Find the right data protection service for your business

United Kingdom · Representative

UK Article 27
Representative

A UK-established representative for non-UK organisations that need a local UK GDPR contact point for the ICO and for individuals.

UK GDPR Article 27ICO contact pointNotice wording
The Data Protection Officers team in a modern office

Practical support, clearly scoped

United Kingdom · UK GDPR Article 27

Plans and inclusions

UK Article 27 Representative: pricing and service scope

Compare the subscription total, payment schedule, and included capacity before choosing your plan. All amounts are in EUR.

  • UK-based representative
  • UK ICO contact point
  • Data-subject contact point
  • Representation wording for privacy notices

Setup fee: none. The first subscription payment follows the billing schedule you select.

UK Article 27 Representative annual and monthly plans, case capacity, and response targets
Company sizeAnnual billingMonthly billingIncluded capacity
Growth< 10 employees

€129/month

€1,548 billed annually

Choose annual

€258/month

Billed monthly

Choose monthly

2 cases / year

Response target: 3 business days

Small10–49 employees

€219/month

€2,628 billed annually

Choose annual

€438/month

Billed monthly

Choose monthly

6 cases / year

Response target: 2 business days

Medium50–249 employees

€349/month

€4,188 billed annually

Choose annual

€698/month

Billed monthly

Choose monthly

18 cases / year

Response target: 1 business day

Large250–749 employees

€649/month

€7,788 billed annually

Choose annual

€1,298/month

Billed monthly

Choose monthly

60 cases / year

Response target: Priority response

Enterprise750+ employees

Custom pricing

Discuss Enterprise

Custom case volume

Response target: Dedicated SLA

Annual prices show the monthly equivalent of an upfront annual subscription. Response targets describe the service response, not a guaranteed resolution time or an extension of a legal deadline. Suitability, taxes, engagement terms, and additional work are confirmed during checkout and onboarding.

Before the appointment starts

Confirm your legal entity, processing activities, jurisdictions, contacts, and open deadlines. Agree the mandate and access arrangements, then establish the contact and reporting route for the selected service.

When additional work is needed

Tell us about expected case volumes and any implementation, urgent incident, or specialist project. Work beyond the selected plan is agreed separately; the subscription does not provide unlimited professional time.

Your UK GDPR contact point

Non-UK organisations may need a representative under Article 27 when the UK territorial-scope rules apply and no exception is available. The assessment should consider the offering, monitoring, establishment, and processing facts.

Our service provides that local anchor together with the notice language and operational support needed to integrate seamlessly into your UK GDPR Compliance Programme.

Why UK representation is enforced

Where UK Article 27 applies, the ICO and UK individuals should have a visible local contact route. A missing or weak representative can complicate supervisory correspondence and Data Breach Response; the requirement remains fact-specific.

Applicable legal framework

UK GDPR Article 27

  • UK GDPR Article 27
    Requires certain non-UK controllers and processors to designate a UK representative.
  • Transparency obligations
    Privacy notices must identify the representative and explain how to contact them.

How the service works

We set up your UK representation in four steps:

1

Applicability review

We confirm whether UK Article 27 applies to your organisation.

2

Designation

We document the representative appointment and review necessary Privacy Documentation.

3

Notice support

We provide privacy notice wording for the UK market.

4

Request handling

We manage authority and individual contact, providing guidance on International Data Transfer Assessments (IDTA) and Privacy Risk Assessments where required.

Serving UK users from abroad?

Appoint a UK Article 27 representative and give the ICO a proper local contact point.

View representative pricing

Product snapshot

RoleRepresentative
RegulationUK GDPR Article 27
Supervisory authorityUK ICO
Setup feeNone
PricingCompare annual and monthly plans above

How we help

See how this service fits your organisation

Use the sections below to understand what we review, what you receive, what your team provides, and how you can keep the result useful after delivery.

01 · Fit

Is a UK Article 27 Representative appointment right for your organisation?

If your organisation is outside the United Kingdom, is subject to the UK GDPR territorial scope, and needs a UK-based contact point for individuals and the ICO, this product gives you that route. It is aimed at companies that offer services to people in the UK or monitor them without a UK establishment.

A company outside the UK can have a strong global privacy programme and still lack a practical UK contact route. This product is for that specific gap: a UK-facing representative arrangement that can receive correspondence and help coordinate requests while the non-UK organisation keeps control of processing decisions. It fits a market-entry project, a support redesign, or a customer diligence deadline.

02 · Decision

What you will be able to decide

You need to separate the representative decision from the DPO decision. The representative provides a local route for correspondence and requests; it does not become the controller, take over the privacy programme, or provide the independence obligations of a DPO.

We help you decide whether representation is the right response to your UK territorial-scope facts and how it should sit beside any DPO or advisory work. The representative should not be presented as the controller, a technical support desk, or a substitute for lawful-basis, security, transfer, retention, and rights processes.

03 · Trigger

When to bring us in

A UK market launch, an updated privacy notice, an enterprise customer request, an ICO enquiry, or a growing volume of UK data-subject communications can reveal that the contact route is missing. Changes to the non-UK entity or UK-facing processing should trigger a review as well.

04 · Evidence

What we need from your team

The appointment should be based on the entity structure, UK-facing activities, monitoring, data categories, privacy information, request channels, and authority correspondence process. The practical question is whether a person in the UK can receive, understand, route, and help coordinate a response.

The source material should show the non-UK entity, UK offers or monitoring, the relevant categories of people and data, the notice that will publish the contact, support and request channels, and the internal owners who can supply facts. We also agree what correspondence can be handled directly and what must be escalated to your organisation.

05 · People

Who should join the work

Legal or privacy should confirm the territorial-scope assessment, customer support should confirm the request path, and leadership should approve the written designation. A representative should also know who can provide the facts needed to answer a request or authority communication.

06 · Method

How we will work together

We confirm scope, record the appointment, prepare the contact language, and align the support and escalation route. A simple scenario test shows whether your business can identify a request, acknowledge it, obtain internal facts, and return an accurate response through the representative.

A simple scenario test is valuable: a UK individual sends a request, the representative recognises it, records it, obtains the right internal facts, confirms the response owner, and tracks the outcome. We can turn that route into a written process and usable notice wording so that the appointment is connected to your day-to-day operation.

07 · Output

What you will receive

You receive a written designation, contact arrangement, privacy-notice wording, correspondence process, and clear statement of what the service covers. Individuals and the ICO should be able to find the right route without exposing internal uncertainty.

08 · Friction

What can make this harder

Organisations sometimes publish an address that is not monitored, or assume the representative will answer questions without timely access to internal records. Another failure is treating representation as evidence that the company has solved lawful-basis, security, transfer, or retention issues.

09 · Maintenance

How you keep it current

Review the appointment when UK processing, notices, support systems, responsible entity, or contact details change. Keep an internal owner for the representative relationship, and ensure that information about requests and authority correspondence can be tracked without creating a second, disconnected privacy inbox.

Update the appointment when the UK-facing service, responsible entity, support provider, public notice, or contact personnel change. Also review after a significant request or authority interaction. Keep the representative’s public details under the same change control as your privacy notice so that the route remains findable and monitored.

10 · Boundaries

What stays with your organisation

Your organisation remains responsible for UK GDPR compliance and for making the decisions that the representative communicates. The service is a local contact point and coordination layer. It is not a replacement for a DPO, legal advice, technical response, or a full compliance programme.

11 · Scope

What to prepare before you start

Prepare the non-UK entity details, UK processing description, current notice, customer or request channels, intended publication wording, and internal escalation contact. If the business also needs independent oversight, assess the UK external DPO separately.

  • Non-UK entity and UK processing or monitoring facts
  • Public UK contact wording and monitored route
  • Request and authority correspondence escalation
  • Separate assessment for a UK DPO if needed
  • Owner and review trigger for published details

12 · Buyer brief

What your first working brief should contain

Build the appointment brief around the UK route that an individual or the ICO would actually use. Identify the non-UK entity, UK-facing activity, monitoring or offer, relevant notice, request inbox, internal response owner, and authority escalation. Include the person responsible for keeping the published details current. If support is outsourced, show how the supplier will recognise a privacy matter and reach the controller. This avoids the common failure where a public address exists but the business cannot supply a timely, accurate response.

A simple launch test can follow one UK request from receipt to closure. Check the acknowledgement, internal assignment, source evidence, response approval, communication, and record retention. The test should also confirm that the representative is not being described as a substitute for the controller, a DPO, or a full compliance programme. Keep the designation with the notice version and escalation map. Review those items after a product, entity, support, or processing change so the contact route remains real.

13 · First test

What we will test first

The first review tests the UK public contact, support recognition, internal escalation, source evidence, and response approval. We also check that the non-UK entity and the UK activity are described consistently across the designation, notice, request route, and customer information. If the organisation has a DPO or adviser, the boundary should be stated so the representative is not treated as a replacement for those functions. A route test should leave a named owner for incoming correspondence and a date for reviewing published details. Keep the test result with the appointment record. This gives the business a practical way to see whether the contact point works after launch, after a support-tool change, or after the person responsible for the inbox changes.

14 · Working record

How the result stays usable

A useful result has a home after delivery. Keep the source evidence, decision, owner, scope, open actions, and next review together in a register, project record, contract file, or management routine that your team already uses. The format can be short; it just needs to make the next action and the reason for reopening the question visible. That is how professional input stays connected to the business instead of becoming a document that no one can find when the facts change.

15 · Progress

How you can judge progress

Judge progress by what your team can use and explain. Look for a supported decision, an owner who understands the action, a route that works in practice, and evidence that the agreed output reached the right system, notice, contract, ticket, or meeting. A large document or a high-level score is not enough on its own. The stronger signal is fewer repeated questions, clearer escalation, and a review date that responds to actual change.

16 · Proportion

What a proportionate scope looks like

A proportionate scope should leave you with enough detail to act and enough clarity to know what remains outside the work. We will ask for the facts that can change the answer, explain material uncertainty, and keep specialist dependencies visible. You should be able to tell a manager what was reviewed, an operating owner what to do next, and a future reviewer what event would reopen the question. That balance protects your budget and makes the result more likely to stay useful after delivery.

17 · Handoff

What remains with your organisation

Your organisation remains responsible for the processing, resources, implementation, and final business decision. We can review the supplied facts, provide professional direction, prepare agreed outputs, and make open issues easier to act on. Bring in security, technical, employment, communications, or specialist legal expertise when the question needs it. Before you buy, name the decision, evidence, owner, deadline, and boundary so the selected scope is proportionate and easy to judge.

In practice

See what you can expect

Each view shows a different part of the buyer journey: the evidence, decision, working route, safeguards, and review point behind the service.

Editorial still life showing a UK Article 27 representative contact point with correspondence, an address marker, and key
Editorial still life showing a UK Article 27 representative contact point with correspondence, an address marker, and key; evidence view for this page
Editorial still life showing a UK Article 27 representative contact point with correspondence, an address marker, and key; decision view for this page
Editorial still life showing a UK Article 27 representative contact point with correspondence, an address marker, and key; workflow view for this page
Editorial still life showing a UK Article 27 representative contact point with correspondence, an address marker, and key; safeguard view for this page
Editorial still life showing a UK Article 27 representative contact point with correspondence, an address marker, and key; review view for this page

Frequently Asked Questions

Common questions about UK Article 27 representation.

Who needs a UK representative?

Typically non-UK organisations whose processing falls within the UK territorial-scope rules in connection with offering goods or services to people in the UK or monitoring behaviour there, subject to applicable exceptions.

Is this the same as a UK Data Protection Officer?

No. The representative is a local contact under Article 27, not an independent oversight officer.

Can we combine UK and EU representation?

Often yes, but each appointment must meet its own legal requirements, which should be reinforced through Staff Privacy Training.

Before you choose your service

UK Article 27 Representative by location

Explore practical business scenarios, preparation steps, and the relevant jurisdiction for your location.

Appoint your UK Article 27 representative

Give the ICO and UK individuals a proper local contact under UK GDPR.

Select representative pricing

Disclaimer: This content is for informational purposes only and does not constitute legal advice or create a solicitor-client relationship. Data protection regulations are subject to change and specific application depends on the context of your processing activities. Please consult directly with our legal team for advice tailored to your organization.

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services