Do I need an EU representative under GDPR if I'm UK-based?
An EU customer's procurement team sends over a data processing due diligence form, and buried in it, after the usual questions about encryption and sub-processors, is a field asking for the name and contact details of your Article 27 representative in the EU. Or an EU-based data subject emails a rights request to your general enquiries inbox, and someone on your team, quite reasonably, isn't sure which country's authority that should even be flagged to. Both moments are pointing at the same gap: UK companies whose activity reaches into the EU often need a formally appointed EU representative, and most don't have one, because nobody told them the requirement survived Brexit and now applies to them specifically.
The starting point: are you even in scope for EU GDPR at all
The representative question only arises once you've established that EU GDPR applies to some part of your business in the first place, under Article 3(2)'s test for offering goods or services to, or monitoring the behaviour of, people in the EU. A UK company whose activity is entirely UK-facing doesn't need an EU representative, because EU GDPR was never in scope for that company to begin with. Assuming that question is already answered yes for at least part of your business, Article 27 of the EU GDPR requires you, as a controller or processor established outside the EU but subject to EU GDPR under Article 3(2), to appoint a representative established in one of the EU member states where the individuals whose data you process are located.
What the representative actually does, and doesn't do
The representative is a formally designated point of contact in the EU, addressed by EU supervisory authorities and by data subjects in addition to, or instead of, the UK company itself. It's not a rubber stamp and it's not a shell appointment: Article 27(5) makes clear the representative can be addressed by any EU supervisory authority and by data subjects on all issues related to processing, and can be the subject of enforcement proceedings. What it doesn't do is take on your compliance obligations for you, or dilute your own accountability as controller or processor. Appointing a representative gives EU regulators and individuals a real point of contact inside the EU; it doesn't hand off responsibility for actually complying with EU GDPR.
The narrow exemption, and why most companies shouldn't assume it applies to them
Article 27(2)(a) exempts processing that is occasional, doesn't include large-scale processing of special categories of data or data relating to criminal convictions, and is unlikely to result in a risk to the rights and freedoms of individuals, taking into account its nature, context, scope, and purposes. That's three conditions, not one, and all three have to hold. A UK SaaS company with a steady, ongoing base of EU subscribers doesn't meet "occasional" no matter how low-risk the processing feels day to day. A UK e-commerce business shipping regularly to EU customers is, by definition, running recurring rather than occasional processing of their data. The exemption is genuinely narrow, and it's aimed at edge cases, a one-off EU visitor to a UK-only service, not at businesses with an established EU customer base. Treating it as a default "we're probably fine" is the mistake that tends to surface only when a regulator or a customer's due diligence team actually asks the question directly.
A separate, related duty under the AI Act
If your business is a provider of a high-risk AI system, or of a general-purpose AI (GPAI) model, and you're established outside the EU but placing that system or model on the EU market, the EU AI Act imposes its own representative requirement under Article 22, distinct from the GDPR's Article 27 duty. The two obligations run on separate legal bases, cover different subject matter, GDPR's representative deals with personal data processing, the AI Act's deals with AI system and model conformity, and in practice will often need to be separate appointments rather than one person or firm wearing both hats by default. A UK company that's only a deployer of AI tools built by someone else generally doesn't trigger the AI Act's Article 22 duty; it's aimed specifically at providers placing high-risk AI systems or GPAI models on the EU market. If that's your business, though, assuming your GDPR representative covers the AI Act angle too is the same category of mistake as assuming UK GDPR covers EU GDPR: related regimes, separate obligations.
What to check before you decide you don't need one
- Have you established, separately and explicitly, that EU GDPR applies to at least part of your processing under Article 3(2), rather than assuming the representative question is moot?
- Is your EU-facing processing genuinely occasional, or is it an established, recurring part of how your business operates, even at modest volume?
- Does that processing involve large-scale special category data or criminal conviction data, which would rule out the Article 27(2)(a) exemption regardless of how occasional it otherwise is?
- If you do need a representative, have you chosen the EU member state correctly, based on where the affected individuals are located, rather than picking one arbitrarily for convenience?
- Are you a provider of a high-risk AI system or a GPAI model placing that system or model on the EU market, which would trigger a separate Article 22 AI Act representative duty on top of any GDPR one?
- Does your customer-facing privacy notice actually name your EU representative, where one is required, rather than listing only a UK contact?
General information, not legal advice: whether the Article 27 exemption applies to your specific processing, and whether the AI Act's Article 22 duty applies to your specific product, depends on facts about your business that a general article can't establish for you. Where Komplya publishes guidance like this, we're clear about which layers have been legally reviewed and which remain draft material, so you can weigh it accordingly.
Rather than guessing at whether your EU-facing processing counts as occasional, the more useful step is to work through your actual data flows and AI systems against both tests. Answer a short questionnaire on your business and get a plain-language read on whether you need an EU representative under GDPR, under the AI Act, or both.