04 Aug Commonly-asked questions no.5 – “What does a GDPR Representative do?”
In this series of articles we are unpacking some of the questions that we frequently get asked about the role of data protection representatives.
Here, our director Kym Fletcher answers the question: “What does a GDPR Representative do?”
The requirement to appoint a GDPR Representative is often misunderstood as a technical formality. In practice, the role serves a specific regulatory purpose within the GDPR framework: ensuring that supervisory authorities and data subjects have an effective point of contact where an organisation has no establishment within the relevant jurisdiction. Understanding what a GDPR Representative does — and does not do — is essential for organisations operating cross border.
The obligation to appoint a GDPR Representative arises under Article 27 GDPR (and its equivalent under the UK GDPR). It applies where an organisation:
- is not established in the EU or UK, but
- processes personal data of individuals located there, and
- does so in connection with offering goods or services to those individuals, or monitoring their behaviour.
The requirement is jurisdiction specific. Organisations targeting individuals in both the EU and the UK may need to appoint separate representatives for each regime. While limited exemptions exist, the starting assumption for many international organisations is that a GDPR Representative will be required, if the above conditions apply.
A GDPR Representative acts as a local interface between the organisation and the regulatory ecosystem in which the data subjects are located. The role is representational rather than managerial. The representative does not control processing, determine purposes, or make compliance decisions. Instead, the function is grounded in accessibility and accountability.
The appointment must be formalised in writing and made transparent through inclusion of the representative’s contact details in relevant privacy notices.
One of the GDPR Representative’s primary tasks is to act as a point of contact for supervisory authorities. This includes receiving communications, responding to enquiries, and facilitating regulatory engagement.
The representative must be able to liaise effectively with regulators, ensuring that information requests or investigative correspondence are transmitted promptly to the organisation. Although enforcement action is directed at the controller or processor, the representative ensures that the organisation is reachable and responsive within the jurisdiction.
GDPR Representatives also serve as a contact point for individuals whose personal data is processed. This typically involves receiving correspondence relating to data subject rights, such as access, rectification, or erasure requests.
The representative’s role is not to decide how those requests are handled, but to ensure they are received and forwarded securely to the relevant controller or processor so that they can be addressed in accordance with the GDPR’s requirements and timescales. This supports the GDPR’s objective of ensuring individuals are not disadvantaged by an organisation’s geographic distance.
Article 27 requires GDPR Representatives to hold a copy of the organisation’s records of processing activities under Article 30, insofar as they relate to the processing that triggers the representative requirement.
These records must be made available to supervisory authorities on request. The representative therefore plays a role in operational transparency, even though responsibility for maintaining records accurately remains with the organisation.
The GDPR Representative role is frequently confused with that of a Data Protection Officer (DPO). The two serve different legal purposes.
A DPO is required based on the nature and scale of processing activities. A GDPR
Representative is required based on geographical establishment. An organisation may require one, both, or neither, depending on its circumstances. Combining the roles is generally inappropriate, as they exist to address different regulatory concerns.
The GDPR Representative must be established in:
- An EU Member State where affected data subjects are located, for EU GDPR purposes; or
- The UK, for UK GDPR purposes.
The establishment must be genuine and capable of fulfilling the role in practice, not merely nominal.
While the GDPR Representative role is limited in scope, it has practical significance. Failure to appoint a representative where required is itself a breach of GDPR. More broadly, the effectiveness of the representative can influence how smoothly regulatory engagement and rights handling operate in practice.
For organisations operating internationally, the appointment of a competent GDPR Representative is an essential component of lawful and transparent processing arrangements.