Service decision and evidence guide

Do you need an EU or UK GDPR representative?

For the EU, Article 27 links representative appointment to Article 3(2): relevant processing by an organisation outside the Union that offers goods or services to people there, or monitors behaviour there. For the UK, ICO guidance describes a separate test for organisations without a UK establishment. Check the exception before buying the service. Serving both markets requires separate assessments.

Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.

Criteria from the actual provisions

Check these differences before appointing a provider

DecisionEU assessmentUK assessment
What triggers the assessment?Processing related to offering goods/services to people in the Union, or monitoring behaviour there, by a controller or processor not established in the Union. Payment is not necessary.Based outside the UK, without a UK branch/office/other establishment, while offering goods/services to people in the UK or monitoring their behaviour there. [1] [2] [4] [5]
Public authority or body?Article 27(2)(b) separately exempts a public authority or body. Confirm that status for the organisation and covered processing.ICO lists a separate public-authority exception. Confirm the organisation’s status under the UK criteria. [2] [6]
Can occasional processing be exempt?All parts of Article 27(2)(a) must be met: occasional processing; no large-scale special-category or criminal-offence processing; and unlikely risk to rights/freedoms, considering its nature, context, scope and purpose.ICO describes the combined exception as occasional, low-risk processing without large-scale special-category or criminal-offence data. A public-authority exception is separate. [2] [6] [7]
Where can the representative be based?In a Member State where affected people whose data are processed for the offering/monitoring are located. Choose against your actual processing geography.The representative must be established in the UK. A location in an EU country does not itself satisfy this UK location criterion. [2] [8]
What are you appointing them to do?Designate in writing and mandate the representative as a contact for authorities and affected people on processing-related compliance matters.Appoint in writing and define the relationship; ICO guidance describes representation regarding UK GDPR obligations. Your own responsibility/liability remains. [2] [9] [10]

Small business size is not one of the Article 27(2)(a) exception conditions. Occasional processing alone also does not satisfy the combined test. [2]

Two distinctions that change the answer

A website visit is not the whole targeting test

EDPB guidance says mere website accessibility does not by itself establish an intention to offer goods or services in the Union. Review actual ordering, marketing and customer-location facts; behaviour monitoring is a separate trigger. [1] [11]

Representative appointment and DPO designation are separate

EU Article 37 has its own DPO criteria, including certain public-authority processing and core activities involving large-scale monitoring or sensitive/criminal-offence processing. Appointing an Article 27 representative does not decide the DPO assessment. [2] [3]

Illustrative scenarios · assumed facts

What changes between these situations?

Overseas shop with recurring EU customers

Assumed facts: Assume the business has no EU establishment, intentionally sells to people in France, and routinely processes their customer data.

What the criteria imply: Assess Article 3(2) offering-related processing. Recurring processing cannot be treated as occasional merely because the business is small; review appointment and the exact scope. [1] [2]

Overseas site with incidental EU visitors

Assumed facts: Assume only website accessibility is known; targeted offering and behavioural monitoring have not been established.

What the criteria imply: That fact alone does not settle Article 3(2). Establish targeting or monitoring facts before concluding an appointment is required or unnecessary. [1] [11]

One-off processing with an exception claim

Assumed facts: Assume Article 3(2) applies, but the business says the processing is occasional.

What the criteria imply: Check the other exception conditions as well: large-scale special/criminal data and risk to people. Record the facts supporting every part of the exception instead of selecting “occasional” alone. [2]

Your applicability worksheet

Assess EU and UK separately

Choose what you know about the covered processing. Not sure preserves an unresolved question. Results apply only to your supplied facts and need specialist confirmation.

EU assessment
Answer the questions to see a conditional result.
UK assessment
Answer the questions to see a conditional result.

Your answers stay in this browser until you choose “Prepare my project brief.” Business size is not an exception condition.

Turn the answer into a scoped appointment

Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.

  1. First: document the applicability conclusion

    For each relevant market and processing activity, record establishment, offering/monitoring and the exception result. Give the representative the conclusion and unresolved questions rather than asking for an unexplained blanket “GDPR package”.

    Useful evidence: A one-page processing/territorial-scope assessment with links to the criteria above.

  2. Then: agree the contact and escalation service

    Specify the covered entity, affected locations, representative location and written mandate. Ask who receives enquiries, how they reach your business and what response handling the contract includes.

    Useful evidence: Appointment/mandate, contact details and a responsibility/escalation matrix.

  3. Separate any additional privacy work

    Ask the provider to quote appointment separately from additional privacy documentation, transfer advice or DPO work. Confirm which deciding facts justify each extra package.

    Useful evidence: A deliverables-and-exclusions schedule, with a separate applicability decision for each additional service.

Work packages and dependencies

Questions for providers

Sources and data dates

Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.

European Union — GDPR (Regulation (EU) 2016/679) ↗

Consolidated text dated 2016-05-04 · retrieved 2026-10-06

Audit details: precise locators and snapshot identifiers

Source key D05 · snapshot 149156a8f8dfc90bead21c89c32eb84f92b7414602c3e00e058755810b48ef8a

  • [1] #art_3 · record e971d61ba2966f81cde250e8814a8e3d60e16da6212a0f1fd180e1dd9869819d
  • [2] #art_27 · record 6b75ebac1e370f3020c6d5dc7f0117ed27d1bf4a4c7c47b155b12f0c3984a10e
  • [3] #art_37 · record dc1ad79ddea7fb5e89310c3d6d0bad6f9e976a4b7cdcf387115350d3658341a0

Information Commissioner’s Office — UK representative guidance ↗

2026-01-15 · retrieved 2026-10-07

Audit details: precise locators and snapshot identifiers

Source key D17 · snapshot ef825a4a6b31ddc6fb18b78fc5fd7909275c9b08e6ad7e9e90e4f3beb4792159

  • [4] HTML li [115] · record daa5831727052dab6794b363c5c81bee468c0591a8bdcd709c04ba9ba693c2ff
  • [5] HTML li [116] · record 94e3098e878163c16a62ccd75908e9b33b6d76624c60afc4dee88511bcfd74f9
  • [6] HTML li [120] · record fd21e5ae89576be539796516a6f777d54300f0c9a2b652b09e262e1c556f8ed6
  • [7] HTML li [121] · record e02d1a4e99f867fc90d550af8aa4f3627ed0174160fdcc5b2a18bcbddd1a5842
  • [8] HTML p [125] · record 19e54cb95c3317d44cdb21bb275030adbb771f21c2688fffef8aa592cb4dbadc
  • [9] HTML p [126] · record 0a0b814e52f844f36fffa23b2b0b9b2066e62d51f1206aff4371feffcc72fd4c
  • [10] HTML p [132] · record 6761adf5a6027d5ffd45733141ebe8d660e19894694975c1dc3c09646540b9ea

EDPB territorial-scope guidance — page 17 ↗

Guidelines 3/2018 version 2.1; 2020-01-07 formatting change · retrieved 2026-10-07

Audit details: precise locators and snapshot identifiers

Source key D17 · snapshot d6910de864b8bbbdd7ed11e7509391a21ac9b627c8745dde87e8acd7c63b4862

  • [11] PDF page 17 · record cbc814429cd082497982efb0b237589e049c160d9fc0d4069b0ed35b1628b7b5

Prepare an editable project brief

Confirm the facts, scope and contact preference before sharing your project. Preparing this page sends no provider outreach.

Choose work packages to discuss

Compare GDPR Article 27 EU/UK Representative