UK GDPR Representative

How it changed the Representative obligation in the EU/EEA and UK

Following the end of the Brexit transition period on 31 December 2020, the UK’s departure from the EU has affected the GDPR Representative obligation for three types of organisations:
UK-based companies selling to the EU, with no EU office
International companies selling to the EU, whose only EU office is in the UK
All companies (including those in the EU) selling to the UK with no UK office

DataRep’s UK GDPR Representative service

At the end of 2020, the UK finished the process of leaving the European Union.

Overall, Brexit will have a huge effect on many businesses; not just in the UK and EU, but around the world. One of the effects relating to data protection and GDPR is that the position in respect of the Data Protection Representative obligation will be altered for many organisations.

This includes the formation of the new UK Data Protection Representative role, a requirement for companies outside the UK selling into the UK or monitoring people there, and it has created an additional obligation for non-UK companies to observe if they wish to continue processing UK personal data. Many companies in the EU will not previously have needed a GDPR Representative, because their EU establishment prevented this obligation from arising in the UK during the UK’s membership of the Union. DataRep offers a UK Representative service, delivered from our London contact location, in addition to our existing EU Representative service, which is available under a single appointment for a single price; please feel free to contact us to discuss your requirements.

You can view the details of our service to meet the UK GDPR Representiatve obligation here.

We have prepared the table below summarising the effects, and more detail is provided below the table.

A table showing the different types of emi.
Please note, for the purposes of the table above: “EU” includes the EEA but not the UK, and “rest of world” does not include UK or any EU/EEA country
UK-based companies selling to the EU, with no EU office

Any organisation in the UK which processes personal data as a result of selling to the UK or across the EU will now be familiar with their obligations under GDPR. These obligations will continue under UK law, but for companies with no establishment (e.g. office) in the EU there will be additional obligation under the extra-territorial scope of GDPR, as the UK will be treated as a ‘third country’ for its purposes. UK companies in this position will need to appoint an EU Representative (see here for confirmation from the UK Information Commissioner’s Office).

If you are a UK-based company with no office in the remainder of the EU or EEA, you can answer some questions here to confirm whether you will need an EU (when considering the questions, assume that your company is not established in the EU if you have no office in the remaining 27 EU countries).

EU companies selling to the UK with no UK office

Any organisation which sells into the UK or monitors people there, unless they have an establishment (e.g. office) in the UK, will be required by UK GDPR to appoint a UK Data Protection Representative – this includes EU-based organisations, which would previously not have had an obligation to appoint a GDPR Representative.

For companies in the EU selling into the UK, which did not have a GDPR Representative requirement before Brexit, our sister company DataRep UK can offer a UK GDPR Representative package with access to our UK contact location only – please visit our DataRep UK website here to view our service to meet this requirement, and make an immediate purchase.

Non-EU/UK companies (with no UK office) selling to the UK and not the EU/EEA

Any organisation which sells into the UK or monitors people there, unless they have an establishment (e.g. office) in the UK, will be required by UK GDPR to appoint a UK Data Protection Representative.

Companies which sell to the UK from outside Europe will, before Brexit, have had an obligation under GDPR to appoint an EU Representative. Now that the UK has left the EU, this position is altered so that their obligation will now be to appoint a UK Representative instead of an EU Representative (assuming they do not also sell to the EU/EEA – if so, they would need both). Please visit our DataRep UK website here to view our service to meet this requirement, and make an immediate purchase.

Companies (inside or outside the EU) selling to the UK with no UK office

As well as the continuing obligation under EU GDPR, legislation has been passed by the UK Parliament which implements GDPR-equivalent obligations for companies processing UK personal data, and creates an obligation on non-UK companies to appoint a UK Data Protection Representative after Brexit (The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019). This is a new role, created as a result of Brexit, to give individuals in the UK roughly equivalent rights to those in the EU. Essentially, the UK GDPR Representative will undertake the same role (for companies selling into the UK from outside) that the EU GDPR Representative does (for companies selling into the EU from outside).

Please note: For companies outside of Europe which sell to the UK but no other EU countries, the obligation is effectively similar – the obligation has changed from appointing a Data Protection Representative in the EU (which the UK was part of) to appointing one in the UK. If you have appointed a Representative other than DataRep for this purpose, please check to make sure they have a UK establishment so their appointment as your GDPR Representative remains compliant after Brexit – if not, we can assist, please contact us.

Brexit and the Representative - what changed?

DataRep offers a market-leading EU GDPR Representative service to our clients through our network of 29 contact locations. These locations include all 27 EU member states and Norway & Iceland in the EEA. In addition, our UK GDPR Representative service, delivered from our UK (London) office, can be bundled into the same package for our clients who appoint us to deliver (or are already protected by) our EU GDPR Representative service – this saves the unnecessary cost of making a second appointment.

Please contact us to discuss your requirements, or if you have any questions.

The dpr logo on a white background.
Datarep logo with an orange and blue background.

Thank you for visiting DPR Group’s website!

We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

If you have any questions about the change, please don’t hesitate to contact us here!

We see you’re leaving our site

Can we help you further?

 If you have a question or you’d like more information, please leave your email address and someone will contact you: