GDPR
UK Representative and EU Representative: Which You Need, and Why One Does Not Cover the Other
A company based outside both the UK and the EU that sells to customers in each is usually covered by two laws that read almost identically: the EU GDPR and the UK GDPR. Each asks the same question and each requires its own representative, so one appointment does not satisfy both.
This page compares the two rules, explains where each representative has to be based, works through the four situations most businesses fall into, and sets out what your privacy notice should say.
The same test, applied twice
Both regulations apply to a controller or processor that is not established in their territory but offers goods or services to people there, or monitors their behaviour there. That is Article 3(2) in each. Where it applies, Article 27(1) of each requires a representative to be designated in writing. The EU text requires "a representative in the Union"; the UK text requires "a representative in the United Kingdom".
The exemption is worded identically in both: processing that is occasional, does not include large-scale processing of special category or criminal offence data, and is unlikely to result in a risk to people's rights and freedoms, or processing by a public authority or body. The assessment still has to be made for each territory on its own facts. A business that serves the UK every day but has only occasional, low-risk contact with people in the EU may need a UK representative while relying on the exemption in the EU, or the reverse.
Where each representative must be based
For the UK, Article 4(17) of the UK GDPR defines a representative as a person "established in the United Kingdom".
For the EU, Article 27(3) of the EU GDPR is more specific. The representative "shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are". A business whose EU customers are in France and Germany therefore needs its EU representative in France or Germany.
For that reason neither appointment satisfies the other requirement. The UK is not a Member State, so a representative based in the UK cannot act for the EU, and a representative established only in an EU country is not established in the United Kingdom.
Free download
Get the AI API Compliance Checklist
OpenAI / Anthropic DPA setup, zero-retention config, and the documentation a procurement or DPIA review will ask for. Worked example included.
Built for engineers implementing AI and the founders or compliance leads responsible for signing it off.
- ·DPA setup steps for OpenAI and Anthropic API accounts
- ·Zero-retention configuration: when it applies, what it changes, how to evidence it
- ·Retention and logging questions to answer before launch
- ·Audit documentation pack a procurement reviewer will accept
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
Four common situations
- Established outside both, with customers in both, such as a US or Nigerian software company with UK and EU users: a UK representative and an EU representative.
- Established outside both, with customers in the UK only: a UK representative.
- A UK company with customers in the EU and no EU establishment: an EU representative. It does not need a UK representative, because it is established in the UK.
- An EU company with customers in the UK and no UK establishment: a UK representative. It does not need an EU representative, because it is established in the EU.
In each case the exemption can remove the requirement for one territory, but only where the processing there is genuinely occasional and low risk. A business that has chosen to sell into a territory will rarely meet that test. The Article 27 decision guide works through each limb.
What your privacy notice should say
Articles 13(1)(a) and 14(1)(a) of both regulations require the information you give people to include "the identity and the contact details of the controller and, where applicable, of the controller's representative". With two representatives, name both and say which territory each covers, so that people in the UK and in the EU can each find the right contact.
What leaving it out can cost
The fine ceilings for failing to designate a representative are set at matching levels. Under Article 83(4)(a) of the EU GDPR the ceiling is €10,000,000 or, for an undertaking, 2% of total worldwide annual turnover in the preceding financial year, whichever is higher. Under Article 83(4) of the UK GDPR it is £8,700,000 or 2% on the same basis. In practice the gap is often found through a customer's due diligence questionnaire, an investor's checklist or a lawyer reviewing your terms. How to answer the questionnaire covers that situation.
One provider or two
You can appoint separate providers or one provider that holds both appointments, as long as each representative is established in the right place. Several providers sell the two together, and the dated cost comparison sets out what they publish. Janus Compliance offers both appointments: UK representative from a registered London office for £249 a year, and EU representative appointed through Ireland for €349 a year. An Irish representative meets Article 27(3) where you have users in Ireland, which is likely for a company selling across the EU. The UK service and EU service pages explain what each appointment covers.
Sources
- EU GDPR (Regulation (EU) 2016/679), Articles 3(2), 4(17), 13(1)(a), 14(1)(a), 27 and 83(4), official text from the EU Publications Office, read 25 and 28 September and 8 October 2026.
- UK GDPR, Articles 3(2), 4(17), 13(1)(a), 14(1)(a), 27 and 83(4), legislation.gov.uk, revised text as at 30 September 2026, read 7 and 8 October 2026.
Last verified 9 October 2026. This page is general information, not legal advice. Whether you need a representative in either territory depends on your own facts.
Free download
Get the AI API Compliance Checklist
OpenAI / Anthropic DPA setup, zero-retention config, and the documentation a procurement or DPIA review will ask for. Worked example included.
Built for engineers implementing AI and the founders or compliance leads responsible for signing it off.
- ·DPA setup steps for OpenAI and Anthropic API accounts
- ·Zero-retention configuration: when it applies, what it changes, how to evidence it
- ·Retention and logging questions to answer before launch
- ·Audit documentation pack a procurement reviewer will accept
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
Frequently Asked Questions
Can our EU representative also act as our UK representative?
Only if it is also established in the United Kingdom and you designate it in writing for the UK as well. Article 27(1) of the UK GDPR requires a representative in the United Kingdom, and Article 4(17) defines a representative as a person established there. A representative based only in an EU country does not meet that.
We are a UK company. Do we need an EU representative?
If you offer goods or services to people in the EU, or monitor their behaviour there, and have no establishment in the EU, yes, unless the exemption applies. The UK is not an EU Member State, so the EU GDPR treats a UK company in the same way as any other company established outside the Union.
Which EU country should our representative be in?
Article 27(3) of the EU GDPR requires the representative to be established in one of the Member States where the people whose data you process are. If your EU customers are in France and Germany, the representative must be in France or Germany.
Is the exemption the same for the UK and the EU?
The wording is identical, but it has to be assessed separately for each territory. A business can need a representative in one and be able to rely on the exemption in the other.
Start with a £500 scoping review
If you need GDPR documentation, AI Act work, or a compliant AI build, the first step is a written scoping review. You get a written report you can act on.
Related Articles
GDPR
A Customer Questionnaire Asks for Your UK GDPR Representative: How to Answer It
UK customers ask suppliers outside the UK whether they have appointed a representative under Article 27 of the UK GDPR. What the question is checking, the five honest answers, and what to attach.
GDPR
Do You Need a UK GDPR Representative? The Article 27 Test, Answered (2026)
Under Article 27 UK GDPR, a company with no UK establishment that offers goods or services to people in the UK, or monitors them, needs a UK representative.
GDPR
Is Microsoft 365 Copilot GDPR Compliant? The Oversharing Problem, and the Two Toggles That Change the Answer
Microsoft 365 Copilot and the GDPR: why SharePoint permissions decide it, the control retiring in January 2027, and two settings outside the EU Data Boundary.