Service

UK GDPR representative for companies outside the UK

Janus Compliance Limited acts as the UK representative under Article 27 UK GDPR for controllers and processors with no establishment in the UK. The fee is £249 a year, the total you pay, from a registered London office, with correspondence from the ICO and from UK data subjects forwarded to you within one working day.

Named in your privacy notice. Reachable by the regulator. Your record of processing held for inspection. About an hour of our work a year, priced accordingly.

£249 a year. No VAT. Cancel at renewal. Last verified 18 September 2026.

Who needs a UK representative

The obligation comes from Article 27(1) UK GDPR: “Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the United Kingdom.” Article 3(2) applies to a company with no UK establishment whose processing relates to “the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the United Kingdom” or to “the monitoring of their behaviour as far as their behaviour takes place within the United Kingdom”.

In plain terms: if people in the UK are your customers or your users, and you have no UK office, branch or subsidiary, the obligation is yours unless the exemption below covers you.

Four companies that need one

A US software company with UK users and no UK office.

Paying UK customers, UK sign-ups, UK support tickets. Article 3(2)(a) on its face.

A Nigerian fintech or remittance app serving the UK diaspora.

Senders in London, Manchester and Birmingham are UK data subjects. The company is established in Lagos. The UK bank or payment partner’s questionnaire is usually where the question first appears. The Nigerian company page covers this case in its own terms.

An EU company that closed its UK branch after Brexit.

Still selling to UK customers, no longer established here. The EU representative it may already have does not count for the UK.

An online store outside the UK that ships to UK consumers and tracks them.

Delivery to UK addresses is the offering of goods; the analytics and retargeting on UK visitors is the monitoring of behaviour. Either limb is enough.

The exemption, and how narrow it is

Article 27(2) removes the obligation for “processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing”, and for a public authority or body.

The ICO’s guidance states the same test in fewer words: you do not need a representative if “your processing is only occasional, of low risk to the data protection rights of individuals, and does not involve the large-scale use of special category or criminal offence data”.

All three limbs of the first exemption have to be met at once. Processing that is part of how the business runs, a customer database, an app, a mailing list, is not occasional, whatever its size. The exemption is for the company that has a handful of UK contacts by accident of geography, and it rarely fits a business that is selling into the UK on purpose.

What the representative does

Article 27(4) sets the mandate: the representative is “to be addressed in addition to or instead of the controller or the processor by, in particular, the Commissioner and data subjects, on all issues related to processing”. In practice that is four things.

Receives and forwards

Letters and emails from the ICO, and requests or complaints from people in the UK, arrive at our London office and reach you within one working day, scanned, with a note of any deadline they carry.

Is named in your privacy notice

Articles 13(1)(a) and 14(1)(a) require the identity and contact details of the controller’s representative in the information you give data subjects. We give you the exact wording and address to paste in.

Holds your record of processing

Article 30(1) puts the record of processing on the controller “and, where applicable, the controller’s representative”. We hold a current copy and produce it to the ICO on request. If you do not have one yet, the intake form builds it.

Cooperates with the ICO

Where the ICO asks the representative a question, we answer what a representative can answer and route the rest to you. We do not answer for you, and we do not guess.

What it is not

It is not a Data Protection Officer, it is not legal advice, and it does not take your liability. Article 27(5) is explicit that appointing a representative “shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves”. The representative answers for its own duties: to be reachable, to hold the record, to cooperate. Everything else stays with you, as it should.

Price

UK representative

£249

a year, the total you pay. No VAT is added because Janus Compliance Limited is not VAT registered.

  • Named Article 27 representative, registered London office
  • Correspondence forwarded within one working day
  • Record of processing held for the ICO
  • Privacy notice wording supplied
  • Written appointment agreement
  • Twelve months, renewed annually, cancel at renewal

Nothing routine costs more. If you ask us to draft a substantive reply to the ICO, or to translate something, that is £250 an hour, agreed in writing before any work is done. Most companies never need it.

Published UK-only prices at the smallest band run from £120 a year at DataRep to £999 a year at GDPR Local, with Prighter at €420 to €852 and VeraSafe at $1,200, each banded by data subjects, headcount or revenue. The dated comparison shows who charges what, who is cheaper than us, and what the difference buys.

How appointment works

  1. 1.You send the four details in the form below and Michael replies within one working day with the appointment agreement, the intake form and the invoice.
  2. 2.You complete the intake, which is your record of processing under Article 30 if you have one, or the ten questions that let us build one if you do not.
  3. 3.Both sides sign the written designation that Article 27(1) requires, and the fee is paid.
  4. 4.You put our name and address into your privacy notice using the wording we send, and the appointment is complete.
  5. 5.Each year we invoice again thirty days before renewal, and you renew or you do not.

Enforcement, honestly

A missing representative is an infringement of Article 27, which Article 83(4) places in the standard tier: a fine of up to £8,700,000 or, for an undertaking, up to 2 per cent of total worldwide annual turnover, whichever is higher (section 157(6) of the Data Protection Act 2018 carries the same figures). That is the ceiling. Nothing in the ICO’s published guidance describes a programme of checking for missing representatives, and in its own words, quoted by the High Court in 2021, the representative is a conduit and enforcement is directed against the controller.

The question reaches most companies from somewhere else: a lawyer or adviser going through the UK obligations, an investor’s due diligence checklist, or a UK customer’s vendor questionnaire with a line that asks for the representative’s name. When it does, it is a yes or no question with a document attached, and the appointment takes a day. That is the case for doing it, and it is the whole case.

Questions we get asked

Can the representative be fined for our breach?+

No. Article 27(5) UK GDPR says the designation of a representative is without prejudice to legal actions which could be initiated against the controller or the processor themselves, and the ICO’s guidance puts it plainly: “Having a representative doesn’t affect your own responsibility or liability under the UK GDPR.” In Sansó Rondón v LexisNexis Risk Solutions UK Limited [2021] EWHC 1427 (QB) the High Court held that Article 27 does not create representative liability, and the ICO’s own position quoted in that case is that enforcement is directed against the controller itself. The representative answers for its own duties: to be contactable, to hold the record of processing, to cooperate with the ICO. Appointing us does not move your liability to us, and we do not pretend otherwise.

Do we still need a Data Protection Officer?+

The two roles are separate. A representative is required by Article 27 where Article 3(2) applies and the exemption does not. A DPO is required by Article 37 where the processing meets the thresholds there, wherever the company is. A company can need one, both or neither. If you need a DPO as well, that is a different service and a different price.

Do we also need an EU representative?+

If you offer goods or services to people in the EU, or monitor their behaviour there, without an EU establishment, Article 27 of the EU GDPR imposes the same obligation for the EU separately. A UK representative does not cover it. We expect to offer the EU appointment through an Irish company; until that page is live, ask and we will tell you where it stands.

Can you act for a processor as well as a controller?+

Yes. Article 27(1) applies to the controller or the processor. A processor outside the UK whose processing falls within Article 3(2) needs its own representative.

What happens if we set up a UK company later?+

Once you have an establishment in the UK, Article 3(2) no longer describes you and the Article 27 obligation falls away. Tell us, we end the appointment at the next renewal or sooner, and there is no exit fee.

What languages do you work in?+

English. Correspondence from the ICO and from UK data subjects arrives in English and is forwarded as received. If a reply needs drafting in another language, that is quoted separately before any work is done.

Is £249 really the whole price?+

Yes. £249 a year, invoiced annually in advance. Janus Compliance Limited is not VAT registered, so there is no VAT to add. The only things that cost extra are things you would ask for: a substantive drafted response to a regulator, or translation, at £250 an hour agreed in writing before the work starts.

Appoint Janus as your UK representative

Four details. The agreement, the intake and the invoice come back within one working day.

Your details go to Janus Compliance Limited (company number 16583861, registered office 167-169 Great Portland Street, London W1W 5PF) and are used only to answer this enquiry. Privacy notice.

Sources, read on 18 September 2026

  • UK GDPR, Articles 3, 4(17), 13, 14, 27, 30 and 83, legislation.gov.uk, revised text as at 19 June 2026.
  • Data Protection Act 2018, section 157, legislation.gov.uk, revised text as at 19 June 2026.
  • ICO, “Receiving personal information from the EEA”, section on UK representatives, ico.org.uk, last updated 15 January 2026.
  • Sansó Rondón v LexisNexis Risk Solutions UK Limited [2021] EWHC 1427 (QB), on representative liability, as reported by Womble Bond Dickinson, 9 June 2021.
  • EDPB Guidelines 3/2018 on the territorial scope of the GDPR, version 2.1, 12 November 2019, pages 24 to 28, for the EU position on the representative’s role and liability.
  • Competitor prices on the comparison page, each fetched from the provider’s own pricing page on the date shown there.