Article 27 UK GDPR · Singapore
UK representative for Singapore companies
Singapore companies are usually well organised about data protection and still miss this, because the gap is structural rather than careless. A regional headquarters is built to serve Asia-Pacific, the British business arrives through a client relationship rather than a consumer market, and nobody asks who represents the company in the United Kingdom until a contract does.
The PDPA and the UK GDPR overlap without substituting
Singapore's Personal Data Protection Act imposes consent, purpose and protection obligations enforced by the PDPC. It contains nothing equivalent to Article 27, and no filing under it is visible to the ICO. A Singapore company serving people in Britain is subject to both regimes at once, each enforced by its own authority.
Regional headquarters, global clients, no British entity
The common structure is a Singapore parent serving clients across several continents from one place. It works well operationally and leaves a specific hole: British clients and their data are handled by an entity established nowhere near Britain. Article 27 is the rule that notices this, and increasingly so does the client's legal team.
Processors are caught, which matters here
Much of Singapore's services trade with Britain is processing rather than controlling — payments, analytics, engineering, support. Article 27 of the UK GDPR applies to processors outside the United Kingdom on the same terms as controllers, so the obligation does not disappear when you are acting on a client's instructions.
What a British client verifies before signing
The data processing agreement asks for the representative by name and address. The reviewer checks that the entity is established in the United Kingdom and that the appointment can be verified. Ours resolves on a public register with a UK27 code, showing the mandate live or expired at the moment of the check.
Where the structural gap sits
A regional headquarters is designed around time zones and client coverage, not around territorial data protection rules. British clients are served from Singapore because that is where the team is, and the question of who represents the company in Britain never arises internally. It arises externally, in the data processing agreement, and by then it is a contractual commitment rather than a planning decision.
Controller or processor, the same answer
| Singapore company as controller | Its own users in Britain | Article 27 applies |
| Singapore company as processor | A British client’s data | Article 27 applies |
| PDPA | Singapore | Separate domestic obligation |
| Transfers UK → Singapore | No adequacy finding | IDTA or addendum required |
| Client’s own representative | Covers the client | Does not cover you |
What renewal season looks for
Contracts with British clients are reviewed annually, and the representative clause is one of the few that can be verified in seconds. A lapsed designation is worse than an absent one, because the contract already promised it would be maintained. A code that resolves as live at the moment of the check answers the question without correspondence.
Questions from Singaporean companies
We comply with the PDPA. Is that enough for Britain?
No. The PDPA governs your obligations in Singapore. The UK GDPR imposes its own requirement on companies outside the United Kingdom.
We are a processor for a UK client. Does Article 27 apply?
Yes. It applies to processors established outside the United Kingdom in the same terms as controllers.
Is Singapore covered by a UK adequacy decision?
No. Transfers from the UK generally need the IDTA or the addendum to the standard clauses.
Our client says they will name us in their own designation.
That designation covers them. A processor caught by Article 27 needs its own, and reviewers increasingly check for it.
Appointed today, verifiable today
One annual fee, no charge per request. From €290 a year for the United Kingdom, €390 for the United Kingdom and the Union together.
How the UK service works PricingCompanies elsewhere, same obligation
What changes from one country to the next is not the rule but the route into it.
Selling into Britain from India
The same rule, a different starting point.
Selling into Britain from Japan
The same rule, a different starting point.
What the ICO expects
The guide that matters most here.