← Back to Insights

GDPR

A Customer Questionnaire Asks for Your UK GDPR Representative: How to Answer It

Michael K. Onyekwere··6 min read

If you sell to UK businesses from outside the UK, a supplier questionnaire will sooner or later ask some version of this: have you appointed a representative in the UK under Article 27 of the UK GDPR?

There are five honest answers to that question, and which one is yours depends on facts you already know. This page explains what the customer is checking, how to give each answer without overstating anything, and what to attach.

What the customer is checking

It is checking whether UK data protection law reaches you at all and, if it does, whether you have met one of its most visible requirements.

Article 3(2) of the UK GDPR applies the law to a controller or processor not established in the UK where the processing activities are related to "the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the United Kingdom" or "the monitoring of their behaviour as far as their behaviour takes place within the United Kingdom".

Where Article 3(2) applies, Article 27(1) says the controller or processor "shall designate in writing a representative in the United Kingdom". The only way out is the exemption in Article 27(2).

If you will process personal data on the customer's behalf, it is answerable for choosing you. Article 28(1) says a controller "shall use only processors providing sufficient guarantees" that the processing will meet the requirements of the Regulation. A supplier that UK law reaches, with no representative designated, is a gap in those guarantees.

The five honest answers

1. Yes, we have appointed one

Give the representative's name, UK address and contact email, and the date of the written designation. Then point to the line in your privacy notice that names them.

The ICO's guidance says you should give your representative's details to the people whose information you process, for example in your privacy notice, and that you must make them easily accessible to the ICO, for example by publishing them on your website. A customer may check the privacy notice, so make sure what you write in the questionnaire matches it.

2. Not required: we are established in the UK

If your business has a UK company, branch or office, and the processing is carried out in the context of its activities, Article 3(1) applies to you directly. Article 3(2) does not, and neither does Article 27. Name the UK entity in your answer, with its company number if it has one.

3. Not required: the Article 27(2) exemption applies

The exemption covers a public authority or body, and processing that is occasional, does not include large-scale processing of special category or criminal offence data, and is unlikely to result in a risk to people's rights and freedoms. All three parts of that second limb must hold at once.

A business that has chosen to sell into the UK will rarely meet it, because regular selling is the opposite of occasional processing. If you do rely on it, say which limb applies and why, in a sentence each. The Article 27 decision guide works through each limb with examples.

4. We act only as a processor

This is the hardest case, and many software suppliers are in it.

Article 3(2) names processors as well as controllers, so being a processor does not take you outside it on its own. The question is still whether your processing activities are related to offering goods or services to people in the UK, or to monitoring their behaviour there. The ICO's guidance on representatives does not deal with processors separately.

Two situations are clear enough to state. If you market the product to individuals in the UK and they sign up to it themselves, you are offering them a service and holding their account data as a controller, so Article 3(2) applies to you and you need a representative unless the exemption does. If you track what users in the UK do inside the product for your own purposes, that points the same way.

If you only handle data for UK businesses, on their instructions and under an Article 28 contract, and do nothing with it for yourself, the position is a judgment. Write down your reasoning, give it in your answer with a reference to the contract, and expect a careful customer to ask how you reached it. The other way to settle the question is to appoint a representative, which turns the answer into a yes.

5. In progress

If you need a representative and have not appointed one yet, say so, and give the date you expect the designation to be signed.

Do not answer yes before the written designation is in place. Article 27(1) requires the designation to be in writing, so a verbal agreement or a quote is not an appointment.

Free download

Get the AI API Compliance Checklist

OpenAI / Anthropic DPA setup, zero-retention config, and the documentation a procurement or DPIA review will ask for. Worked example included.

Built for engineers implementing AI and the founders or compliance leads responsible for signing it off.

  • ·DPA setup steps for OpenAI and Anthropic API accounts
  • ·Zero-retention configuration: when it applies, what it changes, how to evidence it
  • ·Retention and logging questions to answer before launch
  • ·Audit documentation pack a procurement reviewer will accept

Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.

What not to write

Your EU representative's details. Article 27(1) requires a representative in the United Kingdom, and Article 4(17) defines a representative as someone established in the United Kingdom. An EU representative does not count unless the same provider also holds a written UK designation for you.

"We are GDPR compliant." It does not answer the question, and after Brexit the EU GDPR and the UK GDPR are separate regimes with separate representative requirements.

"Not applicable", with nothing after it. Give the reason, whichever of the five it is.

A representative you have not designated in writing. If the customer later asks for the designation and there is none, you have given a false answer in a document it relied on.

What to attach

For a yes: the representative's details as they appear in your privacy notice, and the date of the designation.

For any of the other answers: a short written note of your reasoning. For the exemption, one sentence per limb. For the processor case, your role, the contract you work under, and why you have concluded Article 3(2) does or does not reach you.

If you need one

Janus Compliance Limited acts as UK representative under Article 27 for £249 a year, the total price. That covers a registered London office for the ICO and people in the UK, every item of correspondence forwarded to you within one working day, and your record of processing held and made available to the ICO on request. The service page sets out what the appointment covers and how to start it, and there is a dated comparison of what other providers charge. If the same customers are in the EU, the EU appointment is a separate requirement under Article 27 of the EU GDPR, and we offer it through Ireland for €349 a year.

Sources

  • UK GDPR Articles 3, 4(17), 27 and 28(1), legislation.gov.uk, read 25 September 2026.
  • ICO, "Receiving personal information from the EEA", section "Do we need a UK representative?", ico.org.uk, last updated 15 January 2026, read 25 September 2026.

Free download

Get the AI API Compliance Checklist

OpenAI / Anthropic DPA setup, zero-retention config, and the documentation a procurement or DPIA review will ask for. Worked example included.

Built for engineers implementing AI and the founders or compliance leads responsible for signing it off.

  • ·DPA setup steps for OpenAI and Anthropic API accounts
  • ·Zero-retention configuration: when it applies, what it changes, how to evidence it
  • ·Retention and logging questions to answer before launch
  • ·Audit documentation pack a procurement reviewer will accept

Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.

Frequently Asked Questions

Why is a UK customer asking whether we have a UK representative?

If you will process personal data on the customer's behalf, it is answerable for choosing you. Article 28(1) of the UK GDPR says a controller shall use only processors providing sufficient guarantees that the processing will meet the requirements of the Regulation. If UK law reaches you and you have not designated the representative it requires, that is a gap in the guarantees the customer is relying on.

We already have an EU representative. Can we give their details?

No. Article 27(1) of the UK GDPR requires a representative in the United Kingdom, and Article 4(17) defines a representative as a person established in the United Kingdom. An EU representative does not meet that, unless the same provider has also been designated in writing as your UK representative.

We only process data for our business customers. Do we need one?

Possibly. Article 3(2) applies to processors as well as controllers, so being a processor does not take you outside it on its own. The question is whether your processing activities are related to offering goods or services to people in the UK, or monitoring their behaviour there. The ICO's guidance does not deal with processors separately, so write down your reasoning and give it in your answer.

Can we just answer 'not applicable'?

Only with the reason attached. A bare 'not applicable' tells the customer nothing, and a careful one will come back with the same question. Say which of the honest answers applies: established in the UK, exempt under Article 27(2), processor only with your reasoning, or appointment in progress with a date.

Start with a £500 scoping review

If you need GDPR documentation, AI Act work, or a compliant AI build, the first step is a written scoping review. You get a written report you can act on.

Related Articles

GDPR

Do You Need a UK GDPR Representative? The Article 27 Test, Answered (2026)

A company with no UK establishment that offers goods or services to people in the UK, or monitors them, must designate a UK representative in writing under Article 27 UK GDPR, unless its processing is occasional, low risk and free of large-scale special category data. The two questions that decide it, six worked scenarios, what happens if you skip it, and the exact words for your privacy notice. Verified against legislation.gov.uk on 18 September 2026.

GDPR

Is Microsoft 365 Copilot GDPR Compliant? The Oversharing Problem, and the Two Toggles That Change the Answer

Yes, with a condition Microsoft states in its own words: Copilot surfaces whatever your SharePoint permissions already allow, so the compliance question is your permissions rather than Microsoft's settings. The interim control most firms relied on stopped taking new tenants on 31 July 2026 and retires on 31 January 2027. Two admin toggles move processing outside the EU Data Boundary, and one of them takes it outside Microsoft's DPA altogether. Here is what to check, quoting Microsoft's own documentation.

GDPR

ChatGPT / OpenAI DPA Explained (2026): What the Data Processing Agreement Covers, How to Sign It, and What It Leaves to You

OpenAI's Data Processing Addendum is the Article 28 contract that lets you run the OpenAI API on personal data and stay GDPR compliant. What the DPA actually covers (training, retention, sub-processors, transfers), the exact click path to execute it, and the controller duties it does not cover.

UK GDPR representative questionnaireArticle 27 representative vendor questionnairedo we need a UK representative processorUK GDPR representative SaaSsupplier due diligence UK GDPREU representative UK