UK GDPR · Data Protection Act 2018

UK Representative under the UK GDPR (Article 27)

If your business is not established in the UK but offers goods or services to people in the UK, or monitors their behaviour, the UK GDPR and the Data Protection Act 2018 require you to appoint a UK representative. DataShield acts as that representative: a named, UK-based point of contact for the ICO and for individuals whose data you process. We mirror the role created by Article 27 of the GDPR, transposed into UK law after Brexit, so that US and Canadian companies can serve UK users with a compliant local presence and a clear line of accountability.

🛡 Overseen by a Data Protection Officer designated with the CNIL

What a UK representative is

A UK representative is a person or organisation established in the UK that you designate, in writing, to act on your behalf for UK GDPR purposes. The role exists because the UK retained its own version of the GDPR after Brexit, the UK GDPR, sitting alongside the Data Protection Act 2018 and enforced by the ICO.

The representative does not take over your responsibilities as controller or processor. Instead, it provides a local, accessible interface so that the ICO and UK individuals can raise questions and exercise their rights without contacting an overseas office. Key points:

  • It must be physically established in the UK.
  • It is mandated in writing under Article 27, as adapted by UK law.
  • It is named in your privacy notice so people can find it easily.

Who needs one (and why you may need both an EU and a UK representative)

You need a UK representative if your organisation has no establishment in the UK and your processing targets UK residents by either offering goods or services to them, or monitoring their behaviour, such as analytics, tracking or profiling. This commonly applies to US and Canadian SaaS, e-commerce and app businesses with UK users.

Critically, the UK and the EU are now separate regimes. A UK representative does not satisfy the equivalent EU obligation, and an EU representative does not cover the UK. If you target individuals in both the UK and the EEA, you generally need both:

  • An EU representative established in an EU member state.
  • A separate UK representative established in the UK.

Narrow exemptions exist for occasional, low-risk processing and for public authorities.

What DataShield does as your UK representative

We take on the operational role so your team does not have to staff it. As your appointed UK representative, DataShield:

  • Serves as the local contact point in the UK for the ICO and for data subjects, named in your privacy notice.
  • Routes and triages requests, including data-subject rights requests and ICO correspondence, to the right people at your organisation, with clear timelines.
  • Keeps the record of processing activities we are required to make available, and supports your wider documentation.
  • Provides a UK postal and electronic address that individuals and the regulator can use.

Our service is overseen by a CNIL-designated DPO, giving you experienced privacy governance across both UK and EU mandates from a single provider.

FAQ

UK Representative under the UK GDPR (Article 27)

Does appointing a UK representative make DataShield responsible for my compliance?

No. You remain the controller or processor and stay legally responsible for your compliance under the UK GDPR. The UK representative is your designated local contact and acts on your instructions; it is not liable for your processing decisions. Our role is to make you reachable in the UK by the ICO and by individuals, to maintain the required records, and to route requests promptly so you can respond on time.

We already have an EU representative. Do we still need a UK one?

Most likely yes. Since Brexit, the UK GDPR is a separate regime from the EU GDPR, enforced by the ICO rather than EU supervisory authorities. An EU representative covers the EEA only and does not satisfy the UK requirement. If you offer goods or services to, or monitor, people in the UK and have no UK establishment, you need a UK representative in addition to your EU one. DataShield can provide both.

Which US and Canadian businesses typically need a UK representative?

Any organisation established outside the UK that processes UK residents' personal data in connection with offering them goods or services, or monitoring their behaviour. In practice this covers SaaS platforms, online stores, mobile apps, marketing and analytics businesses, and subscription services with UK customers or website visitors who are tracked or profiled. Narrow exemptions apply to occasional, low-risk processing and to public authorities, so it is worth confirming your specific situation with us.

Work with a real DPO

Appoint an EU representative backed by genuine, verifiable expertise.

Get my quote →