General Data Protection Regulation (GDPR) – Summary

Regulation (EU) 2016/679

To view details of DataRep’s service to meet the Representative obligation under this Regulation, please visit this page.

Enforceable with effect from25th May 2018
Summary of purposeThe protection of the personal data of individuals in the EU (“data subjects”)
Which organisations does it apply to?Any organisation which processes the personal data of individuals in the EU, whether they choose how that personal data is processed (a “data controller”) or simply process it under the instructions of another (a “data processor”), with minor exclusions for personal use, national security matters
Major obligations of regulation

  • To restrict processing of the data to situations where a lawful mechanism exists (e.g. consent, contractual obligation, legitimate interests)

  • To provide certain information to data subjects about the processing being undertaken using their data

  • To afford data subjects certain rights regarding the processing of their data (including access to the data, erasure of the data, correction of the data)

  • To ensure international transfers of personal data only occur where roughly equivalent obligations are placed on the data importer

  • To notify data breaches (etc) to authorities within 72 hours of their discovery


    Main relevant authorities

    • EU member state Data Protection Authorities

    • European Data Protection Board (EDPB)

    Summary of Representative obligationAn organisation which has no EU establishment, which processes the personal data of individuals in the EU, is required to appoint a GDPR Representative in the EU (Article 27)

    You can view DataRep’s service to meet this obligation here
    Which organisations require a Representative?Any organisation which processes EU personal data and has no EU establishment, except:


    • Public sector organisations

    • Organisations whose EU personal data processing is only undertaken using processes which are not typical business processes for that organisation (“occasional” processing)

    Where should the Representative be established?In one of the EU member states where the organisation’s EU data subjects are based, ideally the member state where the largest number of data subjects are based, ensuring that individuals in other EU member states have easy access to the Representative
    Summary obligations placed on the Representative

    • Receive communications from EU data subjects and EU data protection authorities on behalf of their clients

    • Hold a copy of their clients’ Article 30 record of processing activities, and make them available to EU data protection authorities on their request

    • Facilitate communications between their clients and EU authorities

    • Must not also be appointed as Data Protection Officer (DPO) for the same client

    • The Representative may be held liable for the unpaid GDPR fines of their clients



    Please reach out to us at contact@datarep.com if you have any questions, or require a quotation for the Representative service under this law.

    Please note that the contents of this document are not intended to provide complete or exhaustive information, nor should they be considered legal advice. Please ensure that you take legal advice before acting on the contents of this document.

    The dpr logo on a white background.
    Datarep logo with an orange and blue background.

    Thank you for visiting DPR Group’s website!

    We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

    Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

    If you have any questions about the change, please don’t hesitate to contact us here!

    We see you’re leaving our site

    Can we help you further?

     If you have a question or you’d like more information, please leave your email address and someone will contact you: