per request. From €290 a year for the United Kingdom, €390 for the United Kingdom and the Union together.

How the UK service works Pricing
Signing the designation an Indian supplier will show at its next client audit
The auditor checks that the entity is British and that the code resolves.
Compliance review of a processor working for clients in the United Kingdom
The client’s own representative covers the client, never the supplier.

Companies elsewhere, same obligation

What changes from one country to the next is not the rule but the route into it.

Selling into Britain from Australia

The same rule, a different starting point.

Selling into Britain from Switzerland

The same rule, a different starting point.

How the UK service works

The guide that matters most here.