Many businesses outside the EU and UK assume that having no physical office there means GDPR simply does not apply to them. That assumption is wrong, and it is exactly the gap Article 27 was written to close.
Quick Answer
A business established outside the EU or UK that offers goods or services to EU or UK residents, or monitors their behaviour, must appoint a local GDPR representative under Article 27. This representative acts as a contact point for supervisory authorities and data subjects. The EU and UK requirements are separate, meaning a business targeting both markets typically needs two different representatives. Non-compliance can result in fines of up to €10 million or 2% of global annual turnover.
Who Actually Needs a GDPR Representative
The requirement applies specifically to controllers and processors not established in the EU or UK, whose processing activities relate to people located there, where the business either offers goods or services to those individuals, whether or not payment is required, or monitors their behaviour. Common indicators that you are “offering goods or services” include accepting orders or sign-ups from EU or UK residents, using EU-specific pricing or currency, or shipping to those regions.
EU Representative vs UK Representative: Two Separate Roles
Since Brexit, the UK operates its own version of GDPR, sitting alongside the Data Protection Act 2018 and enforced independently by the Information Commissioner’s Office. Appointing an EU representative does not satisfy a UK obligation, and vice versa. A business processing data from both EU and UK residents typically needs two separate representatives, one established within an EU member state and one within the UK.
When You Don’t Need a Separate Representative
If your organisation already has an actual establishment in the EU or UK, such as an office, subsidiary, or branch, that establishment generally serves the representative function, and a separate Article 27 appointment is not required. You must still comply with every other GDPR requirement, but the specific Article 27 representative obligation applies only to organisations with no such local establishment.
What a GDPR Representative Actually Does
- Acts as a local contact point. Supervisory authorities and data subjects can reach the representative directly, rather than needing to contact an overseas entity.
- Facilitates communication. The representative liaises between your organisation and regulators, particularly during enforcement proceedings.
- Maintains required documentation. This can include records of processing activities accessible to the representative on request.
- Does not make decisions on your behalf. The representative is a liaison and point of contact, not a decision-maker regarding your data processing activities.
Choosing Where to Base Your Representative
An EU representative must be established in a member state where the affected data subjects are located. Where a significant proportion of your EU data subjects sit in one particular country, data protection guidance recommends locating your representative there as good practice. Ireland, the Netherlands, and Germany are commonly chosen locations, partly due to established, cost-effective compliance service providers based there.
What Happens If You Don’t Appoint One
Non-compliance exposes your organisation to Tier 1 GDPR fines, up to €10 million or 2% of global annual turnover, alongside regulatory investigation and reputational damage. Enforcement against non-EU companies has become increasingly systematic, meaning the practical risk of being identified as non-compliant continues to grow rather than shrink.
The Appointment Process
- Confirm whether your processing activities genuinely trigger the Article 27 requirement based on your actual customer base and activities
- Select a representative provider established in an appropriate EU member state, and separately in the UK if needed
- Sign a formal written designation agreement, formally mandating the representative to act on your behalf
- Update your privacy notices and public-facing contact information to reflect the appointed representative
- Maintain internal records and escalation procedures so the representative can respond promptly if contacted by a regulator or data subject
How This Connects to Your Wider Compliance
A GDPR representative is one part of a broader data protection picture. See our guide on UK GDPR requirements for small business websites for the practical compliance steps most businesses need to get right on their own website, alongside any representative appointment.
Frequently Asked Questions
Does a small business really need a GDPR representative?
If it processes personal data of EU or UK residents and has no establishment there, yes, regardless of business size, since there is no small business exemption under Article 27.
Can one representative cover both the EU and UK?
No. These are separate legal requirements under separate frameworks, and a business targeting both typically needs two distinct representatives.
What is the difference between a GDPR representative and a Data Protection Officer?
A representative is a local contact point for regulators and data subjects. A Data Protection Officer is a separate, internal role focused on overseeing an organisation’s data protection compliance.
How much does a GDPR representative typically cost?
Pricing varies by provider, though many services for small and mid-sized businesses are available at a modest fixed annual cost compared with the potential fines for non-compliance.
Does simply having a website accessible in the EU trigger the requirement?
Not on its own. Regulators look for genuine intention to serve that market, such as local pricing, currency, language, or delivery options, not just website accessibility.
Related Reading
- UK GDPR Requirements for Small Business Websites
- Is Website Accessibility a Legal Requirement in the UK?
For official guidance referenced in this article, see the ICO’s guidance for organisations.
