Frequently Asked Questions

We have prepared a collection of the most common questions, which are listed below. However, if you have another question or would like to discuss how we can help, please feel free to request a free consultation, or contact us.

Please note that the information provided below is intended to be generic, and may not be 100% accurate and/or complete for your specific circumstances. We recommend that, before you proceed, you should verify your understanding of any information provided here with your legal counsel or privacy consultant.
What is the purpose of a Data Protection Representative?

The Data Protection Representative role is intended to ensure that an individual, whose data is being processed by an organisation in a different country outside the legal jurisdiction in which that individual is based, is able to conveniently access their rights with respect to that data.


The Data Protection Representative is also the point of contact for the EU/EEA/UK/Swiss data protection authorities to contact an organisation outside their jurisdiction which is processing the personal data of the individuals they are responsible to, to ensure that effective regulation, investigation and enforcement of data protection laws.

Are there any exemptions from the obligation for organisations to appoint an EU/EEA or UK GDPR Representative?

Yes, the following are exempt from appointing a GDPR Representative:

  • Public sector organisations (those funded by and under the control of governments) (GDPR Article 27(2)(b))
  • Organisations undertaking processing of personal data in the course of an activity which falls outside the scope of EU/EEA/UK law (this is very limited, largely to national security matters – please seek legal advice if you intend to rely on this exemption)
  • Organisations undertaking “occasional” EU/EEA/UK personal data processing (GDPR Article 27(2)(a)) – to qualify for this exemption, both of the following must apply:
    • Organisation does not undertake large scale processing of special categories of data (those types of data listed in GDPR Articles 9(1) or 10, see “What is “special category personal data”?” below) – “large scale processing” is processing which could affect a large number of people, for more detail see GDPR Recital 91
    • The data processing “is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing”
  • In general, processing is considered as “occasional” if it “is not carried out regularly, and occurs outside the regular course of business or activity of the controller or processor” (European Data Protection Board guidance 03/2018).
What is “personal data”?

This is defined in GDPR Article 4(1) as “any information relating to an identified or identifiable natural person” (more detail is provided in GDPR – see the full GDPR wording available here), and any information which describes an individual or is otherwise unique to them, either on its own or in combination with other information available to the data controller or data processor, should be considered personal data for the purposes of GDPR.


This includes not just the obvious personal details (e.g. name, address, date of birth) but also less obvious data points (e.g. IP addresses processed using cookies on a website).

What is a “data subject”?

This is defined in GDPR Article 4(1) as “an identifiable natural person” based in the EU/EEA (or, for UK GDPR, the UK) (more detail is provided in GDPR – see the full GDPR wording available here). Please note that citizenship of the EU or a European country is not required for an individual to qualify as a data subject.


This includes not just those individuals for whom you directly process personal data (e.g. your EU/EEA/UK customers, the contacts at your EU/EEA/UK business clients) but also those for whom you are processing personal data under the instructions of others (e.g. for an online SaaS payroll platform, the employees of the clients of the that platform provider, even if the platform provider is not permitted to view that data themselves).

How should we calculate the number of EU/EEA and/or UK data subjects for the purposes of finding the correct DataRep package for our needs?

We base our pricing primarily on the number of data subjects processed by a client during an annual appointment period.


This number should include all of the following:

  • The data subjects whose personal data is stored by the client on the first day of our appointment period, including any personal data held in backups and archives etc (storage is deemed an act of data processing by GDPR);
  • The data subjects which the client anticipates collecting, adding, or otherwise temporarily processing personal data during the following 12-month period (we appreciate this can be difficult to predict with 100% accuracy, so we ask you to base this on a combination of previous year’s growth and targeted growth in the upcoming period);
  • Data subjects for whom the client acts as data controller (e.g. direct contacts) and those for whom they process as data processor (e.g. the personal data provided by their customers); and
  • Data subjects for whom they are processing IP addresses and/or locations using cookies on the website or similar (if this number can be provided separately, we may be able to rate this lower-depth data at a lower rate).
What happens if we process the personal data of more data subjects than we declared at the commencement of DataRep’s appointment period?
If, during our appointment period, it becomes apparent that you will exceed the data subject limit of the package purchased, please let us know immediately so we can update our terms with you, otherwise there is a risk that our appointment may be invalidated from commencement for being based on incorrect information.
What is “data processing”?

This is defined in GDPR Article 4(2) as “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction” (see the full GDPR wording available here). If you hold, store, collect or otherwise undertake any action which involves the personal data of an EU/EEA/UK data subject, it’s likely you are undertaking data processing.

What is “special category personal data”?

This is defined in GDPR Article 9(1) as “personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation” (more detail is provided in GDPR – see the full GDPR wording available here).


Processing of these types of data is not permitted under GDPR without additional protection measures.


Financial data is not considered special category data.


For the purposes of advising DataRep of your data processing scope, please be aware that we also include “personal data relating to criminal convictions and offences” (as described in GDPR Article 10) as part of the description of “special category data”.

What is a “data controller”?

This is defined in GDPR Article 4(7) as an organisation which decides the manner in which EU/EEA/UK personal data is processed (more detail is provided in GDPR – see the full GDPR wording available here).

What is a “data processor”?

This is defined in GDPR Article 4(8) as an organisation which only processes EU/EEA/UK personal data under the specific instructions of their data controller customer/client (or an organisation to which one data processor subcontracts the delivery of data processing activities on behalf of their data controller client – again, without any scope for choosing how that data processing is undertaken). If an organisation has any flexibility as to how they process personal data, they are more likely to be a data controller – it is possible for one organisation to be both data controller and data processor of different types of personal data – e.g. the personal data of their employees and that of their client’s customers (more detail is provided in GDPR – see the full GDPR wording available here).

What is an “establishment” for the purposes of GDPR?
Establishment is explained in GDPR Recital 22: “Establishment implies the effective and real exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect.”
Which of DataRep’s 31 contact locations will we be permitted to declare as locations for our Representative?

Because we base our pricing on the number of data subjects, we don’t take into account in our pricing where those data subjects are located, so it is the same to us if they are in a single EU country, or spread across the continent. As a result, we make available to our clients all the contact locations in the jurisdictions where you have appointed us – this prevents a situation where you need to pay more if you expand into another country, or even have to appoint a different or additional Representative


If you have appointed us as your EU GDPR Representative, you will have access to all 29 of our EU and EEA contact locations (one in each of the 27 EU member states, plus Norway and Iceland in the EEA).


If you have appointed us as your UK GDPR Representative, you will have access to our UK contact location.


If you have appointed us as your Swiss Data Protection Representative, you will have access to our contact location in Switzerland.

Why does DataRep have contact location establishments in so many countries when other Representative services only have one or a few?

The European Data Protection Board has provided guidance that the GDPR Representative should be established in the EU country where their client has the largest number of EU data subjects, and that data subjects in other EU countries should have easy access to the GDPR Representative (EDPB guidance 03/2018).


By having establishments in all 27 EU countries, and Norway & Iceland in the EEA, DataRep ensure that their clients remain compliant with EU GDPR good practice throughout the entire annual appointment period, even if their data subject demographics change during the year (e.g. if they start with France as the country with the largest number of EU data subjects, but then get a contract mid-year which means they process the personal data of many more data subjects in Poland) – and clients obtain this benefit without additional costs because they have access to those locations during the entire appointment period.

What is the process when DataRep receive a communication on our behalf?

When DataRep receive a communication on a client’s behalf we

  • Check whether it is a spam communication (one which is generic, irrelevant and/or clearly not directed solely at the client) and filter it out if so;
  • Acknowledge the request to the sender with a generic response advising that their request has been received and sent to our client; and
  • Forward the request and our acknowledgement to our client, with general guidance on how to respond.

 

Our client will then usually reply directly to the sender – although we are happy to continue to act as the conduit for those communications, it is generally preferable for the client to respond directly so that they are not sharing any additional personal data with us (at a time when the sender may be particularly sensitive about such sharing, as well as the additional GDPR obligations which arise when asking DataRep to process that personal data on their behalf) and to reassure the sender that they are taking the request seriously.

What is required to start a Data Protection Representative appointment with DataRep?
To commence our appointment as Data Protection Representative for our clients we require two elements – (1) a satisfactorily completed one-page client questionnaire, and (2) payment of our appointment fee (or a purchase order confirming payment will be made).
What is the Article 30 record of processing activities (ROPA)?

 

 

Article 30 of EU/EEA and UK GDPR requires that organisations which are required to meet GDPR’s obligations prepare a high-level summary of their data processing activities – this is the record of processing activities (ROPA). Details of what should be included are set out in GDPR Article 30 (see the full GDPR wording available here)

Are there any exemptions to the obligation to prepare a ROPA?

Article 30(5) of GDPR sets out a limited exemption from the obligation to prepare a ROPA if a company meets all of the following elements:

  • They employ fewer than 250 people;
  • The data processing they undertake is not likely to result in a risk to the rights and freedoms of data subjects;
  • The data processing they undertake is occasional (in general, processing is considered as “occasional” if it “is not carried out regularly, and occurs outside the regular course of business or activity of the controller or processor” (European Data Protection Board guidance 03/2018)); and
  • The data processing they undertake does not involve “special category personal data” for the purposes of GDPR Articles 9 or 10 (see relevant question above)
Why does DataRep require a copy of our ROPA?

As your GDPR Representative, we are required by GDPR Article 30(1) to hold the ROPAs of our clients unless they are exempt from this obligation, and by Article 30(4) to make those ROPAs available on the request of a data protection authority.


DataRep holds its clients’ ROPAs in our secure archive.

What happens if we don’t provide DataRep with our ROPA?

If we don’t receive a client’s ROPA within 30 days of the start of our appointment, we treat that as a declaration by the client that they have assessed they are exempt from the obligation to prepare this document. Please note that, if that client isn’t exempt from the ROPA obligation, there is a risk that our appointment may be invalidated from commencement because of that client not being compliant with GDPR (specifically the obligation to provide their Representative with a copy of their ROPA).

What happens when a Data Protection Authority requests our ROPA from DataRep?

When we receive a request for a client’s ROPA, the first thing we do is contact the relevant client to confirm that the version of the ROPA we hold in our secure archive is the current and correct version, or – if we don’t have a ROPA on file – that the client is still exempt from the obligation to prepare that document.


We will then respond to the Data Protection Authority once we have that confirmation (and, if relevant, the current version of the ROPA).


If we don’t hear back from our client within one week, we will provide the Authority with the latest version of the ROPA provided by that client, or – if none is on file – notify the Authority that the client is exempt from that obligation.

Why does DataRep have a Reasonable Use Policy in connection with its unlimited communications allowance?

We have established the Reasonable Use Policy so that we were able to offer the unlimited communications allowance – in the past, our packages included strict limits as to the number of communications which were included each year.


The Policy is there to protect us (and our clients) in the event that one client suffers a data breach or similar and suddenly experiences a surge in data requests as a result – it ensures that we will be able to put the necessary short-term resources in place to meet this need, without that additional cost needing to be passed down to all our clients.


In reality, only a small handful of our clients have ever come near to the Cap proposed in the Reasonable Use Policy – we’ve found that our clients receive on average one relevant communication for every 50,000 data subjects they process personal data for – to exceed the Reasonable Use Policy, it would usually be necessary to exceed this rate of requests by a factor of 10!

What should we do if our situation changes during the course of DataRep’s appointment?

There are many reasons why a client of ours may experience changes in their business which impact either the delivery of our service or the information declared by our clients at its commencement – for example, a client may buy another company and add its data processing activities to their own, or they may develop a new product which will cause them to alter the types of personal data which they process.


This shouldn’t be a problem – we’re happy to be flexible to your needs – but we do need you to notify us as soon as you become aware that any of the information provided to us on the questionnaire becomes inaccurate, or will become inaccurate during the remainder of our appointment period. If you have any questions, please don’t hesitate to contact us at contact@datarep.com, or via your usual DataRep point of contact.

What if none of DataRep’s standard Representative service packages suit our needs?

If you anticipate processing the personal data of more than 1,000,000 EU/EEA/UK data subjects, your circumstances are unusual or not appropriate for rating based on data subject numbers, please contact us to discuss pricing for our appointment as your Data Protection Representative.

How does DataRep verify the information we provide?

Although we have an audit right under our terms of business, we rarely exercise it. We rely on the accurate declarations of our clients, and that they advise us immediately if any of the information provided becomes inaccurate, because a failure to do so would likely invalidate our appointment back to its commencement, leaving that organisation without a Data Protection Representative for that period, and open to potential enforcement action from Data Protection Authorities as a result.

How do we choose the EU/EEA country in which our Leading Supervisory Authority is based?

To meet good-practice requirements, this should be the country which you are most closely aligned with, or the one where you have the largest number of EU data subjects.


Because DataRep has contact locations in all 27 EU member states, along with Norway and Iceland in the EEA, we make it possible for our clients to identify the country which is most appropriate, and to change during the course of our appointment if necessary – something which isn’t always possible with Representative service providers which have only one or a few contact locations across the EU.

What is the renewal process to continue DataRep’s appointment as our Data Protection Representative for additional annual appointment periods?

We contact clients around 6-8 weeks before our annual appointment is due to expire and ask them to provide an updated one-page questionnaire. We then issue renewal terms based on this updated information – those renewal terms will also attract the benefit of our renewal discount, providing up to 50% off the base price of our annual appointment.

Why do we need to complete DataRep’s one-page questionnaire each year?

Because our fees are based on the number of data subjects processed by out clients during each annual period, and we’ve found that most clients’ personal data processing (along with the rest of their business) grows each year, it’s important that we have current information, to prevent our appointment becoming accidentally invalidated due to being based on incorrect information. We also need to know if our clients have had any data breach events or similar, and check that they are still GDPR compliant.


We’ve done our best to keep the one-page questionnaire as short and simple as possible, but please don’t hesitate to contact us at contact@datarep.com if you have any questions about completing it.

What is the renewal discount for the second year (and beyond) based on?

We found that, for many of our clients, we receive only a small number requests each year, and so we wanted to offer those clients a discount to reflect the reduced operational work undertaken by DataRep during our appointment as their Data Protection Representative.

We base the renewal discount on the number of relevant communications we’ve received on their behalf, as compared with the data subject number limit for the package they purchased and the Reasonable Use Cap which applies.

The levels of renewal discount are set out below:

Communications receivedRenewal discount*

Fewer than 1 per 5,000 data subjects

 

50%

Fewer than 1 per 2,000 data subjects

(or more than 50% of Reasonable Use Cap)

25%

More than 1 per 2,000 data subjects

(or more than Reasonable Use Cap)

10%

(minimum renewal discount)


Renewal pricing is subject to our minimum annual appointment fee of €100.

What happens at the end of DataRep’s appointment as our Representative?

If you decide not to renew our appointment as your Data Protection Representative at the end of the appointment period, we will be sad to see you go! However, we completely understand that commercial situations change, so we wish you the best for your future operations.


There are a few matters you should be aware of:

  • Following the end of our appointment, we are no longer your Data Protection Representative – it is essential that our details are removed from your privacy notice and any other public-facing documentation, so that you are no longer obtaining the benefit of our appointment (the appearance that you have appointed us to the role of Data Protection Representative, and are therefore compliant with the relevant laws requiring that appointment). If you continue to declare us as your Representative – and therefore obtain the benefit of our service – into a subsequent annual appointment period, the fee for that period will become due.
  • If you are replacing DataRep with another Data Protection Representative, you may wish to add their details to your privacy notice etc prior to the end of our appointment period, so that any relevant communications which are sent to us towards the end of our appointment are received during the period it remains active.
  • If you are no longer required to appoint a Data Protection Representative because your organisation has added establishments in the jurisdictions in which we previously represented you, please ensure that contact details are provided for those establishments, so that data subjects in the relevant jurisdictions can contact you there (and any Data Protection Authority which views your privacy notice can see that you are not required to appoint a Representative).
  • If you are no longer required to appoint a Data Protection Representative because your organisation no longer processed the personal data of individuals in the relevant jurisdiction, please ensure that all the personal data of individuals in that jurisdiction has been completely deleted from your systems and any backups / archives – “storage” is deemed to be data processing for the purposes of GDPR, so continued retention of the personal data would mean that your organisation would still be obliged to meet GDPR’s requirements, including appointing a Representative if you have no establishment in the relevant jurisdiction.
  • If we receive a relevant communication after the expiry of our appointment period, we will offer to provide this to you on a non-Representative basis for a fee – that fee will be reduced if you have provided the details of your replacement Representative (or your own establishment in the relevant jurisdiction) in your privacy notice in place of our details. We have to take this step to ensure that ex-clients don’t continue to declare us as their Representative beyond the period we are contracted to deliver that service, as we may be inferred to have accepted the role – and the accompanying liability – if they do, despite us not having been paid our fee (or provided the relevant information) to enable us to do so.

 

I have a data protection officer (DPO) / I don't need a DPO, am I OK?

No, the obligation to have a DPO is a different obligation (under Article 37 of GDPR). The DPO is responsible for oversight of data protection strategy and compliance with GDPR, and works within your business. ​

 

A Data Protection Representative is based in the EU member states where your customers live, and is their local point of contact for raising data requests with your business.

Can my DPO be my EU representative as well?

No, Guidance issued by the European Data Protection Board (click this link to view) in November 2018 has clarified that there is a potential conflict of interest between the roles of the Data Protection Officer and the EU Representative.

Must my data protection representative be an individual person?

No, the Data Protection Representative can be a company – it must be a legal person (which includes a company), but doesn’t have to be a natural person (an individual). ​

 

If appointed by you, DataRep becomes your Data Protection Representative in the EU, able to accept and manage communications on your behalf.

Where should my EU representative be based? / Do I need to be represented in every member state of the EU?

Guidance issued by the European Data Protection Board (click this link to view) in November 2018 has clarified this. You should appoint an EU Representative which is established in the EU member state where you have the largest number of data subjects, and data subjects in other EU member states should have easy access to the Representative as well. ​

 

DataRep has representation and a physical postal address in every EU member state, giving equal access to all persons and protecting our clients against accusations that they have not properly catered for the needs of individuals in the EU.

This seems odd - how can the European Union issue my non-EU company with a multi-million Euro fine?

It is one of the key European Union principles that the rights of individuals are protected, and this protection extends out from the EU to the rest of the world ensuring that, in the modern world of de-centralised data, the privacy of European citizens is protected when it leaves the Union.

 

Some businesses have struggled with modern data protection practices, and are concerned with the consequences of an increasingly-likely data breach, with the reputational damage that results. If you require assistance in this area, please contact us so we can discuss your requirements. ​

 

In order to meet the needs of the EU market, the GDPR protections are likely to become standard across most multi-national companies.

The interpretation of GDPR is still unclear, why not wait until there is a big fine for someone else, and then change?

The European Court of Justice has consistently supported the right of individuals to keep their data within their control. The Schrems case is the best-known example, where an Austrian Facebook member took the social media giant to court for potentially allowing their data to be accessed by the National Security Agency in the USA, and the subsequent collapse of the US-EU Safe Harbour Scheme, but others like the recent WhatsApp case in the Netherlands show that the most sensible interpretation of EU data protection law is that it will be determined to the benefit of the individual.

 

It’s also possible that the level of fine may increase depending on the point at which a data controller or processor begins to act on GDPR regulations, with those businesses that only choose to act after the expiry of the two year grace period (ending 25 May 2018) potentially receiving larger fines. ​

 

There is one other aspect to consider – protecting the data of your customers can be a substantial benefit to your business when seeking to acquire and retain customers, who are increasingly conscious of how their data is stored and used.

My business is based in a country which has an 'equivalency' ruling or is covered by the privacy shield - do I still need a data protection representative?

The EU recognises some countries as having data protection laws which are equivalent to those in the EU. These are the other EEA countries (Iceland, Liechtenstein and Norway) and others – see the current list here. The EU permits transfers of data to these countries without extra measures being put in place, such as binding corporate rules etc. A similar arrangement with the USA via the ‘Privacy Shield’, the replacement for the failed ‘Safe Harbour’, was ruled insufficient by the European courts in 2020.


BUT, being based in an adequate country does not remove the need to appoint a Data Protection Representative. The adequacy ruling relates to data transportation across international boundaries but makes no difference to the obligation that a non-EU data controller or processor is required to appoint an EU-based Data Protection Representative under Article 27.

What about the UK and Brexit?

The UK was subject to EU GDPR until Brexit was finalised at the end of 2020. From 2021 onwards, an almost-identical UK GDPR applies in the UK.


UK GDPR places an equivalent obligation on non-UK data controllers and processors to appoint a UK GDPR Representative.

DataRep can include UK GDPR Representative service in the same package as our EU GDPR Representative package – see our Shop for details of the packages available.

The dpr logo on a white background.
Datarep logo with an orange and blue background.

Thank you for visiting DPR Group’s website!

We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

If you have any questions about the change, please don’t hesitate to contact us here!

We see you’re leaving our site

Can we help you further?

 If you have a question or you’d like more information, please leave your email address and someone will contact you: