# EU Representative vs UK Representative, Which One Do You Need?

> EU Representative vs UK Representative, when does a Swiss or US company need which mandate? Comparison table, costs, duties and 2026 practitioner guide.

- Source: https://www.sidd.swiss/en/insights/eu-vs-uk-representative/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-06-18
- Author: Dr. Dominic Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## What is this about?

Companies without an establishment in the EU or in the UK have been required, since the entry into force of the GDPR (Art. 27 GDPR) and the UK GDPR (Art. 27 UK GDPR), to designate a domestic representative whenever they offer goods or services to individuals in those markets or monitor their behaviour. Swiss companies, US providers and corporate groups from APAC are the typical target audience. The EU Representative and the UK Representative are two distinct mandates with different supervisory authorities and different language regions, even if the function appears identical on the surface.

## Direct comparison at a glance

| Dimension | EU Representative (Art. 27 GDPR) | UK Representative (Art. 27 UK GDPR) |
| --- | --- | --- |
| Legal basis | Art. 27 GDPR (Regulation 2016/679) | Art. 27 UK GDPR (Data Protection Act 2018, retained EU law) |
| Geographic scope | EU + EEA (Norway, Iceland, Liechtenstein) | England, Wales, Scotland, Northern Ireland |
| Supervisory authority | Lead supervisory authority in the EU Member State of the representative | ICO (Information Commissioner's Office) |
| Required for | Non-EU controllers that offer goods or services to individuals in the EU or monitor their behaviour | Non-UK controllers that offer goods or services to individuals in the UK or monitor their behaviour |
| Language of communication | Language of the EU Member State (English often accepted) | English |
| Duty to designate | Mandatory, unless the exemption under Art. 27(2) GDPR applies | Mandatory, with a comparable exemption under the UK GDPR |
| Possible fines for non-appointment | Up to EUR 10 million or 2% of global annual turnover (Art. 83(4) GDPR) | Up to GBP 8.7 million or 2% of global annual turnover (DPA 2018) |
| Typical annual cost | from CHF 600 / year (SIDD standard package) | from GBP 1,200 / year (SIDD standard package) |
| Data transfer implication | No additional transfer, the representative is located in the EU | No additional transfer, the representative is located in the UK |

## When do you need an EU Representative?

You need an EU Representative if all three conditions are met: (1) your company has no establishment in the EU or in the EEA; (2) your company offers goods or services to individuals in the EU or monitors their behaviour; (3) no exemption under Art. 27(2) GDPR applies (occasional processing without sensitive data and without significant risk).

Concrete triggers are a German-language or multilingual web shop with EU delivery addresses, a SaaS offering with active customer acquisition in the EU, EU-specific marketing campaigns, or tracking cookies that profile EU visitors. Swiss companies are the largest target group by number, because Switzerland is a third country under data protection law, a Swiss establishment does not satisfy the EU establishment requirement.

Public authorities are exempt, as are companies whose EU exposure is purely occasional and does not involve special categories of personal data. The exemption is to be interpreted narrowly; in case of doubt, designation is the safer route.

## When do you need a UK Representative?

With Brexit, the UK has become a third country under data protection law vis-à-vis the EU, and vice versa. A UK Representative is required if your company has no UK establishment and offers goods or services to individuals in Great Britain or monitors their behaviour.

Common triggers include: an e-commerce offering with UK shipping, an English-language marketing pipeline with UK targeting, B2B SaaS with British customers, or digital services that track UK IP addresses. Companies with an EU establishment also need a **separate** UK representation, the EU establishment does not satisfy the UK obligation.

The ICO is more conservative in its interpretation of "occasional processing" than some EU supervisory authorities. If you regularly serve UK customers, the obligation must as a rule be affirmed.

## Do I need both in parallel?

Yes, as soon as you are active in both the EU and the UK. The EU Representative and the UK Representative are two independent mandates supervised by two different authorities (the EU Member State authority and the ICO). SIDD takes on both mandates jointly, so that you have only one contractual relationship while being correctly represented before both supervisory authorities. Synergies exist above all in a shared privacy notice, the record of processing activities and incident-response communication.

## What does a SIDD mandate deliver in practice?

In the standard package, SIDD takes on the formal designation vis-à-vis the supervisory authority, inclusion in the record of processing activities (Art. 30 GDPR and UK GDPR respectively), correspondence with the supervisory authority, the handling of data subject requests, and the ongoing availability of a named point of contact. The premium package adds DPIA advisory services, an annual compliance review and emergency support during data breaches.

Operational handover is typically possible within 48 hours of contract signature. We update your privacy notice with the representative's contact details and provide the appointment document for your internal compliance records.

## Frequently asked questions

**Can a Swiss establishment satisfy the EU representation requirement?** No. Switzerland is treated as a third country under data protection law. An establishment in the EU within the meaning of the GDPR requires the effective activity of an employee or representative on EU territory, a Swiss business address is not sufficient.

**What happens without an EU Representative or UK Representative?** The supervisory authorities can open investigations, impose fines (up to EUR 10 million or 2% of global turnover) and prohibit processing. In practice, escalation by data subjects or competitors who report the absence of a representative as a breach is more common.

**Who bears liability, the controller or the representative?** Primary liability rests with the controller. The representative is the point of contact and correspondent; joint liability is not expressly excluded under Art. 27(5) GDPR, but in CJEU practice to date it has been narrowly contained.

**Can we appoint the EU Representative from within our own group?** Yes, provided a group company is based in the EU and formally assumes the representative role. The separation between operational duties and the representative role must be documented. External representation is frequently chosen because supervisory authorities perceive an external specialist as more independent.

**How quickly does the designation become effective?** As soon as the privacy notice names the representative and the internal record of processing activities has been updated. SIDD can typically complete these steps within 48 hours of contract signature.

## How SIDD supports you

SIDD is the consulting brand of Priverion GmbH (Baar/ZG) and takes on both the [EU Representative mandate under Art. 27 GDPR](https://www.sidd.swiss/en/services/eu-representative) and the [UK Representative mandate](https://www.sidd.swiss/en/services/uk-representative). For companies with a dual obligation we offer a bundled contractual solution. If you also need an [external Data Protection Officer](https://www.sidd.swiss/en/services/data-protection-officer-eu), we take on that mandate in personal union as well. For the Swiss perspective, see our in-depth [Article 27 GDPR compliance guide](https://www.sidd.swiss/en/insights/article-27-gdpr/).

## Cited legislation and sources

- Art. 27 GDPR
- Art. 27(2) GDPR
- Art. 27(5) GDPR
- Art. 30 GDPR
- Art. 83(4) GDPR
- Art. 27 UK GDPR
- Data Protection Act 2018 (UK)

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
