EU or UK Representative? A Guide for US Companies
A US company may need to assess EU and UK representative obligations separately. One appointment does not automatically cover both regimes, and the correct answer depends on territorial scope, establishments, exceptions, and the people affected.

The short answer: treat them as separate assessments
A US company serving people in both the European Economic Area and the United Kingdom should assess the EU GDPR and UK GDPR representative routes separately. The regimes use similar concepts, but they have different territorial contexts, authorities, establishment questions, and contact locations. A single contract or address should not be assumed to satisfy both without reviewing the facts and the written mandate.
The starting point is the same operational question: which legal entity processes what personal data, for which people, through which product or activity, and from which establishments? Map the EU and UK footprints separately, then record whether each representative condition and exception is met.
The EU representative route
Under the EU GDPR, Article 27 links the representative requirement to Article 3(2). A non-EU controller or processor may need a written representative in the Union when the relevant processing concerns offering goods or services to people in the Union or monitoring their behaviour there, subject to the Article 27(2) exceptions. The representative should be established in a Member State where relevant data subjects are located.
For a US SaaS company, the assessment should distinguish customer organisations from individual data subjects, controller and processor activities, EU establishments, and any marketing or analytics activity. B2B language alone does not decide the question because identifiable employee, administrator, or user information may still be processed, but the full territorial-scope analysis remains necessary.
The UK representative route
The UK GDPR has its own representative route for organisations based outside the UK that offer goods or services to people in the UK or monitor their behaviour without a UK establishment, subject to the applicable exception. The representative is a UK contact for the organisation's UK GDPR obligations and should be appointed and authorised in writing.
The UK contact details should be made available to people whose information is processed and accessible to the ICO. The organisation remains responsible for its processing and compliance. A UK representative is therefore not a replacement for a UK DPO, internal privacy owner, or broader governance programme.
A practical decision map for US companies
Create one row for the EU and one for the UK. Record the relevant establishment, target market, offering or monitoring evidence, data categories, processing frequency and scale, current privacy notice, contact channel, and proposed representative location. Then record the conclusion, the exception analysis, the owner, and the next review trigger.
This approach avoids two common mistakes: assuming that an EU appointment automatically covers the UK, or purchasing two contacts without checking whether either legal route applies. It also exposes other work that may be needed, such as a DPO assessment, transfer review, incident process, privacy-notice update, or customer questionnaire response.
- EU establishment and EU data-subject locations.
- UK establishment and UK data-subject locations.
- Offering, targeting, monitoring, and account or analytics evidence.
- Controller and processor roles for each product and business function.
- Separate mandate, notice wording, authority route, and review date.
Choosing the right support
A representative service is appropriate when the main need is a local contact and correspondence route. An external DPO service is different: it provides independent advice and monitoring under the DPO provisions. A privacy check-up can be the better first step when the company is uncertain which role, jurisdiction, or wider compliance work applies.
Before appointment, prepare the US entity details, EU and UK activities, current notices, support channels, product and vendor map, data-subject groups, internal response owners, and any customer or authority deadline. The provider should state what it can receive, route, record, and coordinate—and what remains with the company.
Frequently asked questions
Can one EU representative cover the UK?
Do not assume so. The EU GDPR and UK GDPR are separate regimes with separate establishment and authority questions. If both representative routes apply, separate arrangements may be needed.
Does selling only to businesses remove the representative question?
No. B2B status is not enough to decide the issue. Review the people whose information is processed, the offering or monitoring activity, the processing roles, and the territorial-scope criteria.
Do we need an EU representative and an external DPO?
Possibly, but they are different roles. Assess the Article 27 representative question and the DPO criteria separately against your organisation's processing and governance needs.
Where should we publish representative details?
The applicable regime may require or expect representative details to be included in privacy information and accessible to the relevant supervisory authority. Keep the details accurate and monitored.
Keep researching
Related resources
A practical next step
Make the next privacy decision clearer
Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.
This guide provides general information, not legal advice or a conclusion that a particular organisation is required to appoint a role. Final scope, responsibilities, capacity, and deliverables should be confirmed against the organisation's facts.
Sources: EUR-Lex: GDPR Articles 3 and 27, ICO: Receiving personal information from the EEA
