Outside the UK
No relevant UK establishment.
UK GDPR REPRESENTATIVE
Article 27 representation for controllers and processors outside the United Kingdom whose processing falls within the territorial scope of the UK GDPR.
Our UK Representative service provides a UK-based regulatory and data-subject interface, formal Article 27 appointment, representative contact infrastructure, Article 30 record arrangements and ongoing coordination within a specialist privacy and technology-regulation practice.
UK GDPR Representative services are provided by PRIVACY MINDERS (UK) LIMITED, company no. 13248616, established in the United Kingdom.
Not sure whether Article 3(2) and Article 27 apply to your organisation? Start with the scope assessment.
ARTICLE 27 DECISION ARCHITECTURE
IF NO Assess the relevant processing
Article 27 representative requirement does not arise on the basis of absence of UK establishment.
Offering goods or services to people in the UK
ORMonitoring their behaviour in the UK?
IF YES Assess the exemption
No Article 27 representative trigger on this basis.
Public authority or body
ORNarrow processing exemption
All required: occasional processing; no large-scale special-category or criminal-offence processing; unlikely to result in a risk to individuals' rights and freedoms.IF NO EXEMPTION
No Article 27 representative requirement.
The appointment must be made in writing.
Not sure whether Article 3(2) applies?
Request a UK territorial-scope assessmentARTICLE 3 + ARTICLE 27
Being located outside the UK does not by itself trigger Article 27. The relevant question is whether Article 3(2) applies to the organisation's processing.
Where Article 3(2) applies, Article 27 generally requires a written UK representative unless the statutory exemption applies.
No relevant UK establishment.
Processing relates to offering goods or services to people in the UK, whether or not payment is required.
Processing relates to monitoring behaviour taking place in the UK.
WHO IS CAUGHT?
Organisations determining the purposes and means of relevant processing.
Organisations processing personal data on behalf of controllers where their own relevant processing falls within Article 3(2).
The representative assessment should therefore be carried out at entity level and in light of the organisation's actual role and UK-facing processing.
UK TARGETING
An overseas website or service does not automatically fall within Article 3(2) merely because it can be accessed from the UK.
The assessment considers whether there is evidence that the organisation intends to offer the relevant goods or services to people in the UK.
The analysis depends on the organisation's actual circumstances.
UK MONITORING
Article 3(2) can apply where a non-UK organisation monitors the behaviour of people in the UK where that behaviour takes place in the UK.
Illustrative examples may include, depending on the circumstances:
The presence of analytics or cookies does not by itself determine the Article 3(2) analysis. The actual processing purpose and circumstances matter.
TERRITORIAL SCOPE
Article 3(2) refers to data subjects who are in the United Kingdom. The test is not limited to British citizens or UK nationals.
Whether the UK GDPR applies depends on the relevant processing activity and territorial connection.
THE EXEMPTION
Processing is occasional.
All three conditions must be satisfied, taking into account the nature, context, scope and purposes of the processing. There is no general company-size exemption in Article 27.
PUBLIC AUTHORITIES / BODIES
Article 27(2)(b) contains a separate exemption.
Unsure whether the Article 27 exemption applies?
Review your UK representative positionARTICLE 27
The representative is formally mandated so that the Information Commissioner and data subjects can address it, in addition to or instead of the controller or processor, on issues related to processing for the purposes of UK GDPR compliance.
Effective representation therefore requires a functioning UK contact point, defined escalation arrangements and access to the represented organisation's privacy and compliance teams.
UK REGULATORY INTERFACE
UK GDPR REPRESENTATIVE
REPRESENTED ORGANISATION
The representative provides the UK interface. The represented organisation remains responsible for its underlying processing and compliance decisions.
UK SERVICE ENTITY
PRIVACY MINDERS (UK) LIMITED is established in the United Kingdom and provides the UK-based representative for the Article 27 mandate.
UK GDPR Representative services are provided by:
This legal entity is distinct from OSTRAI Limited.
YOUR REPRESENTATION SERVICE
Written appointment of PRIVACY MINDERS (UK) LIMITED as UK GDPR Representative within the agreed mandate.
A monitored electronic channel for communications relating to the representative mandate.
A defined contact for the representative relationship and material escalations.
Receipt and coordination of communications addressed to the representative by the Information Commissioner.
Receipt and coordination of communications from individuals addressed to the organisation through its UK representative.
Support for correctly identifying and publishing the representative's contact details within relevant privacy information.
Maintenance of the representative's required Article 30 records based on current information supplied by the represented organisation, where applicable.
Cooperation with the Information Commissioner within the role required by the UK GDPR.
Defined routes for urgent, material or time-sensitive matters.
Review of material changes affecting territorial scope, establishment, processing and the representative mandate.
Need to appoint a UK GDPR Representative?
Discuss the mandateCOMMUNICATIONS IN PRACTICE
The representative facilitates the communication channel. The controller or processor remains responsible for substantive rights decisions and compliance obligations applicable to it.
ARTICLE 30
Article 30 places record-keeping obligations on controllers and processors and, where applicable, their representatives.
The representative's record arrangement depends on accurate and up-to-date information supplied by the represented organisation. Required records must be made available to the Information Commissioner on request.
The content of the record differs depending on whether the represented organisation acts as controller or processor.
Full data mapping, RoPA remediation and wider privacy implementation can be separately scoped.
Need to prepare your representative records?
Discuss representation readinessPUBLIC CONTACT DETAILS
The ICO advises organisations to give people in the UK the representative's details, for example through their privacy information, and to make those details easily accessible to the Information Commissioner.
As part of onboarding, we can support the practical update of relevant privacy information.
RESPONSIBILITY
Article 27(5) preserves legal action against the controller or processor despite appointment of a representative.
The representative role does not replace the organisation's underlying UK GDPR responsibilities.
Lawfulness · Transparency · Rights decisions · Security · Processor / controller obligations · Data governance
UK contact interface · ICO communications · Data-subject communications · Article 30 representative records · Cooperation
DIFFERENT ROLES
Required in relevant Article 3(2) / Article 27 circumstances for organisations outside the UK.
Provides a UK regulatory and data-subject interface. Can be addressed on matters related to processing. Maintains representative records where applicable.
Governance and oversight function under the UK GDPR where the DPO requirements apply.
Advises and monitors compliance. Has specific independence and organisational-position requirements.
An organisation may require both roles. Neither role automatically substitutes for the other.
TWO REGIMES
UNITED KINGDOM
EUROPEAN UNION
An organisation subject to both regimes without the relevant establishments may require separate UK and EU representative appointments. One appointment does not satisfy both regimes.
Need representation in both the UK and EU?
Discuss your structure with OSTRAICONTROLLED ACCEPTANCE
Before accepting a UK GDPR Representative mandate, we review the organisation, legal entity, controller or processor role, UK territorial scope, processing activity, relevant data categories, regulatory history, rights-handling arrangements and operational readiness.
Where Article 3(2), Article 27 or wider UK GDPR issues require substantive legal assessment, that work can be scoped separately before appointment.
The organisation's regulatory position and readiness determine whether the mandate can proceed.
Discuss whether we can accept the mandateONBOARDING
OPERATIONAL READINESS
Effective representation depends on prompt access to accurate information, instructions and responsible internal contacts when an individual or the ICO contacts the representative.
SCOPE
UK PRIVACY REGULATION
The UK GDPR Representative service sits within a broader privacy and technology-regulation practice.
Where necessary, separately scoped work can address territorial scope, transparency, controller and processor obligations, individual rights, international transfers, privacy governance and regulatory response.
This means communications reaching the UK representative can be understood in their wider regulatory context.
UK ESTABLISHMENT
The representative appointment is provided by a UK-incorporated legal entity.
The mandate is structured around the statutory representative role.
A defined UK channel for supervisory-authority communications.
A UK contact route for people whose personal data falls within the represented processing.
Article 30 record arrangements form part of the representative infrastructure where applicable.
Ability to identify UK / EU and wider privacy-regulation intersections.
QUESTIONS & ANSWERS
A controller or processor without a relevant UK establishment generally needs a UK representative where its relevant processing falls within Article 3(2): offering goods or services to people in the UK, whether or not payment is required, or monitoring their behaviour where it takes place in the UK. Article 27 requires a written appointment unless an Article 27(2) exemption applies.
No. Being outside the UK is not enough. The organisation's processing must fall within the relevant territorial scope of Article 3(2), and the Article 27 exemption must be considered. This applies to organisations in the EU, the United States and elsewhere on the same statutory basis.
Yes, potentially. Article 27 expressly covers both controllers and processors. A processor, including a SaaS or other service provider, needs an assessment of its own relevant processing and territorial position. Its customer's location alone does not settle that assessment.
No. UK customers may be relevant evidence, but the assessment concerns intentional offering or monitoring and the organisation's actual processing under Article 3(2). The establishment position and any Article 27 exemption must also be considered.
Not by itself. Mere accessibility does not establish intentional UK targeting. UK-facing marketing, a UK-specific offering and other evidence of intended goods or services provision may be relevant. Monitoring activity requires its own assessment.
All three processing conditions must be satisfied: the processing is occasional; it does not include large-scale processing of special-category or criminal-conviction and offence data; and it is unlikely to result in a risk to individuals' rights and freedoms, taking account of its nature, context, scope and purposes. Public authorities or bodies have a separate exemption under Article 27(2)(b). There is no general company-size exemption.
The representative is appointed in writing and can be addressed by the Information Commissioner and data subjects in addition to or instead of the controller or processor on processing-related compliance issues. Its role includes the UK contact interface, escalation, Article 30 representative records where applicable and Article 31 cooperation. Substantive privacy implementation is separately scoped.
No. Article 27(5) preserves legal action against the controller or processor itself. The represented organisation remains responsible for its underlying processing and compliance decisions. The representative does not replace the controller or processor.
No. A representative provides the statutory UK interface under Articles 3 and 27. A DPO performs a governance, advice and monitoring role where required under Article 37 or voluntarily appointed, with specific independence requirements. Neither appointment automatically satisfies the other role.
Potentially, where both territorial regimes apply and the organisation lacks the relevant establishments. A UK appointment does not satisfy EU Article 27, and an EU appointment does not satisfy UK Article 27. UK GDPR Representative services are provided by PRIVACY MINDERS (UK) LIMITED; EU GDPR Representative services are provided by OSTRAI Limited. The mandates remain separate.
Still unsure whether Article 27 applies?
Discuss your positionUK GDPR REPRESENTATIVE
We support eligible controllers and processors outside the United Kingdom from Article 3 and Article 27 scope assessment through appointment, UK contact infrastructure, ICO and data-subject communications, representative records and ongoing mandate coordination.
UK GDPR Representative services are provided by PRIVACY MINDERS (UK) LIMITED, company no. 13248616.