GDPR / Article 27 Representation
GDPR Representative services for the EU, UK or both
Organisations outside the EU or UK may need a local Representative when they offer goods or services to people in the relevant territory or monitor their behaviour there. We assess the requirement, document the decision and put the correct appointment and contact process in place.
A Representative is a local contact point. It does not replace your organisation’s accountability or automatically act as your DPO.
Choose the correct coverage
EU Representative
Use this route when: Your organisation is outside the EU/EEA, has no relevant EU establishment and Article 3(2) processing brings EU GDPR into scope.
Legal structure: Written appointment to an EU-established Representative.
Explore →UK Representative
Use this route when: Your organisation is outside the UK, has no relevant UK establishment and UK-targeting or monitoring brings UK GDPR into scope.
Legal structure: Written appointment to a UK-established Representative.
Explore →EU + UK
Use this route when: Your organisation is outside both territories and independently meets the trigger for each market.
Legal structure: Two separate legal appointments coordinated through one operating process.
Explore →Assessment only
Use this route when: The territorial test, exemption or establishment position is unclear.
Legal structure: Documented recommendation and decision record before appointment.
Explore →The requirement in plain English
The representative requirement is linked to territorial scope. It is relevant where a controller or processor is not established in the relevant territory but the law applies because of activities directed at people there or because their behaviour is monitored there.
The exemption is narrow and should be documented rather than assumed. For the EU, the occasional-processing exemption requires a cumulative assessment of frequency, sensitive or criminal-offence data at scale, and the risk posed to people. Public authorities and bodies are separately excluded. The UK regime has an analogous representative requirement and exemptions, but the UK analysis should be completed separately.
What a GDPR Representative does
- Provides the required local point of contact for individuals and the relevant supervisory authority.
- Operates under a written mandate from the controller or processor.
- Receives and routes correspondence relating to the processing covered by the appointment.
- Supports the availability of Article 30 records where the law requires the controller, processor or representative to provide them.
- Maintains an agreed escalation and evidence process so requests are not lost between jurisdictions.
- Cooperates with the relevant supervisory authority when required in connection with the appointed role.
Role boundary
The Representative is not the controller, does not take over the controller or processor’s legal responsibility, and is not automatically the organisation’s DPO or general GDPR consultant.
What is included in the service
- Territorial-scope and exemption assessment.
- Confirmation of the appropriate EU country and/or UK arrangement.
- Written appointment documentation and operating instructions.
- Representative contact details and approved wording for privacy notices and other disclosures.
- Correspondence intake, triage, logging and escalation routes.
- Initial review of the records and contacts needed to operate the mandate.
- Periodic confirmation of markets, processing and contact information.
- Clear boundaries for matters outside the Representative mandate and optional wider support.
Representative, DPO or wider GDPR support?
These services can sit alongside each other, but the roles should not be blurred. A Representative addresses the local-contact requirement for certain non-established organisations. A DPO independently informs, advises and monitors where the statutory trigger applies or the role is voluntarily designated. Wider GDPR support helps implement and operate the underlying compliance programme.
| Question | Representative | DPO | GDPR project support |
|---|---|---|---|
| Why is it appointed? | Territorial-scope requirement for certain non-established organisations. | Statutory trigger or voluntary governance decision. | Defined implementation, remediation or operational need. |
| Main function | Local regulatory and data-subject contact under mandate. | Independent advice, monitoring and regulator contact. | Deliver agreed work and evidence. |
| Takes over management accountability? | No. | No. | No. |
| Can the roles overlap? | Only after careful scope and conflict review. | Only if independence and conflicts are protected. | Project support should not be misrepresented as statutory oversight. |
For a practical role comparison, read DPO vs GDPR Representative.
How appointment works
Assess scope
Confirm establishments, markets, offering/monitoring activities, processing frequency, data categories and risk.
Select coverage
Determine EU, UK, both, or a documented no-appointment decision.
Confirm the legal contact
Select the appropriate EU establishment and/or UK-established Representative arrangement.
Execute the mandate
Approve the written appointment, scope, communications process and responsibilities.
Update transparency information
Add the applicable Representative details to privacy information and relevant records.
Go live and review
Test the contact route, confirm escalation owners and review when markets or processing change.
Start with a documented answer
The assessment is designed to show how the result was reached. It is not a disguised contact form. You can complete the questions, receive a provisional result and decide whether you need a formal review or appointment proposal.
Frequently asked questions
Does every company outside the EU or UK need a Representative?
No. The requirement depends on whether the relevant law applies through the organisation's offering or monitoring activities, whether there is a relevant establishment, and whether an exemption applies. The EU and UK assessments must be completed separately.
Can one Representative appointment cover the EU and UK?
No. The EU and UK are separate regimes. A coordinated service can use one intake and reporting process, but it requires separate legal appointments and contact points.
Is a Representative the same as a DPO?
No. A Representative is a local contact for certain non-established organisations. A DPO has independent advisory and monitoring tasks. Some organisations may need both roles.
Does appointment make the Representative responsible for our compliance?
No. Appointment does not transfer the controller or processor's accountability. The organisation must still comply with the applicable requirements and provide the information and cooperation needed to operate the mandate.
What information is needed for the assessment?
We need the legal entities and establishments, markets served, indicators of targeting, monitoring activities, processing frequency, categories of personal data, approximate scale and any existing EU or UK offices or agents.
When should the requirement be reviewed?
Review it before entering a new market, launching materially different monitoring or profiling, changing group structure, opening or closing an establishment, or materially changing the scale or sensitivity of processing.
