
A US software provider launches a subscription service for UK businesses. An APAC life sciences company runs a UK-facing clinical research portal. A global manufacturer monitors website behaviour to tailor sales activity in Britain. None has an office, branch or employees in the UK. Each should ask the same operational question: who needs a UK representative under UK GDPR?
For organisations outside the UK, this is not a formality to leave until a regulator makes contact. Article 27 of the UK GDPR can require a designated representative in the UK where the organisation processes personal data connected to offering goods or services to people in the UK, or monitoring their behaviour there. The requirement is designed to give data subjects and the Information Commissioner's Office (ICO) a reliable local point of contact.
Who needs a UK representative under UK GDPR?
A controller or processor that is not established in the UK will generally need a UK representative if its processing falls within the UK GDPR's extra-territorial scope. In practical terms, two triggers matter.
The first is offering goods or services to individuals in the UK. Payment is not required. A free app, product trial, research platform or online account service can still create a UK GDPR obligation where the organisation is intentionally serving people in the UK. Signals may include UK delivery options, prices in pounds sterling, UK-specific marketing, British customer support arrangements or contract terms written for the UK market.
The second is monitoring the behaviour of individuals in the UK. This can include tracking online activity for behavioural advertising, profiling users, observing location data, or analysing behaviour where the activity is connected to individuals in the UK. The assessment is fact-specific. Basic technical analytics do not automatically mean an organisation is monitoring behaviour, but extensive tracking, segmentation or profiling deserves careful review.
The obligation applies to both controllers and processors. A non-UK service provider processing UK personal data solely on documented customer instructions may therefore have its own representative requirement. This is often missed in multi-party cloud, software-as-a-service and outsourced operations arrangements.
A UK representative is not the same as a UK subsidiary. It also does not mean the organisation must establish a permanent office in the country. The representative is a locally established person or organisation appointed in writing to act on the non-UK organisation's behalf for UK GDPR matters.
The limited exceptions need evidence
Article 27 does contain exceptions, but they are narrower than many organisations assume. A representative may not be required where processing is occasional, does not include large-scale processing of special category or criminal offence data, and is unlikely to result in a risk to individuals' rights and freedoms. Public authorities and public bodies are also outside the requirement.
These conditions are cumulative. An organisation cannot rely on the exception merely because its UK customer base is presently small. A recurring service, ongoing employee recruitment, routine lead generation or continuously available product platform may be difficult to describe as occasional. Similarly, health, biometric, financial vulnerability or detailed location data can alter the risk assessment quickly.
The right approach is to document the scope assessment, the data categories involved, processing frequency, intended UK audience and risk rationale. This creates a decision record that can be reviewed as the business expands. A company that initially qualifies for an exception may need to appoint a representative once its service model, data use or UK market activity changes.
What a UK representative does in practice
The representative acts as the accessible UK contact point for the ICO and individuals whose data is processed. Their name and contact details should be included in the organisation's privacy information where the appointment is required. They must be able to receive communications and facilitate an effective response.
That role requires more than publishing an address. The representative should hold, or be able to obtain promptly, the records of processing activities that the organisation is required to maintain. They need defined escalation routes for data subject requests, complaints, regulatory correspondence and potential incident-related enquiries. They must also understand which legal entity is responsible for each processing activity, particularly in complex corporate groups.
Appointment does not transfer accountability away from the controller or processor. The overseas organisation remains responsible for meeting its UK GDPR obligations, responding to requests and maintaining appropriate governance. Nor does a representative automatically perform the role of Data Protection Officer. Where a DPO is required or voluntarily appointed, the organisation must keep the roles, reporting lines and contact arrangements clear.
For executive teams, the key operational test is straightforward: if an ICO communication arrived tomorrow, could the representative identify the responsible team, retrieve the relevant processing records and coordinate a timely, informed response? If not, the appointment is incomplete.
UK representative, EU representative and DPO: keep the mandates separate
International organisations often assume one European appointment covers every jurisdiction. It may not. The UK GDPR and EU GDPR are separate legal regimes following the UK's departure from the EU. An EU representative appointed under EU GDPR Article 27 does not automatically meet the requirement for a UK representative, and a UK appointment does not cover EU representation.
The same distinction applies to a DPO. A DPO provides independent advice, oversight and a point of contact on data protection matters. An Article 27 representative provides local representation for an organisation not established in the relevant territory. One organisation or service provider may support multiple functions where the arrangements are appropriate, but the mandates, contact details and responsibilities should be expressly documented.
This matters particularly for US and APAC-headquartered organisations expanding across the UK and EU at the same time. Separate representation decisions should be built into launch governance, alongside privacy notices, vendor terms, records of processing, data transfer arrangements and request-handling workflows. Treating representation as an isolated procurement task creates avoidable gaps once operations begin.
How to appoint a representative that can operate under pressure
Start with a jurisdictional and processing assessment. Identify every non-UK group entity that interacts with UK individuals' data, then distinguish between controller and processor roles. Map the relevant products, websites, recruitment activities, support channels, research programmes and marketing operations. This prevents the common error of appointing a representative for one entity while leaving another entity without coverage.
Next, establish a written mandate. It should define the entities and processing activities covered, the representative's authority, information access, communication channels, escalation timescales and termination arrangements. It should also set out how the representative will receive current records of processing and privacy notice updates.
Then connect the mandate to operating controls. Data subject access requests cannot sit unattended in a shared inbox. Regulatory correspondence must reach the right privacy, legal and operational owners. Breach and incident response plans should identify when the representative is notified and how external communications are coordinated. These controls should be tested, not assumed.
For organisations managing several markets, a managed representative service is most useful when it connects legal interpretation with privacy operations and technical evidence. Formiti brings together Legal, Privacy and Technical Operations teams to support that execution model, including representative mandates, records management, request workflows and cross-border accountability across more than 120 countries and 100 regulatory frameworks.
Representation should support expansion, not trail behind it
A UK representative requirement often emerges from commercial activity that has already been approved: a new UK sales campaign, a locally targeted platform, a recruitment drive or a data-led product feature. Bringing the assessment into market-entry and product governance means compliance teams can address the requirement before public-facing activity begins.
For organisations using AI systems, the same discipline is valuable. Where AI-enabled products profile, personalise or otherwise process UK personal data, representation analysis should sit alongside data protection impact assessments, AI system records, vendor reviews and governance controls. The question is not whether a technology is labelled AI. It is whether the processing brings the organisation within the UK GDPR's territorial reach and whether its operating model can demonstrate accountability.
A properly appointed UK representative gives overseas organisations a clear route for regulatory and individual engagement. More importantly, the work needed to support that representative creates better visibility of data processing, ownership and response capability - practical controls that make international growth more manageable.