
The Post-Brexit Reality of Dual GDPR Obligations
Many UK leaders still believe UK GDPR compliance is enough. It is not. The UK and the EU now run two separate legal regimes. Consequently, a UK firm can comply fully at home and still breach EU law.
According to the ICO, 25% of UK organisations are unaware of data protection registration requirements. If that many miss a domestic duty, cross-border duties are easier to overlook.
The reason lies in Article 3(2) of the EU GDPR. This provision gives the regulation extraterritorial reach. It applies to organisations outside the EU that offer goods or services to people in the EU. It also applies to those that monitor their behaviour. Where it applies, Article 27 requires a written appointment of an EU representative.
In short, the obligation follows your customers, not your head office. Therefore, UK firms with European audiences must act deliberately.
Trigger Conditions: Does Your Organisation Need a Representative?
Start with a simple diagnostic. Ask whether your organisation targets people in the EU. Then ask whether you track what those people do online. A "yes" to either question deserves immediate attention.
First, consider "offering goods or services". Payment is not required. A free app, a free trial or a free download can qualify. Moreover, the EDPB Guidelines 3/2018 point to practical signals. These include EU currencies, local languages, EU delivery options and marketing aimed at EU residents.
Second, consider "monitoring of behaviour". This covers behavioural advertising, cookie-based profiling and website analytics that follow EU visitors. Similarly, location tracking and online personality profiling count.
The EDPB treats intent as the key test. Mere accessibility of your website from the EU is not enough.
Exceptions exist, but they are narrow. Article 27(2) exempts processing that is occasional. The processing must also avoid large-scale special category or criminal data. Finally, it must be unlikely to risk individuals' rights. Few multinational firms meet all three conditions. Accordingly, most should assume the duty applies.
The Financial Risk of "Data Inadequacy"
Legal theory becomes real once money enters the picture. Consider the wider context. The EU currently treats UK data protection as adequate. That status lets personal data flow freely from the EU to the UK. However, adequacy is not permanent. It remains subject to review.
The stakes are high. The European Parliament estimates that losing adequacy could cost UK firms between £1 billion and £1.6 billion. That figure reflects extra legal tools, contract work and compliance overhead. Furthermore, it excludes the revenue lost when European customers hesitate.
Awareness remains low. As noted, 25% of UK organisations are unaware of data protection registration requirements, per the ICO. Representation duties are even less visible. Consequently, many boards have never priced this risk.
An EU representative works as a bridge. It does not replace adequacy. Nevertheless, it shows regulators that your organisation takes EU obligations seriously. It also gives them a local contact. That reduces friction when questions arise. Ultimately, it protects the revenue your European customers generate.
Operationalising Article 27: Beyond the Paperwork
Many organisations treat the representative as a name on a form. That approach is risky. A representative is a working point of contact. Supervisory authorities and data subjects can approach them directly. In addition, the appointment must be backed by a written mandate.
In practice, the role carries real duties. The representative receives regulator enquiries and passes them on promptly. They also help you respond. Moreover, they keep a Record of Processing Activities (ROPA) for your organisation, as Article 30 requires. A thin "mailbox" service cannot do this well.
Location matters too. Article 27(3) requires the representative to be established in a Member State where affected individuals are located. A representative in the wrong country may fail the test. Therefore, map your EU audience first. Then choose the Member State.
Scale raises the bar further. The UK Government's Department for Business and Trade reports that 12% of UK businesses collecting digitised data transfer it internationally. For multinationals, the true figure is far higher. Data flows between many entities, vendors and systems. Consequently, a representative needs to understand your operations, not just your address.
For this reason, a responsive and knowledgeable representative is worth more than a cheap one. You can see how this works in practice through our EU and UK representative services.
Common Compliance Pitfalls for UK Multinational Firms
Experienced teams still make avoidable mistakes. Four stand out.
Confusing a DPO with an EU representative. These roles are legally distinct. The DPO monitors compliance and advises the organisation. The representative acts as a contact point for authorities and individuals. Importantly, the DPO must operate independently. Combining the roles can create conflicts of interest. Do not assume one appointment covers both.
Forgetting to update privacy notices. Articles 13 and 14 require you to identify your representative. Many firms appoint one but never amend their notices. As a result, they remain non-compliant. Review every notice, including cookie and recruitment notices. Our guide to privacy policy updates can help.
Appointing a representative in the wrong place. Some firms pick a country for convenience. Yet the location must reflect where their data subjects live. Revisit this choice whenever your market footprint changes.
Ignoring Switzerland. The revised Swiss FADP can require a Swiss representative from some foreign controllers. Its logic closely mirrors the EU GDPR. Therefore, treat Swiss exposure as part of the same exercise. Otherwise, a gap may remain even after your EU appointment.
The Bottom Line: UK-EU Compliance Checklist
Boards need clarity, not complexity. These takeaways summarise the position.
- UK companies that target EU markets or monitor EU individuals must appoint an EU representative under Article 27.
- UK GDPR compliance does not exempt a firm from its EU GDPR obligations.
- Failure to appoint a representative risks regulatory fines and can disrupt international data transfers.
- A DPO and an Article 27 representative are different roles and should not be treated as interchangeable.
- Managed services such as Formiti Consulting bridge the gap between legal theory and operational reality.
Taken together, these points show a clear pattern. The risk is predictable. The fix is also predictable.
Securing Your European Market Access with Formiti
Article 27 is a small appointment with large consequences. Handled well, it protects your European revenue. Handled poorly, it exposes you to enforcement and operational disruption.
At Formiti Consulting, we approach this as an operational discipline. Our method rests on three teams working together.
The Three-Team Methodology: legal consultants interpret the law for your business. Privacy architects design the governance around it. Technical operations teams keep it running day to day.
Additionally, the Privacy360 platform keeps your records organised and audit-ready. Your ROPA, your notices and your regulator correspondence sit in one place. As a result, you can answer questions quickly and evidence your compliance.
Your next step is simple. Review whether Article 3(2) applies to you. Then confirm that your representative is real, local and responsive. Move from regulatory complexity to operational confidence by speaking to our EU representative team today.