UK General Data Protection Regulation (UK GDPR) – Summary

To view details of DataRep’s service to meet the Representative obligation under this Regulation, please visit this page.

Enforceable with effect from1st February 2020
(prior to Brexit, EU GDPR was enforceable in the UK from 25th May 2018)
Summary of purposeThe protection of the personal data of individuals in the UK (“data subjects”)
Which organisations does it apply to?Any organisation which processes the personal data of individuals in the UK, whether they choose how that personal data is processed (a “data controller”) or simply process it under the instructions of another (a “data processor”), with minor exclusions for personal use, national security matters
Major obligations of regulation

  • To restrict processing of the data to situations where a lawful mechanism exists (e.g. consent, contractual obligation, legitimate interests)

  • To provide certain information to data subjects about the processing being undertaken using their data

  • To afford data subjects certain rights regarding the processing of their data (including access to the data, erasure of the data, correction of the data)

  • To ensure international transfers of personal data only occur where roughly equivalent obligations are placed on the data importer

  • To notify data breaches (etc) to authorities within 72 hours of their discovery

    Main relevant authoritiesInformation Commissioner’s Office (ICO)
    Summary of Representative obligationAn organisation which has no UK establishment, which processes personal data of individuals in the UK, is required to appoint a GDPR Representative in the UK (Article 27)

    You can view DataRep’s service to meet this obligation here
    Which organisations require a Representative?Any organisation which processes UK personal data and has no UK establishment, except:


    • Public sector organisations

    • Organisations whose UK personal data processing is only undertaken using processes which are not typical business processes for that organisation (“occasional” processing)

    Where should the Representative be established?In the UK
    Summary obligations placed on the Representative

    • Receive communications from UK data subjects and the ICO

    • Hold a copy of their clients’ Article 30 record of processing activities, and make them available to the ICO on their request

    • Facilitate communications between their clients and the ICO

    • Must not also be appointed as Data Protection Officer (DPO) for the same client

    Please reach out to us at contact@datarep.com if you have any questions, or require a quotation for the Representative service under this law.

    Please note that the contents of this document are not intended to provide complete or exhaustive information, nor should they be considered legal advice. Please ensure that you take legal advice before acting on the contents of this document.

    The dpr logo on a white background.
    Datarep logo with an orange and blue background.

    Thank you for visiting DPR Group’s website!

    We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

    Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

    If you have any questions about the change, please don’t hesitate to contact us here!

    We see you’re leaving our site

    Can we help you further?

     If you have a question or you’d like more information, please leave your email address and someone will contact you: