gdprrepresentative
Home · UK representative · Ireland

Article 27 UK GDPR · Ireland

UK representative for Irish companies

No two markets are more entangled than Ireland and Britain, which is precisely why this obligation is missed here more than anywhere. Companies that sell across the border every day, in the same language and often in both currencies, assume the arrangement is domestic. For data protection it is not: Britain is a third country, and an Irish company selling to people there needs a representative established there.

The Common Travel Area does not reach data protection

Free movement of people, the right to work, reciprocal social welfare — none of it touches the UK GDPR. The Common Travel Area is an immigration and social security arrangement that predates both regulations and was carefully preserved after the referendum. It says nothing about who receives a subject access request in Britain, and the ICO has never treated it as though it did.

WHERE THE BORDER FALLS FOR DATA PROTECTIONCompany in Dublinestablished in the UnionCustomer in CorkEU GDPR · no representativeCustomer in BelfastUK GDPR · representative required
A desk in Britain receiving requests from customers of an Irish company
Requests from Belfast reach the British representative, not the Dublin office.
The British market an Irish exporter reaches without leaving the same language
The closest market is the one where the gap is noticed last.

Northern Ireland is the United Kingdom for this purpose

Selling to Belfast is selling into the United Kingdom. The protocol arrangements govern goods, customs and standards; they do not create a data protection regime of their own. An Irish company with customers in Derry and customers in Donegal is dealing with two regimes at once, and only one of them is answered by its Dublin establishment.

The DPC supervises you, the ICO does not

Your relationship with the Data Protection Commission is genuine and it covers the Union. The Information Commissioner's Office is a separate authority with its own enforcement powers, and it looks for a representative with a British address. The two regulators cooperate closely, which is often what misleads people: cooperation is not substitution.

Shared language, faster complaints

Because there is no language barrier, British customers of Irish companies exercise their rights more readily than the average. Requests arrive worded confidently and land at whatever address the privacy notice gives. If that address is in Dublin, the request is still valid, the clock still runs, and the absence of a British contact point is the thing that ends up in the complaint.

What goes in an Irish privacy notice

One paragraph, added to the section that identifies the controller, naming an entity established in the United Kingdom. Your existing text stays as it is: established in Ireland you are inside the Union and need no European representative. What is new is the British line, and it has to carry a British address rather than a Dublin one.

Two islands, two regimes

Republic of IrelandEU GDPRNo representative needed — you are established here
Northern IrelandUK GDPRRepresentative in Britain required
Great BritainUK GDPRRepresentative in Britain required
Your regulator at homeData Protection CommissionCovers the Union only
Regulator across the waterInformation Commissioner’s OfficeLooks for a UK address

The cross-border retailer

The clearest case is a retailer with a single website, one warehouse and customers on both sides of the border. Nothing in the operation distinguishes an order from Dundalk from an order from Newry, which is exactly why the obligation is invisible until a request arrives from the northern side. The designation costs less than a single hour spent arguing about whether it was needed.

Questions from Irish companies

We trade with Britain daily. Is that not enough of a presence?

Presence in trade is not establishment for data protection. What counts is a fixed establishment in the United Kingdom, which most Irish exporters do not have.

Does Northern Ireland count as the EU for this?

No. For data protection Northern Ireland is part of the United Kingdom and the UK GDPR applies there.

Our parent company is British. Does that cover us?

It can, if the British entity accepts the mandate in writing and is named in your notice. A group relationship alone does not create a designation.

How quickly is it issued?

The same working day once the form is complete, with a verification code that resolves immediately.

Appointed today, verifiable today

One annual fee, no charge per request. From €290 a year for the United Kingdom, €390 for the United Kingdom and the Union together.

How the UK service works Pricing
The regulator building where a complaint from across the border eventually lands
The Data Protection Commission covers the Union. Belfast is not in it.
A request desk handling correspondence that crossed a border nobody noticed
Same language, same currency in places, two separate regimes.

Companies elsewhere, same obligation

What changes from one country to the next is not the rule but the route into it.

Selling into Britain from the United States

The same rule, a different starting point.

Selling into Britain from Poland

The same rule, a different starting point.

Why one duty became two

The guide that matters most here.