We have prepared a collection of the most common questions, which are listed below. However, if you have another question or would like to discuss how we can help, please feel free to request a free consultation, or contact us.
The Data Protection Representative role is intended to ensure that an individual, whose data is being processed by an organisation in a different country outside the legal jurisdiction in which that individual is based, is able to conveniently access their rights with respect to that data.
The Data Protection Representative is also the point of contact for the EU/EEA/UK/Swiss data protection authorities to contact an organisation outside their jurisdiction which is processing the personal data of the individuals they are responsible to, to ensure that effective regulation, investigation and enforcement of data protection laws.
Yes, the following are exempt from appointing a GDPR Representative:
- Public sector organisations (those funded by and under the control of governments) (GDPR Article 27(2)(b))
- Organisations undertaking processing of personal data in the course of an activity which falls outside the scope of EU/EEA/UK law (this is very limited, largely to national security matters – please seek legal advice if you intend to rely on this exemption)
- Organisations undertaking “occasional” EU/EEA/UK personal data processing (GDPR Article 27(2)(a)) – to qualify for this exemption, both of the following must apply:
- Organisation does not undertake large scale processing of special categories of data (those types of data listed in GDPR Articles 9(1) or 10, see “What is “special category personal data”?” below) – “large scale processing” is processing which could affect a large number of people, for more detail see GDPR Recital 91
- The data processing “is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing”
- In general, processing is considered as “occasional” if it “is not carried out regularly, and occurs outside the regular course of business or activity of the controller or processor” (European Data Protection Board guidance 03/2018).
This is defined in GDPR Article 4(1) as “any information relating to an identified or identifiable natural person” (more detail is provided in GDPR – see the full GDPR wording available here), and any information which describes an individual or is otherwise unique to them, either on its own or in combination with other information available to the data controller or data processor, should be considered personal data for the purposes of GDPR.
This includes not just the obvious personal details (e.g. name, address, date of birth) but also less obvious data points (e.g. IP addresses processed using cookies on a website).
This is defined in GDPR Article 4(1) as “an identifiable natural person” based in the EU/EEA (or, for UK GDPR, the UK) (more detail is provided in GDPR – see the full GDPR wording available here). Please note that citizenship of the EU or a European country is not required for an individual to qualify as a data subject.
This includes not just those individuals for whom you directly process personal data (e.g. your EU/EEA/UK customers, the contacts at your EU/EEA/UK business clients) but also those for whom you are processing personal data under the instructions of others (e.g. for an online SaaS payroll platform, the employees of the clients of the that platform provider, even if the platform provider is not permitted to view that data themselves).
We base our pricing primarily on the number of data subjects processed by a client during an annual appointment period.
This number should include all of the following:
- The data subjects whose personal data is stored by the client on the first day of our appointment period, including any personal data held in backups and archives etc (storage is deemed an act of data processing by GDPR);
- The data subjects which the client anticipates collecting, adding, or otherwise temporarily processing personal data during the following 12-month period (we appreciate this can be difficult to predict with 100% accuracy, so we ask you to base this on a combination of previous year’s growth and targeted growth in the upcoming period);
- Data subjects for whom the client acts as data controller (e.g. direct contacts) and those for whom they process as data processor (e.g. the personal data provided by their customers); and
- Data subjects for whom they are processing IP addresses and/or locations using cookies on the website or similar (if this number can be provided separately, we may be able to rate this lower-depth data at a lower rate).
This is defined in GDPR Article 4(2) as “any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction” (see the full GDPR wording available here). If you hold, store, collect or otherwise undertake any action which involves the personal data of an EU/EEA/UK data subject, it’s likely you are undertaking data processing.
This is defined in GDPR Article 9(1) as “personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation” (more detail is provided in GDPR – see the full GDPR wording available here).
Processing of these types of data is not permitted under GDPR without additional protection measures.
Financial data is not considered special category data.
For the purposes of advising DataRep of your data processing scope, please be aware that we also include “personal data relating to criminal convictions and offences” (as described in GDPR Article 10) as part of the description of “special category data”.
This is defined in GDPR Article 4(7) as an organisation which decides the manner in which EU/EEA/UK personal data is processed (more detail is provided in GDPR – see the full GDPR wording available here).
This is defined in GDPR Article 4(8) as an organisation which only processes EU/EEA/UK personal data under the specific instructions of their data controller customer/client (or an organisation to which one data processor subcontracts the delivery of data processing activities on behalf of their data controller client – again, without any scope for choosing how that data processing is undertaken). If an organisation has any flexibility as to how they process personal data, they are more likely to be a data controller – it is possible for one organisation to be both data controller and data processor of different types of personal data – e.g. the personal data of their employees and that of their client’s customers (more detail is provided in GDPR – see the full GDPR wording available here).
Because we base our pricing on the number of data subjects, we don’t take into account in our pricing where those data subjects are located, so it is the same to us if they are in a single EU country, or spread across the continent. As a result, we make available to our clients all the contact locations in the jurisdictions where you have appointed us – this prevents a situation where you need to pay more if you expand into another country, or even have to appoint a different or additional Representative
If you have appointed us as your EU GDPR Representative, you will have access to all 29 of our EU and EEA contact locations (one in each of the 27 EU member states, plus Norway and Iceland in the EEA).
If you have appointed us as your UK GDPR Representative, you will have access to our UK contact location.
If you have appointed us as your Swiss Data Protection Representative, you will have access to our contact location in Switzerland.
The European Data Protection Board has provided guidance that the GDPR Representative should be established in the EU country where their client has the largest number of EU data subjects, and that data subjects in other EU countries should have easy access to the GDPR Representative (EDPB guidance 03/2018).
By having establishments in all 27 EU countries, and Norway & Iceland in the EEA, DataRep ensure that their clients remain compliant with EU GDPR good practice throughout the entire annual appointment period, even if their data subject demographics change during the year (e.g. if they start with France as the country with the largest number of EU data subjects, but then get a contract mid-year which means they process the personal data of many more data subjects in Poland) – and clients obtain this benefit without additional costs because they have access to those locations during the entire appointment period.
When DataRep receive a communication on a client’s behalf we
- Check whether it is a spam communication (one which is generic, irrelevant and/or clearly not directed solely at the client) and filter it out if so;
- Acknowledge the request to the sender with a generic response advising that their request has been received and sent to our client; and
- Forward the request and our acknowledgement to our client, with general guidance on how to respond.
Our client will then usually reply directly to the sender – although we are happy to continue to act as the conduit for those communications, it is generally preferable for the client to respond directly so that they are not sharing any additional personal data with us (at a time when the sender may be particularly sensitive about such sharing, as well as the additional GDPR obligations which arise when asking DataRep to process that personal data on their behalf) and to reassure the sender that they are taking the request seriously.
Article 30 of EU/EEA and UK GDPR requires that organisations which are required to meet GDPR’s obligations prepare a high-level summary of their data processing activities – this is the record of processing activities (ROPA). Details of what should be included are set out in GDPR Article 30 (see the full GDPR wording available here)
Article 30(5) of GDPR sets out a limited exemption from the obligation to prepare a ROPA if a company meets all of the following elements:
- They employ fewer than 250 people;
- The data processing they undertake is not likely to result in a risk to the rights and freedoms of data subjects;
- The data processing they undertake is occasional (in general, processing is considered as “occasional” if it “is not carried out regularly, and occurs outside the regular course of business or activity of the controller or processor” (European Data Protection Board guidance 03/2018)); and
- The data processing they undertake does not involve “special category personal data” for the purposes of GDPR Articles 9 or 10 (see relevant question above)
As your GDPR Representative, we are required by GDPR Article 30(1) to hold the ROPAs of our clients unless they are exempt from this obligation, and by Article 30(4) to make those ROPAs available on the request of a data protection authority.
DataRep holds its clients’ ROPAs in our secure archive.
If we don’t receive a client’s ROPA within 30 days of the start of our appointment, we treat that as a declaration by the client that they have assessed they are exempt from the obligation to prepare this document. Please note that, if that client isn’t exempt from the ROPA obligation, there is a risk that our appointment may be invalidated from commencement because of that client not being compliant with GDPR (specifically the obligation to provide their Representative with a copy of their ROPA).
When we receive a request for a client’s ROPA, the first thing we do is contact the relevant client to confirm that the version of the ROPA we hold in our secure archive is the current and correct version, or – if we don’t have a ROPA on file – that the client is still exempt from the obligation to prepare that document.
We will then respond to the Data Protection Authority once we have that confirmation (and, if relevant, the current version of the ROPA).
If we don’t hear back from our client within one week, we will provide the Authority with the latest version of the ROPA provided by that client, or – if none is on file – notify the Authority that the client is exempt from that obligation.
We have established the Reasonable Use Policy so that we were able to offer the unlimited communications allowance – in the past, our packages included strict limits as to the number of communications which were included each year.
The Policy is there to protect us (and our clients) in the event that one client suffers a data breach or similar and suddenly experiences a surge in data requests as a result – it ensures that we will be able to put the necessary short-term resources in place to meet this need, without that additional cost needing to be passed down to all our clients.
In reality, only a small handful of our clients have ever come near to the Cap proposed in the Reasonable Use Policy – we’ve found that our clients receive on average one relevant communication for every 50,000 data subjects they process personal data for – to exceed the Reasonable Use Policy, it would usually be necessary to exceed this rate of requests by a factor of 10!
There are many reasons why a client of ours may experience changes in their business which impact either the delivery of our service or the information declared by our clients at its commencement – for example, a client may buy another company and add its data processing activities to their own, or they may develop a new product which will cause them to alter the types of personal data which they process.
This shouldn’t be a problem – we’re happy to be flexible to your needs – but we do need you to notify us as soon as you become aware that any of the information provided to us on the questionnaire becomes inaccurate, or will become inaccurate during the remainder of our appointment period. If you have any questions, please don’t hesitate to contact us at contact@datarep.com, or via your usual DataRep point of contact.
If you anticipate processing the personal data of more than 1,000,000 EU/EEA/UK data subjects, your circumstances are unusual or not appropriate for rating based on data subject numbers, please contact us to discuss pricing for our appointment as your Data Protection Representative.
Although we have an audit right under our terms of business, we rarely exercise it. We rely on the accurate declarations of our clients, and that they advise us immediately if any of the information provided becomes inaccurate, because a failure to do so would likely invalidate our appointment back to its commencement, leaving that organisation without a Data Protection Representative for that period, and open to potential enforcement action from Data Protection Authorities as a result.
To meet good-practice requirements, this should be the country which you are most closely aligned with, or the one where you have the largest number of EU data subjects.
Because DataRep has contact locations in all 27 EU member states, along with Norway and Iceland in the EEA, we make it possible for our clients to identify the country which is most appropriate, and to change during the course of our appointment if necessary – something which isn’t always possible with Representative service providers which have only one or a few contact locations across the EU.
We contact clients around 6-8 weeks before our annual appointment is due to expire and ask them to provide an updated one-page questionnaire. We then issue renewal terms based on this updated information – those renewal terms will also attract the benefit of our renewal discount, providing up to 50% off the base price of our annual appointment.
Because our fees are based on the number of data subjects processed by out clients during each annual period, and we’ve found that most clients’ personal data processing (along with the rest of their business) grows each year, it’s important that we have current information, to prevent our appointment becoming accidentally invalidated due to being based on incorrect information. We also need to know if our clients have had any data breach events or similar, and check that they are still GDPR compliant.
We’ve done our best to keep the one-page questionnaire as short and simple as possible, but please don’t hesitate to contact us at contact@datarep.com if you have any questions about completing it.
We found that, for many of our clients, we receive only a small number requests each year, and so we wanted to offer those clients a discount to reflect the reduced operational work undertaken by DataRep during our appointment as their Data Protection Representative.
We base the renewal discount on the number of relevant communications we’ve received on their behalf, as compared with the data subject number limit for the package they purchased and the Reasonable Use Cap which applies.
The levels of renewal discount are set out below:
| Communications received | Renewal discount* |
Fewer than 1 per 5,000 data subjects
| 50% |
Fewer than 1 per 2,000 data subjects (or more than 50% of Reasonable Use Cap) | 25% |
More than 1 per 2,000 data subjects (or more than Reasonable Use Cap) | 10% (minimum renewal discount) |
Renewal pricing is subject to our minimum annual appointment fee of €100.
If you decide not to renew our appointment as your Data Protection Representative at the end of the appointment period, we will be sad to see you go! However, we completely understand that commercial situations change, so we wish you the best for your future operations.
There are a few matters you should be aware of:
- Following the end of our appointment, we are no longer your Data Protection Representative – it is essential that our details are removed from your privacy notice and any other public-facing documentation, so that you are no longer obtaining the benefit of our appointment (the appearance that you have appointed us to the role of Data Protection Representative, and are therefore compliant with the relevant laws requiring that appointment). If you continue to declare us as your Representative – and therefore obtain the benefit of our service – into a subsequent annual appointment period, the fee for that period will become due.
- If you are replacing DataRep with another Data Protection Representative, you may wish to add their details to your privacy notice etc prior to the end of our appointment period, so that any relevant communications which are sent to us towards the end of our appointment are received during the period it remains active.
- If you are no longer required to appoint a Data Protection Representative because your organisation has added establishments in the jurisdictions in which we previously represented you, please ensure that contact details are provided for those establishments, so that data subjects in the relevant jurisdictions can contact you there (and any Data Protection Authority which views your privacy notice can see that you are not required to appoint a Representative).
- If you are no longer required to appoint a Data Protection Representative because your organisation no longer processed the personal data of individuals in the relevant jurisdiction, please ensure that all the personal data of individuals in that jurisdiction has been completely deleted from your systems and any backups / archives – “storage” is deemed to be data processing for the purposes of GDPR, so continued retention of the personal data would mean that your organisation would still be obliged to meet GDPR’s requirements, including appointing a Representative if you have no establishment in the relevant jurisdiction.
- If we receive a relevant communication after the expiry of our appointment period, we will offer to provide this to you on a non-Representative basis for a fee – that fee will be reduced if you have provided the details of your replacement Representative (or your own establishment in the relevant jurisdiction) in your privacy notice in place of our details. We have to take this step to ensure that ex-clients don’t continue to declare us as their Representative beyond the period we are contracted to deliver that service, as we may be inferred to have accepted the role – and the accompanying liability – if they do, despite us not having been paid our fee (or provided the relevant information) to enable us to do so.
No, the obligation to have a DPO is a different obligation (under Article 37 of GDPR). The DPO is responsible for oversight of data protection strategy and compliance with GDPR, and works within your business.
A Data Protection Representative is based in the EU member states where your customers live, and is their local point of contact for raising data requests with your business.
No, Guidance issued by the European Data Protection Board (click this link to view) in November 2018 has clarified that there is a potential conflict of interest between the roles of the Data Protection Officer and the EU Representative.
No, the Data Protection Representative can be a company – it must be a legal person (which includes a company), but doesn’t have to be a natural person (an individual).
If appointed by you, DataRep becomes your Data Protection Representative in the EU, able to accept and manage communications on your behalf.
Guidance issued by the European Data Protection Board (click this link to view) in November 2018 has clarified this. You should appoint an EU Representative which is established in the EU member state where you have the largest number of data subjects, and data subjects in other EU member states should have easy access to the Representative as well.
DataRep has representation and a physical postal address in every EU member state, giving equal access to all persons and protecting our clients against accusations that they have not properly catered for the needs of individuals in the EU.
It is one of the key European Union principles that the rights of individuals are protected, and this protection extends out from the EU to the rest of the world ensuring that, in the modern world of de-centralised data, the privacy of European citizens is protected when it leaves the Union.
Some businesses have struggled with modern data protection practices, and are concerned with the consequences of an increasingly-likely data breach, with the reputational damage that results. If you require assistance in this area, please contact us so we can discuss your requirements.
In order to meet the needs of the EU market, the GDPR protections are likely to become standard across most multi-national companies.
The European Court of Justice has consistently supported the right of individuals to keep their data within their control. The Schrems case is the best-known example, where an Austrian Facebook member took the social media giant to court for potentially allowing their data to be accessed by the National Security Agency in the USA, and the subsequent collapse of the US-EU Safe Harbour Scheme, but others like the recent WhatsApp case in the Netherlands show that the most sensible interpretation of EU data protection law is that it will be determined to the benefit of the individual.
It’s also possible that the level of fine may increase depending on the point at which a data controller or processor begins to act on GDPR regulations, with those businesses that only choose to act after the expiry of the two year grace period (ending 25 May 2018) potentially receiving larger fines.
There is one other aspect to consider – protecting the data of your customers can be a substantial benefit to your business when seeking to acquire and retain customers, who are increasingly conscious of how their data is stored and used.
The EU recognises some countries as having data protection laws which are equivalent to those in the EU. These are the other EEA countries (Iceland, Liechtenstein and Norway) and others – see the current list here. The EU permits transfers of data to these countries without extra measures being put in place, such as binding corporate rules etc. A similar arrangement with the USA via the ‘Privacy Shield’, the replacement for the failed ‘Safe Harbour’, was ruled insufficient by the European courts in 2020.
BUT, being based in an adequate country does not remove the need to appoint a Data Protection Representative. The adequacy ruling relates to data transportation across international boundaries but makes no difference to the obligation that a non-EU data controller or processor is required to appoint an EU-based Data Protection Representative under Article 27.
The UK was subject to EU GDPR until Brexit was finalised at the end of 2020. From 2021 onwards, an almost-identical UK GDPR applies in the UK.
UK GDPR places an equivalent obligation on non-UK data controllers and processors to appoint a UK GDPR Representative.
DataRep can include UK GDPR Representative service in the same package as our EU GDPR Representative package – see our Shop for details of the packages available.