UK GDPR Article 27 requires controllers and processors not established in the UK to appoint a UK representative when they process UK residents' personal data — subject to limited exceptions. This requirement is frequently overlooked by EU and international companies that have UK users but no UK office. Non-compliance is simple to detect and is one of the easier enforcement actions for the ICO.
The UK GDPR Article 27 Requirement
The rule: if you are not established in the UK (no office, no branch, no employees based in the UK) and you process personal data of individuals in the UK under the targeting criterion, you must designate a representative in writing.
The representative must be:
- Established in the UK
- Designated by the controller or processor in writing
- Available as a contact point for the ICO and for data subjects in the UK
Who Needs a UK Representative
Needs one:
- EU-based SaaS companies with UK users or customers
- US companies serving UK consumers or businesses
- Non-UK companies monitoring UK users' behaviour (analytics, behavioural profiling)
- Any controller or processor not established in the UK that processes UK personal data under the targeting criterion
Does not need one:
- Public authorities and bodies (specific exemption)
- Controllers/processors where processing is "occasional, unlikely to result in risk to rights and freedoms, and does not involve large-scale processing of special category data" — this exception is narrow in practice
- Organisations that ARE established in the UK (they are directly subject to UK GDPR)
The "occasional" exception is often misunderstood. It means genuinely rare, incidental processing — not regular business processing that happens to involve UK individuals. A SaaS company with 200 UK customers does not qualify for the exception.
What a UK Representative Does
The representative:
- Acts as the point of contact for UK data subjects exercising their rights
- Acts as the point of contact for the ICO for enquiries, investigations, and enforcement
- Receives service of legal proceedings on behalf of the controller/processor in the UK
The representative does not take on personal liability for the controller's compliance. They are an administrative interface, not a liability shield. The controller/processor remains responsible for compliance.
The representative can be:
- A UK-based business providing UK GDPR representation services (various professional services firms offer this)
- A UK-based partner, agent, or subsidiary (if they agree to act in this capacity)
- A law firm or specialist data protection services company
How to Appoint a UK Representative
Step 1: Select a representative For most EU SaaS companies, the simplest option is a specialist UK GDPR representative service. These companies provide:
- A UK-established contact point
- Handling of ICO correspondence
- Handling of data subject rights requests received in their UK capacity
- An address in your UK privacy notice and registration with the ICO as your representative
Typical cost: £300–£800/year for a standard SaaS company.
Step 2: Document the appointment The appointment must be in writing. This is typically a service agreement or letter of appointment that:
- Names the representative and confirms their UK establishment
- Specifies the scope of the representation (receiving ICO and data subject correspondence)
- Defines the process for handling enquiries received by the representative
Step 3: Update your privacy notice Include the UK representative's name and contact details in your UK GDPR privacy notice — the representative's address as the point of contact for UK data subjects.
Step 4: Maintain the appointment If the representative changes, update the privacy notice and ICO records promptly.
What Happens If You Don't Appoint
Failure to appoint a required UK representative is a violation of UK GDPR. The ICO can:
- Issue an enforcement notice requiring appointment
- Issue a fine — typically at the lower penalty tier for this type of administrative failure, but material violations (e.g., large-scale processing without any representative) can attract higher fines
- Use the absence of a representative as an aggravating factor in other enforcement proceedings
The ICO actively reviews privacy notices for compliance with the representative requirement. Targeted sweeps of specific sectors have identified and contacted companies missing UK representatives.
Timing
If you are currently processing UK personal data without a UK representative and this requirement applies to you, appoint one as soon as possible. There is no transition period. Appoint, document it, and update your privacy notice.