UK GDPR REPRESENTATIVE

UK GDPR Representative
for Organisations Outside the UK

Article 27 representation for controllers and processors outside the United Kingdom whose processing falls within the territorial scope of the UK GDPR.

Our UK Representative service provides a UK-based regulatory and data-subject interface, formal Article 27 appointment, representative contact infrastructure, Article 30 record arrangements and ongoing coordination within a specialist privacy and technology-regulation practice.

UK GDPR Representative services are provided by PRIVACY MINDERS (UK) LIMITED, company no. 13248616, established in the United Kingdom.

Not sure whether Article 3(2) and Article 27 apply to your organisation? Start with the scope assessment.

ARTICLE 27 DECISION ARCHITECTURE

From territorial scope
to a written appointment.

  1. Is the controller or processor established in the UK?

    IF NO Assess the relevant processing

    IF YES

    Article 27 representative requirement does not arise on the basis of absence of UK establishment.

  2. Does the relevant processing relate to:

    Offering goods or services to people in the UK

    OR

    Monitoring their behaviour in the UK?

    IF YES Assess the exemption

    IF NO

    No Article 27 representative trigger on this basis.

  3. Does an Article 27(2) exemption apply?

    Public authority or body

    OR

    Narrow processing exemption

    All required: occasional processing; no large-scale special-category or criminal-offence processing; unlikely to result in a risk to individuals' rights and freedoms.

    IF NO EXEMPTION

    IF EXEMPTION APPLIES

    No Article 27 representative requirement.

UK GDPR Representative required

The appointment must be made in writing.

Not sure whether Article 3(2) applies?

Request a UK territorial-scope assessment

ARTICLE 3 + ARTICLE 27

Territorial scope comes
before appointment.

Being located outside the UK does not by itself trigger Article 27. The relevant question is whether Article 3(2) applies to the organisation's processing.

Where Article 3(2) applies, Article 27 generally requires a written UK representative unless the statutory exemption applies.

Outside the UK

No relevant UK establishment.

AND

UK targeting

Processing relates to offering goods or services to people in the UK, whether or not payment is required.

OR

UK monitoring

Processing relates to monitoring behaviour taking place in the UK.

Request a UK Article 27 scope assessment

WHO IS CAUGHT?

Article 27 can apply to
controllers and processors.

Controllers

Organisations determining the purposes and means of relevant processing.

Processors

Organisations processing personal data on behalf of controllers where their own relevant processing falls within Article 3(2).

The representative assessment should therefore be carried out at entity level and in light of the organisation's actual role and UK-facing processing.

UK TARGETING

Accessibility alone
is not the test.

An overseas website or service does not automatically fall within Article 3(2) merely because it can be accessed from the UK.

The assessment considers whether there is evidence that the organisation intends to offer the relevant goods or services to people in the UK.

  • UK-facing marketing
  • UK-specific offering
  • UK customer acquisition
  • UK-focused commercial activity
  • Other evidence of intentional targeting

The analysis depends on the organisation's actual circumstances.

UK MONITORING

Article 3(2) also reaches
certain monitoring activity.

Article 3(2) can apply where a non-UK organisation monitors the behaviour of people in the UK where that behaviour takes place in the UK.

Illustrative examples may include, depending on the circumstances:

  • Behavioural tracking
  • Profiling
  • Behavioural advertising
  • Location or activity monitoring
  • Systematic online observation

The presence of analytics or cookies does not by itself determine the Article 3(2) analysis. The actual processing purpose and circumstances matter.

TERRITORIAL SCOPE

Presence, not nationality.

Article 3(2) refers to data subjects who are in the United Kingdom. The test is not limited to British citizens or UK nationals.

Whether the UK GDPR applies depends on the relevant processing activity and territorial connection.

THE EXEMPTION

The occasional-processing
exemption is cumulative.

Occasional

Processing is occasional.

AND

No large-scale special-category or criminal-offence data

AND

Unlikely to result in a risk to rights and freedoms

All three conditions must be satisfied, taking into account the nature, context, scope and purposes of the processing. There is no general company-size exemption in Article 27.

PUBLIC AUTHORITIES / BODIES
Article 27(2)(b) contains a separate exemption.

Unsure whether the Article 27 exemption applies?

Review your UK representative position

ARTICLE 27

A UK representative
is more than an address.

The representative is formally mandated so that the Information Commissioner and data subjects can address it, in addition to or instead of the controller or processor, on issues related to processing for the purposes of UK GDPR compliance.

Effective representation therefore requires a functioning UK contact point, defined escalation arrangements and access to the represented organisation's privacy and compliance teams.

UK REGULATORY INTERFACE

A local interface.
A connected organisation.

Information
Commissioner

People
in the UK

UK GDPR REPRESENTATIVE

PRIVACY MINDERS
(UK) LIMITED

  • UK regulatory contact
  • ICO communications
  • Data-subject contact
  • Article 30 records
  • Escalation
  • Mandate coordination
↔

REPRESENTED ORGANISATION

Controller /
processor

  • Substantive compliance
  • Rights decisions
  • Lawful basis
  • Security
  • Privacy governance
  • Instructions and evidence

The representative provides the UK interface. The represented organisation remains responsible for its underlying processing and compliance decisions.

UK SERVICE ENTITY

Representation through
a UK-established company.

PRIVACY MINDERS (UK) LIMITED is established in the United Kingdom and provides the UK-based representative for the Article 27 mandate.

UK GDPR Representative services are provided by:

PRIVACY MINDERS (UK) LIMITED

Company number
13248616
Legal form
UK private limited company
Registered office
1 Kings Avenue
London, United Kingdom
N21 3NA

This legal entity is distinct from OSTRAI Limited.

YOUR REPRESENTATION SERVICE

A functioning Article 27
UK representation structure.

Formal Article 27 appointment

Written appointment of PRIVACY MINDERS (UK) LIMITED as UK GDPR Representative within the agreed mandate.

UK representative contact channel

A monitored electronic channel for communications relating to the representative mandate.

Designated lead

A defined contact for the representative relationship and material escalations.

ICO communications

Receipt and coordination of communications addressed to the representative by the Information Commissioner.

Data-subject communications

Receipt and coordination of communications from individuals addressed to the organisation through its UK representative.

Privacy notice support

Support for correctly identifying and publishing the representative's contact details within relevant privacy information.

Article 30 record arrangements

Maintenance of the representative's required Article 30 records based on current information supplied by the represented organisation, where applicable.

Article 31 cooperation

Cooperation with the Information Commissioner within the role required by the UK GDPR.

Escalation

Defined routes for urgent, material or time-sensitive matters.

Mandate review

Review of material changes affecting territorial scope, establishment, processing and the representative mandate.

Need to appoint a UK GDPR Representative?

Discuss the mandate

COMMUNICATIONS IN PRACTICE

Two channels.
Clear escalation.

Data-subject communications

  1. Individual
  2. UK representative
  3. Log & identify request
  4. Verify represented entity and relevant processing
  5. Escalate to client
  6. Client assesses / instructs
  7. Coordinate response
  8. Record

ICO communications

  1. ICO communication
  2. Receive
  3. Log
  4. Triage issue / deadline
  5. Escalate
  6. Obtain information and instructions
  7. Coordinate
  8. Relay / facilitate
  9. Record

The representative facilitates the communication channel. The controller or processor remains responsible for substantive rights decisions and compliance obligations applicable to it.

ARTICLE 30

Representative records
must remain current.

Article 30 places record-keeping obligations on controllers and processors and, where applicable, their representatives.

The representative's record arrangement depends on accurate and up-to-date information supplied by the represented organisation. Required records must be made available to the Information Commissioner on request.

The content of the record differs depending on whether the represented organisation acts as controller or processor.

  • Controller / processor identity
  • Representative details
  • DPO details where applicable
  • Purposes / categories of processing as applicable
  • Categories of individuals and personal data where applicable
  • Recipients
  • International transfers where applicable
  • Retention information where required
  • Security-measure description where required

Full data mapping, RoPA remediation and wider privacy implementation can be separately scoped.

Need to prepare your representative records?

Discuss representation readiness

PUBLIC CONTACT DETAILS

The representative must
be visible to the people
who may need it.

The ICO advises organisations to give people in the UK the representative's details, for example through their privacy information, and to make those details easily accessible to the Information Commissioner.

As part of onboarding, we can support the practical update of relevant privacy information.

RESPONSIBILITY

Representation does not
transfer UK GDPR compliance.

Article 27(5) preserves legal action against the controller or processor despite appointment of a representative.

The representative role does not replace the organisation's underlying UK GDPR responsibilities.

Represented controller / processor

Lawfulness · Transparency · Rights decisions · Security · Processor / controller obligations · Data governance

UK GDPR Representative

UK contact interface · ICO communications · Data-subject communications · Article 30 representative records · Cooperation

DIFFERENT ROLES

Representative and DPO
are not the same function.

UK GDPR Representative

Required in relevant Article 3(2) / Article 27 circumstances for organisations outside the UK.

Provides a UK regulatory and data-subject interface. Can be addressed on matters related to processing. Maintains representative records where applicable.

Data Protection Officer

Governance and oversight function under the UK GDPR where the DPO requirements apply.

Advises and monitors compliance. Has specific independence and organisational-position requirements.

An organisation may require both roles. Neither role automatically substitutes for the other.

TWO REGIMES

UK and EU Article 27
appointments are separate.

UNITED KINGDOM

UK GDPR Article 27

Representative established
United Kingdom
Service provider
PRIVACY MINDERS (UK) LIMITED
Regulator
Information Commissioner

EUROPEAN UNION

EU GDPR Article 27

Representative established
European Union
Service provider
OSTRAI Limited
Regulatory interface
Relevant EU supervisory authorities

An organisation subject to both regimes without the relevant establishments may require separate UK and EU representative appointments. One appointment does not satisfy both regimes.

Need representation in both the UK and EU?

Discuss your structure with OSTRAI
EU GDPR Representative

CONTROLLED ACCEPTANCE

We assess the mandate
before appointment.

Before accepting a UK GDPR Representative mandate, we review the organisation, legal entity, controller or processor role, UK territorial scope, processing activity, relevant data categories, regulatory history, rights-handling arrangements and operational readiness.

Where Article 3(2), Article 27 or wider UK GDPR issues require substantive legal assessment, that work can be scoped separately before appointment.

The organisation's regulatory position and readiness determine whether the mandate can proceed.

Discuss whether we can accept the mandate

ONBOARDING

The information behind
an effective UK appointment.

Entity
Correct legal entity to be represented
Role
Controller · Processor · Both, where relevant
UK establishment
Whether the entity has a branch, office or other relevant establishment in the UK
UK activities
Goods / services · Monitoring · Other relevant processing
UK individuals
Relevant categories of people in the UK
Data categories
Personal data · Special category · Criminal offence data where relevant
Processing frequency
Whether activity is occasional or ongoing
Risk
Relevant risk to individuals' rights and freedoms
Article 30 records
Availability and currency of relevant processing records
Privacy information
Representative disclosure and contact information
Rights procedures
How data-subject communications are handled
Regulatory contacts
Legal · Privacy · DPO · Operational contacts
Escalation
Contacts for time-sensitive ICO or individual communications
Regulatory history
Relevant complaints, investigations or existing authority matters
Start UK Representative onboarding

OPERATIONAL READINESS

The UK contact point
needs access to the
organisation behind it.

Effective representation depends on prompt access to accurate information, instructions and responsible internal contacts when an individual or the ICO contacts the representative.

  • Privacy / DPO
  • Legal
  • Operations
  • Security
  • Product / technology
  • Customer support
  • External counsel, where relevant

UK GDPR Representative

SCOPE

Representation and
UK GDPR implementation
are distinct.

Standard representative mandate

  • Written Article 27 appointment
  • UK contact channel
  • ICO communications
  • Data-subject communications
  • Representative disclosure support
  • Article 30 representative record arrangements
  • Routine regulatory cooperation
  • Escalation
  • Mandate maintenance

Separately scoped support

  • Article 3 territorial-scope assessment
  • Article 27 applicability analysis
  • Privacy notices
  • Data mapping
  • RoPA development / remediation
  • Lawful-basis analysis
  • Data-subject rights procedures
  • Controller / processor analysis
  • Data processing agreements
  • International transfers
  • UK Addendum / transfer mechanisms
  • DPIAs
  • Legitimate interests assessments
  • Cookie / tracking analysis
  • Direct marketing / PECR
  • Data breach response
  • ICO response strategy
  • DPO services
  • Privacy governance
  • Training

UK PRIVACY REGULATION

Representation backed by
substantive privacy capability.

The UK GDPR Representative service sits within a broader privacy and technology-regulation practice.

Where necessary, separately scoped work can address territorial scope, transparency, controller and processor obligations, individual rights, international transfers, privacy governance and regulatory response.

This means communications reaching the UK representative can be understood in their wider regulatory context.

UK ESTABLISHMENT

A genuine UK
representative structure.

UK-established entity

The representative appointment is provided by a UK-incorporated legal entity.

Article 27 focus

The mandate is structured around the statutory representative role.

ICO interface

A defined UK channel for supervisory-authority communications.

Data-subject accessibility

A UK contact route for people whose personal data falls within the represented processing.

Representative records

Article 30 record arrangements form part of the representative infrastructure where applicable.

Cross-border privacy capability

Ability to identify UK / EU and wider privacy-regulation intersections.

QUESTIONS & ANSWERS

Before your
UK appointment.

A controller or processor without a relevant UK establishment generally needs a UK representative where its relevant processing falls within Article 3(2): offering goods or services to people in the UK, whether or not payment is required, or monitoring their behaviour where it takes place in the UK. Article 27 requires a written appointment unless an Article 27(2) exemption applies.

No. Being outside the UK is not enough. The organisation's processing must fall within the relevant territorial scope of Article 3(2), and the Article 27 exemption must be considered. This applies to organisations in the EU, the United States and elsewhere on the same statutory basis.

Yes, potentially. Article 27 expressly covers both controllers and processors. A processor, including a SaaS or other service provider, needs an assessment of its own relevant processing and territorial position. Its customer's location alone does not settle that assessment.

No. UK customers may be relevant evidence, but the assessment concerns intentional offering or monitoring and the organisation's actual processing under Article 3(2). The establishment position and any Article 27 exemption must also be considered.

Not by itself. Mere accessibility does not establish intentional UK targeting. UK-facing marketing, a UK-specific offering and other evidence of intended goods or services provision may be relevant. Monitoring activity requires its own assessment.

All three processing conditions must be satisfied: the processing is occasional; it does not include large-scale processing of special-category or criminal-conviction and offence data; and it is unlikely to result in a risk to individuals' rights and freedoms, taking account of its nature, context, scope and purposes. Public authorities or bodies have a separate exemption under Article 27(2)(b). There is no general company-size exemption.

The representative is appointed in writing and can be addressed by the Information Commissioner and data subjects in addition to or instead of the controller or processor on processing-related compliance issues. Its role includes the UK contact interface, escalation, Article 30 representative records where applicable and Article 31 cooperation. Substantive privacy implementation is separately scoped.

No. Article 27(5) preserves legal action against the controller or processor itself. The represented organisation remains responsible for its underlying processing and compliance decisions. The representative does not replace the controller or processor.

No. A representative provides the statutory UK interface under Articles 3 and 27. A DPO performs a governance, advice and monitoring role where required under Article 37 or voluntarily appointed, with specific independence requirements. Neither appointment automatically satisfies the other role.

Potentially, where both territorial regimes apply and the organisation lacks the relevant establishments. A UK appointment does not satisfy EU Article 27, and an EU appointment does not satisfy UK Article 27. UK GDPR Representative services are provided by PRIVACY MINDERS (UK) LIMITED; EU GDPR Representative services are provided by OSTRAI Limited. The mandates remain separate.

Still unsure whether Article 27 applies?

Discuss your position

UK GDPR REPRESENTATIVE

Put the right UK
representation structure
in place.

We support eligible controllers and processors outside the United Kingdom from Article 3 and Article 27 scope assessment through appointment, UK contact infrastructure, ICO and data-subject communications, representative records and ongoing mandate coordination.

UK GDPR Representative services are provided by PRIVACY MINDERS (UK) LIMITED, company no. 13248616.