Back to Blog
UK GDPR LawEU Privacy LawSwiss FADP LawThailand PDPALocal RepresentativeAsia Privacy Laws

Appointing an EU, UK, Swiss or Thai Representative: The 2026 Buyer's Guide

By Rob Healey · May 10, 2026

Conceptual illustration of four glowing flag-pin beacons across Europe and Southeast Asia connected by data-flow lines, representing local data privacy representatives

If your business sells into the EU, UK, Switzerland, or Thailand without a local establishment, this article matters. Specifically, the law may require you to appoint a designated representative. Furthermore, missing this step can trigger fines up to €10 million or 2% of global turnover.

Today, this is one of the most common compliance gaps we see in mid-market and scale-up clients. Meanwhile, it is also one of the easiest to fix.

What is a representative, and why does it matter?

To clarify, a representative is not a Data Protection Officer. Rather, it is a designated legal contact within the regulator's territory. According to GDPR Article 27, the representative is the local point through which:

  • Supervisory authorities send legal notices and inquiries.
  • Data subjects raise complaints and requests.
  • Regulators verify that a non-resident company is reachable.

Above all, the representative is your visible legal anchor inside that jurisdiction. Without one, regulators have no recipient for enforcement letters, which accelerates penalties.

When are you required to appoint one?

In short, the trigger is the same across most regimes: you offer goods or services to local data subjects, or you monitor their behaviour, without an establishment in that territory.

However, each regime has its own statute:

  • EU GDPR Article 27 — requires an EU-based representative for non-EU controllers and processors.
  • UK GDPR Article 27 — requires a UK-based representative for non-UK controllers and processors. Read our explainer on why your business needs a UK representative.
  • Swiss FADP Article 14 — requires a Swiss representative for non-Swiss controllers processing high-risk data on Swiss residents.
  • Thailand PDPA Section 37 — requires a Thai representative for non-Thai controllers and processors.

For a single-source comparison, see our practical playbook on appointing local representatives.

What does a representative actually do?

In practice, a representative carries five operational duties:

  1. Receive correspondence from regulators on your behalf.
  2. Maintain records including the controller's Records of Processing Activities.
  3. Respond to data subjects within statutory deadlines.
  4. Coordinate between you, the regulator, and any complainant.
  5. Provide a physical address that the law recognises as valid service.

Crucially, the representative must be mandated in writing. Otherwise, the appointment is invalid and the gap remains open.

Why the three-team model matters here

At Formiti, representation is not a mailbox. Specifically, every appointment is delivered by three coordinated teams.

  • The Legal Team drafts the mandate, reviews scope, and handles regulator correspondence.
  • The Privacy Team prepares DPIA, ROPA, and DSAR responses when authorities request evidence.
  • The Operations Team logs every inquiry, tracks SLAs, and maintains audit-ready evidence.

As a result, when an inquiry lands, your response is coordinated, not improvised. Moreover, all four representative regimes — EU, UK, Swiss FADP, and Thai PDPA — are operated from physical offices in Dublin, Birmingham, Zug, and Nakhon Sawan.

Where Privacy360 fits

In parallel, Privacy360 gives your representative a live operating layer. Specifically, every DSAR, breach notice, and inquiry routes into the Privacy360 platform where evidence is timestamped and audit-ready. Furthermore, the Privacy360 Dynamic ROPA keeps records current so the representative can respond in hours, not weeks.

For organisations operating across multiple regimes, this matters even more. For example, our EU GDPR vs Swiss FADP guide shows how a unified approach prevents duplicated work.

Common mistakes to avoid

Finally, three mistakes appear repeatedly:

  • Naming a law firm as representative without a written mandate. This is invalid.
  • Using one representative for both EU and UK. Since Brexit, you need two.
  • Ignoring Switzerland and Thailand. Both have full enforcement teeth in 2026.

For broader context, see our 2026 fines playbook.

Key takeaway

In short, representation is the simplest "missing piece" in most global privacy programmes. However, it is also the highest-leverage one. To assess your gap across the EU, UK, Swiss, and Thai regimes, contact the Formiti team for a free representation review.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.