You need a UK GDPR representative if two things are true at once: your company has no establishment in the UK, and your processing relates to offering goods or services to people in the UK or to monitoring their behaviour there. That is Article 3(2) UK GDPR, and where it applies Article 27(1) requires you to "designate in writing a representative in the United Kingdom". The exemption in Article 27(2) is narrow. Everything below is read from the revised text on legislation.gov.uk as at 19 June 2026, checked on 18 September 2026.
Two questions decide it. Answer them in order.
Question one: are you established in the UK?
Article 3(1) applies UK GDPR to processing "in the context of the activities of an establishment of a controller or a processor in the United Kingdom". If you have a UK company, a UK branch, a UK office with staff, or any other stable arrangement through which you carry on real activity here, you are established in the UK. You then fall under Article 3(1), not Article 3(2), and the representative obligation does not arise. You have other obligations instead, starting with the ICO data protection fee.
Things that do not make you established in the UK: UK customers, a UK domain name, a UK payment processor, a UK freelancer, a server in a London data centre, or a UK accountant. The test is your own presence and activity, and none of those is you.
If you answered yes, stop here. If you answered no, go to question two.
Question two: does Article 3(2) describe your processing?
Article 3(2) applies UK GDPR to "the relevant processing of personal data of data subjects who are in the United Kingdom by a controller or processor not established in the United Kingdom, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the United Kingdom; or (b) the monitoring of their behaviour as far as their behaviour takes place within the United Kingdom."
Two limbs, and either is enough.
Offering goods or services. Payment is irrelevant, so a free app counts. The question is whether you are directing the offer at people in the UK. Pricing in pounds, delivery to UK addresses, a UK phone number, UK-specific marketing, an English-language site that names the UK as a market, a UK App Store listing: each is evidence that you are. A site that a UK resident happens to find, with no UK targeting at all, is the borderline case, and most businesses that are selling into the UK are not on it.
Monitoring behaviour. Tracking what people in the UK do: analytics tied to identifiable users, behavioural advertising, profiling, location tracking, fraud scoring on UK transactions. An online store outside the UK that runs retargeting on UK visitors is monitoring their behaviour whether or not it ever ships them anything.
If neither limb describes you, UK GDPR does not reach your processing through Article 3(2) and you do not need a representative. If either does, Article 27(1) applies unless the exemption saves you.
The exemption, read closely
Article 27(2) removes the obligation for "processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing", and for "a public authority or body".
The three limbs of the first exemption are joined by "and". All three must hold. The ICO's guidance compresses the same test into one sentence: you do not need a representative if "your processing is only occasional, of low risk to the data protection rights of individuals, and does not involve the large-scale use of special category or criminal offence data".
Occasional. Not part of how the business runs. A customer database, an app with UK users, a subscriber list, a CRM with UK leads: none of these is occasional, however small. Occasional processing is the enquiry that arrives from a UK address once in a while at a business that does not serve the UK.
No large-scale special category or criminal offence data. Health, biometric, genetic, racial or ethnic origin, political, religious, trade union, sex life or orientation data, or criminal convictions data, processed at scale. A health platform with UK users fails this limb on its own.
Unlikely to result in a risk. Judged on the nature, context, scope and purposes. Financial data, children's data, location data and anything used to make decisions about people push the processing out of "unlikely".
A business that has decided to sell into the UK will almost never satisfy all three, because deciding to sell is what makes the processing regular, and regular is the opposite of occasional. The exemption is for the accidental case, and it should be claimed only after writing down why each limb is met.
Free download
Get the AI API Compliance Checklist
OpenAI / Anthropic DPA setup, zero-retention config, and the documentation a procurement or DPIA review will ask for. Worked example included.
Built for engineers implementing AI and the founders or compliance leads responsible for signing it off.
- ·DPA setup steps for OpenAI and Anthropic API accounts
- ·Zero-retention configuration: when it applies, what it changes, how to evidence it
- ·Retention and logging questions to answer before launch
- ·Audit documentation pack a procurement reviewer will accept
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
Six scenarios
- A US software company with paying UK customers and no UK office. Article 3(2)(a) applies. Not occasional. Representative required.
- A Nigerian remittance app whose senders live in London. The sender is a data subject in the UK being offered a service in the UK. Financial data. Representative required. The Nigerian company page covers the payments, property and platform cases in their own terms.
- A German retailer that closed its UK subsidiary after Brexit and still ships to UK customers. It was established in the UK and now is not. Article 3(2)(a) applies. Its EU representative, if it has one, does not count for the UK. Representative required.
- A Canadian consultancy whose only UK contact is one former client who occasionally emails. No offer directed at the UK, no monitoring, and the processing is occasional and low risk. No representative required. Write down why.
- A Singapore telehealth platform with UK patients. Article 3(2)(a) applies, and the data is Article 9 health data. The exemption fails on two limbs. Representative required.
- A UK-registered company processing UK data. Established in the UK. Article 3(1), not 3(2). No representative required for the UK, whatever it does.
What happens if you skip it
Article 27 is one of the provisions listed in Article 83(4)(a) UK GDPR, which sets the standard maximum: a fine "up to £8,700,000, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher". Section 157(6) of the Data Protection Act 2018 repeats the figures. That is the ceiling the law provides, and it should be stated once and not dressed up.
How the gap is actually found matters more than the ceiling. Nothing in the ICO's published guidance describes a programme of checking for missing representatives, and the ICO's own description of the role, quoted by the High Court in Sansó Rondón v LexisNexis Risk Solutions UK Limited [2021] EWHC 1427 (QB), is a conduit through which enforcement against the controller becomes easier. The gap surfaces when something else is already happening: a complaint from a UK customer that reaches the ICO and has no UK address to go to, a breach notification, a UK customer's vendor due diligence questionnaire, an investor's legal checklist. At that point a missing representative is a further infringement counted alongside whatever brought the ICO or the counterparty to your door, and it is the one that would have cost the least to avoid.
What goes in your privacy notice
Articles 13(1)(a) and 14(1)(a) UK GDPR require you to give data subjects "the identity and the contact details of the controller and, where applicable, of the controller's representative". One sentence in the section where you give your own details:
Our representative in the United Kingdom for the purposes of UK GDPR is [representative's name], [postal address], [email address]. You can contact them on any matter relating to our processing of your personal data.
Article 30(1) also puts the record of processing activities on "each controller and, where applicable, the controller's representative". Your representative should hold a current copy and be able to produce it to the ICO.
How to appoint one
Article 27(1) says "in writing", so the appointment is a signed document, not an email saying yes. The representative must be established in the UK (Article 4(17)). The written designation should set out the mandate in Article 27(4): to be addressed by the ICO and by data subjects "on all issues related to processing", and what the representative will do with what it receives. It should also say what it does not do, since Article 27(5) keeps every legal action against the controller or processor exactly where it was.
Janus Compliance Limited provides the appointment for £249 a year, the total price, from a registered London office, with correspondence forwarded within one working day. The cost comparison sets out what the other providers charge for the same thing, with dates.
Sources
- UK GDPR, Articles 3, 4(17), 13, 14, 27, 30 and 83. legislation.gov.uk, revised text as at 19 June 2026, read 18 September 2026.
- Data Protection Act 2018, section 157. legislation.gov.uk, revised text as at 19 June 2026, read 18 September 2026.
- ICO, "Receiving personal information from the EEA", section "Do we need UK representatives?", ico.org.uk, last updated 15 January 2026, read 18 September 2026.
- Sansó Rondón v LexisNexis Risk Solutions UK Limited [2021] EWHC 1427 (QB), as reported by Womble Bond Dickinson, 9 June 2021.
Last verified 18 September 2026. This is educational and not legal advice. Whether the exemption applies to your processing is a judgement on your facts, and it should be written down at the time you make it.
Free download
Get the AI API Compliance Checklist
OpenAI / Anthropic DPA setup, zero-retention config, and the documentation a procurement or DPIA review will ask for. Worked example included.
Built for engineers implementing AI and the founders or compliance leads responsible for signing it off.
- ·DPA setup steps for OpenAI and Anthropic API accounts
- ·Zero-retention configuration: when it applies, what it changes, how to evidence it
- ·Retention and logging questions to answer before launch
- ·Audit documentation pack a procurement reviewer will accept
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
Frequently Asked Questions
Do I need a UK GDPR representative?
You do if two things are true at once: your company has no establishment in the UK, and your processing relates to offering goods or services to people in the UK or monitoring their behaviour there (Article 3(2) UK GDPR). Article 27(1) then requires you to designate a representative in the UK in writing. The only escape is the Article 27(2) exemption for processing that is occasional, involves no large-scale special category or criminal offence data, and is unlikely to result in a risk, or for a public authority.
What counts as an establishment in the UK?
A UK company, branch, office or other stable arrangement through which you carry on real activity in the UK. If you have one, Article 3(1) applies to you directly and you do not need a representative for the UK. A UK customer, a UK server, a UK freelancer or a UK payment provider is not, on its own, an establishment of yours.
Does a UK representative have to be a company?
No. Article 4(17) UK GDPR defines a representative as a natural or legal person established in the United Kingdom, designated in writing under Article 27. A person living in the UK can be one. Most companies choose a firm whose job it is, because the representative is the address the ICO writes to and the record of processing is held by them under Article 30(1).
What is the penalty for not appointing a UK representative?
Article 27 is in the standard tier under Article 83(4) UK GDPR: a fine of up to £8,700,000 or, for an undertaking, up to 2 per cent of total worldwide annual turnover, whichever is higher, with the same figures in section 157(6) of the Data Protection Act 2018. That is the ceiling. In practice the gap is found inside something else, a complaint, a breach, a customer's due diligence, and it is one more thing counted against you at that point.
Do I need an EU representative as well as a UK one?
They are separate obligations under two separate laws. If you serve people in the EU without an EU establishment, Article 27 of the EU GDPR requires an EU representative established in one of the member states where your data subjects are. A UK representative does not satisfy it, and an EU representative does not satisfy the UK.
What do I put in my privacy notice once I have appointed one?
Articles 13(1)(a) and 14(1)(a) UK GDPR require the identity and the contact details of the controller's representative alongside your own. One sentence does it: 'Our representative in the United Kingdom for the purposes of UK GDPR is [name], [address], [email].' Put it wherever your notice gives your own contact details.
Start with a £500 scoping review
If you need GDPR documentation, AI Act work, or a compliant AI build, the first step is a written scoping review. You get a written report you can act on.
Related Articles
GDPR
Is Microsoft 365 Copilot GDPR Compliant? The Oversharing Problem, and the Two Toggles That Change the Answer
Yes, with a condition Microsoft states in its own words: Copilot surfaces whatever your SharePoint permissions already allow, so the compliance question is your permissions rather than Microsoft's settings. The interim control most firms relied on stopped taking new tenants on 31 July 2026 and retires on 31 January 2027. Two admin toggles move processing outside the EU Data Boundary, and one of them takes it outside Microsoft's DPA altogether. Here is what to check, quoting Microsoft's own documentation.
GDPR
ChatGPT / OpenAI DPA Explained (2026): What the Data Processing Agreement Covers, How to Sign It, and What It Leaves to You
OpenAI's Data Processing Addendum is the Article 28 contract that lets you run the OpenAI API on personal data and stay GDPR compliant. What the DPA actually covers (training, retention, sub-processors, transfers), the exact click path to execute it, and the controller duties it does not cover.
GDPR
GDPR-Compliant LLM APIs: OpenAI vs Anthropic vs Google (2026)
Which LLM API can you run on personal data and stay GDPR compliant: OpenAI, Anthropic, or Google? All three can be configured to comply on the right tier, and the differences are in the defaults: who trains on your data, the DPA, EU data residency, retention, and transfers. A side-by-side for 2026, plus where Mistral and self-hosting fit.