DataRep’s UK GDPR Representative service
At the end of 2020, the UK finished the process of leaving the European Union.
Overall, Brexit will have a huge effect on many businesses; not just in the UK and EU, but around the world. One of the effects relating to data protection and GDPR is that the position in respect of the Data Protection Representative obligation will be altered for many organisations.
This includes the formation of the new UK Data Protection Representative role, a requirement for companies outside the UK selling into the UK or monitoring people there, and it has created an additional obligation for non-UK companies to observe if they wish to continue processing UK personal data. Many companies in the EU will not previously have needed a GDPR Representative, because their EU establishment prevented this obligation from arising in the UK during the UK’s membership of the Union. DataRep offers a UK Representative service, delivered from our London contact location, in addition to our existing EU Representative service, which is available under a single appointment for a single price; please feel free to contact us to discuss your requirements.
You can view the details of our service to meet the UK GDPR Representiatve obligation here.
We have prepared the table below summarising the effects, and more detail is provided below the table.
Any organisation in the UK which processes personal data as a result of selling to the UK or across the EU will now be familiar with their obligations under GDPR. These obligations will continue under UK law, but for companies with no establishment (e.g. office) in the EU there will be additional obligation under the extra-territorial scope of GDPR, as the UK will be treated as a ‘third country’ for its purposes. UK companies in this position will need to appoint an EU Representative (see here for confirmation from the UK Information Commissioner’s Office).
If you are a UK-based company with no office in the remainder of the EU or EEA, you can answer some questions here to confirm whether you will need an EU (when considering the questions, assume that your company is not established in the EU if you have no office in the remaining 27 EU countries).
Any organisation which sells into the UK or monitors people there, unless they have an establishment (e.g. office) in the UK, will be required by UK GDPR to appoint a UK Data Protection Representative – this includes EU-based organisations, which would previously not have had an obligation to appoint a GDPR Representative.
For companies in the EU selling into the UK, which did not have a GDPR Representative requirement before Brexit, our sister company DataRep UK can offer a UK GDPR Representative package with access to our UK contact location only – please visit our DataRep UK website here to view our service to meet this requirement, and make an immediate purchase.
Any organisation which sells into the UK or monitors people there, unless they have an establishment (e.g. office) in the UK, will be required by UK GDPR to appoint a UK Data Protection Representative.
Companies which sell to the UK from outside Europe will, before Brexit, have had an obligation under GDPR to appoint an EU Representative. Now that the UK has left the EU, this position is altered so that their obligation will now be to appoint a UK Representative instead of an EU Representative (assuming they do not also sell to the EU/EEA – if so, they would need both). Please visit our DataRep UK website here to view our service to meet this requirement, and make an immediate purchase.
As well as the continuing obligation under EU GDPR, legislation has been passed by the UK Parliament which implements GDPR-equivalent obligations for companies processing UK personal data, and creates an obligation on non-UK companies to appoint a UK Data Protection Representative after Brexit (The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019). This is a new role, created as a result of Brexit, to give individuals in the UK roughly equivalent rights to those in the EU. Essentially, the UK GDPR Representative will undertake the same role (for companies selling into the UK from outside) that the EU GDPR Representative does (for companies selling into the EU from outside).
Please note: For companies outside of Europe which sell to the UK but no other EU countries, the obligation is effectively similar – the obligation has changed from appointing a Data Protection Representative in the EU (which the UK was part of) to appointing one in the UK. If you have appointed a Representative other than DataRep for this purpose, please check to make sure they have a UK establishment so their appointment as your GDPR Representative remains compliant after Brexit – if not, we can assist, please contact us.
Brexit and the Representative - what changed?
DataRep offers a market-leading EU GDPR Representative service to our clients through our network of 29 contact locations. These locations include all 27 EU member states and Norway & Iceland in the EEA. In addition, our UK GDPR Representative service, delivered from our UK (London) office, can be bundled into the same package for our clients who appoint us to deliver (or are already protected by) our EU GDPR Representative service – this saves the unnecessary cost of making a second appointment.
Please contact us to discuss your requirements, or if you have any questions.