Find the right data protection service for your business
UK Article 27
Representative
A UK-established representative for non-UK organisations that need a local UK GDPR contact point for the ICO and for individuals.

Practical support, clearly scoped
United Kingdom · UK GDPR Article 27
Plans and inclusions
UK Article 27 Representative: pricing and service scope
Compare the subscription total, payment schedule, and included capacity before choosing your plan. All amounts are in EUR.
- UK-based representative
- UK ICO contact point
- Data-subject contact point
- Representation wording for privacy notices
Setup fee: none. The first subscription payment follows the billing schedule you select.
| Company size | Annual billing | Monthly billing | Included capacity |
|---|---|---|---|
| Growth< 10 employees | €129/month €1,548 billed annually Choose annual | €258/month Billed monthly Choose monthly | 2 cases / year Response target: 3 business days |
| Small10–49 employees | €219/month €2,628 billed annually Choose annual | €438/month Billed monthly Choose monthly | 6 cases / year Response target: 2 business days |
| Medium50–249 employees | €349/month €4,188 billed annually Choose annual | €698/month Billed monthly Choose monthly | 18 cases / year Response target: 1 business day |
| Large250–749 employees | €649/month €7,788 billed annually Choose annual | €1,298/month Billed monthly Choose monthly | 60 cases / year Response target: Priority response |
| Enterprise750+ employees | Custom pricing Discuss Enterprise | Custom case volume Response target: Dedicated SLA | |
Annual prices show the monthly equivalent of an upfront annual subscription. Response targets describe the service response, not a guaranteed resolution time or an extension of a legal deadline. Suitability, taxes, engagement terms, and additional work are confirmed during checkout and onboarding.
Before the appointment starts
Confirm your legal entity, processing activities, jurisdictions, contacts, and open deadlines. Agree the mandate and access arrangements, then establish the contact and reporting route for the selected service.
When additional work is needed
Tell us about expected case volumes and any implementation, urgent incident, or specialist project. Work beyond the selected plan is agreed separately; the subscription does not provide unlimited professional time.
Your UK GDPR contact point
Non-UK organisations may need a representative under Article 27 when the UK territorial-scope rules apply and no exception is available. The assessment should consider the offering, monitoring, establishment, and processing facts.
Our service provides that local anchor together with the notice language and operational support needed to integrate seamlessly into your UK GDPR Compliance Programme.
Why UK representation is enforced
Where UK Article 27 applies, the ICO and UK individuals should have a visible local contact route. A missing or weak representative can complicate supervisory correspondence and Data Breach Response; the requirement remains fact-specific.
Applicable legal framework
UK GDPR Article 27
- UK GDPR Article 27
Requires certain non-UK controllers and processors to designate a UK representative. - Transparency obligations
Privacy notices must identify the representative and explain how to contact them.
How the service works
We set up your UK representation in four steps:
Applicability review
We confirm whether UK Article 27 applies to your organisation.
Designation
We document the representative appointment and review necessary Privacy Documentation.
Notice support
We provide privacy notice wording for the UK market.
Request handling
We manage authority and individual contact, providing guidance on International Data Transfer Assessments (IDTA) and Privacy Risk Assessments where required.
Serving UK users from abroad?
Appoint a UK Article 27 representative and give the ICO a proper local contact point.
View representative pricingProduct snapshot
| Role | Representative |
| Regulation | UK GDPR Article 27 |
| Supervisory authority | UK ICO |
| Setup fee | None |
| Pricing | Compare annual and monthly plans above |
How we help
See how this service fits your organisation
Use the sections below to understand what we review, what you receive, what your team provides, and how you can keep the result useful after delivery.
01 · Fit
Is a UK Article 27 Representative appointment right for your organisation?
If your organisation is outside the United Kingdom, is subject to the UK GDPR territorial scope, and needs a UK-based contact point for individuals and the ICO, this product gives you that route. It is aimed at companies that offer services to people in the UK or monitor them without a UK establishment.
A company outside the UK can have a strong global privacy programme and still lack a practical UK contact route. This product is for that specific gap: a UK-facing representative arrangement that can receive correspondence and help coordinate requests while the non-UK organisation keeps control of processing decisions. It fits a market-entry project, a support redesign, or a customer diligence deadline.
02 · Decision
What you will be able to decide
You need to separate the representative decision from the DPO decision. The representative provides a local route for correspondence and requests; it does not become the controller, take over the privacy programme, or provide the independence obligations of a DPO.
We help you decide whether representation is the right response to your UK territorial-scope facts and how it should sit beside any DPO or advisory work. The representative should not be presented as the controller, a technical support desk, or a substitute for lawful-basis, security, transfer, retention, and rights processes.
03 · Trigger
When to bring us in
A UK market launch, an updated privacy notice, an enterprise customer request, an ICO enquiry, or a growing volume of UK data-subject communications can reveal that the contact route is missing. Changes to the non-UK entity or UK-facing processing should trigger a review as well.
04 · Evidence
What we need from your team
The appointment should be based on the entity structure, UK-facing activities, monitoring, data categories, privacy information, request channels, and authority correspondence process. The practical question is whether a person in the UK can receive, understand, route, and help coordinate a response.
The source material should show the non-UK entity, UK offers or monitoring, the relevant categories of people and data, the notice that will publish the contact, support and request channels, and the internal owners who can supply facts. We also agree what correspondence can be handled directly and what must be escalated to your organisation.
05 · People
Who should join the work
Legal or privacy should confirm the territorial-scope assessment, customer support should confirm the request path, and leadership should approve the written designation. A representative should also know who can provide the facts needed to answer a request or authority communication.
06 · Method
How we will work together
We confirm scope, record the appointment, prepare the contact language, and align the support and escalation route. A simple scenario test shows whether your business can identify a request, acknowledge it, obtain internal facts, and return an accurate response through the representative.
A simple scenario test is valuable: a UK individual sends a request, the representative recognises it, records it, obtains the right internal facts, confirms the response owner, and tracks the outcome. We can turn that route into a written process and usable notice wording so that the appointment is connected to your day-to-day operation.
07 · Output
What you will receive
You receive a written designation, contact arrangement, privacy-notice wording, correspondence process, and clear statement of what the service covers. Individuals and the ICO should be able to find the right route without exposing internal uncertainty.
08 · Friction
What can make this harder
Organisations sometimes publish an address that is not monitored, or assume the representative will answer questions without timely access to internal records. Another failure is treating representation as evidence that the company has solved lawful-basis, security, transfer, or retention issues.
09 · Maintenance
How you keep it current
Review the appointment when UK processing, notices, support systems, responsible entity, or contact details change. Keep an internal owner for the representative relationship, and ensure that information about requests and authority correspondence can be tracked without creating a second, disconnected privacy inbox.
Update the appointment when the UK-facing service, responsible entity, support provider, public notice, or contact personnel change. Also review after a significant request or authority interaction. Keep the representative’s public details under the same change control as your privacy notice so that the route remains findable and monitored.
10 · Boundaries
What stays with your organisation
Your organisation remains responsible for UK GDPR compliance and for making the decisions that the representative communicates. The service is a local contact point and coordination layer. It is not a replacement for a DPO, legal advice, technical response, or a full compliance programme.
11 · Scope
What to prepare before you start
Prepare the non-UK entity details, UK processing description, current notice, customer or request channels, intended publication wording, and internal escalation contact. If the business also needs independent oversight, assess the UK external DPO separately.
- Non-UK entity and UK processing or monitoring facts
- Public UK contact wording and monitored route
- Request and authority correspondence escalation
- Separate assessment for a UK DPO if needed
- Owner and review trigger for published details
12 · Buyer brief
What your first working brief should contain
Build the appointment brief around the UK route that an individual or the ICO would actually use. Identify the non-UK entity, UK-facing activity, monitoring or offer, relevant notice, request inbox, internal response owner, and authority escalation. Include the person responsible for keeping the published details current. If support is outsourced, show how the supplier will recognise a privacy matter and reach the controller. This avoids the common failure where a public address exists but the business cannot supply a timely, accurate response.
A simple launch test can follow one UK request from receipt to closure. Check the acknowledgement, internal assignment, source evidence, response approval, communication, and record retention. The test should also confirm that the representative is not being described as a substitute for the controller, a DPO, or a full compliance programme. Keep the designation with the notice version and escalation map. Review those items after a product, entity, support, or processing change so the contact route remains real.
13 · First test
What we will test first
The first review tests the UK public contact, support recognition, internal escalation, source evidence, and response approval. We also check that the non-UK entity and the UK activity are described consistently across the designation, notice, request route, and customer information. If the organisation has a DPO or adviser, the boundary should be stated so the representative is not treated as a replacement for those functions. A route test should leave a named owner for incoming correspondence and a date for reviewing published details. Keep the test result with the appointment record. This gives the business a practical way to see whether the contact point works after launch, after a support-tool change, or after the person responsible for the inbox changes.
14 · Working record
How the result stays usable
A useful result has a home after delivery. Keep the source evidence, decision, owner, scope, open actions, and next review together in a register, project record, contract file, or management routine that your team already uses. The format can be short; it just needs to make the next action and the reason for reopening the question visible. That is how professional input stays connected to the business instead of becoming a document that no one can find when the facts change.
15 · Progress
How you can judge progress
Judge progress by what your team can use and explain. Look for a supported decision, an owner who understands the action, a route that works in practice, and evidence that the agreed output reached the right system, notice, contract, ticket, or meeting. A large document or a high-level score is not enough on its own. The stronger signal is fewer repeated questions, clearer escalation, and a review date that responds to actual change.
16 · Proportion
What a proportionate scope looks like
A proportionate scope should leave you with enough detail to act and enough clarity to know what remains outside the work. We will ask for the facts that can change the answer, explain material uncertainty, and keep specialist dependencies visible. You should be able to tell a manager what was reviewed, an operating owner what to do next, and a future reviewer what event would reopen the question. That balance protects your budget and makes the result more likely to stay useful after delivery.
17 · Handoff
What remains with your organisation
Your organisation remains responsible for the processing, resources, implementation, and final business decision. We can review the supplied facts, provide professional direction, prepare agreed outputs, and make open issues easier to act on. Bring in security, technical, employment, communications, or specialist legal expertise when the question needs it. Before you buy, name the decision, evidence, owner, deadline, and boundary so the selected scope is proportionate and easy to judge.
In practice
See what you can expect
Each view shows a different part of the buyer journey: the evidence, decision, working route, safeguards, and review point behind the service.






Frequently Asked Questions
Common questions about UK Article 27 representation.
Who needs a UK representative?
Typically non-UK organisations whose processing falls within the UK territorial-scope rules in connection with offering goods or services to people in the UK or monitoring behaviour there, subject to applicable exceptions.
Is this the same as a UK Data Protection Officer?
No. The representative is a local contact under Article 27, not an independent oversight officer.
Can we combine UK and EU representation?
Often yes, but each appointment must meet its own legal requirements, which should be reinforced through Staff Privacy Training.
Before you choose your service
UK Article 27 Representative by location
Explore practical business scenarios, preparation steps, and the relevant jurisdiction for your location.
Appoint your UK Article 27 representative
Give the ICO and UK individuals a proper local contact under UK GDPR.
Select representative pricingDisclaimer: This content is for informational purposes only and does not constitute legal advice or create a solicitor-client relationship. Data protection regulations are subject to change and specific application depends on the context of your processing activities. Please consult directly with our legal team for advice tailored to your organization.
