Find straightforward answers on EU/UK/Swiss representation, RoPA, and DPO

Plus tools to assess if you’re in scope.

FAQ

What’s the difference between GDPR, UK GDPR and “Applied GDPR”, and how do they relate?

GDPR (EU GDPR). This is the European Union’s data protection regulation (Regulation (EU) 2016/679). It applies across the EU/EEA and also reaches organisations outside the EU if they offer goods/services to people in the EU or monitor their behaviour (the “targeting” rule in Article 3(2)).

UK GDPR. After Brexit, the UK kept (and adapted) the EU GDPR in domestic law. This UK version — commonly called UK GDPR — mirrors the EU GDPR in structure and many duties, but is a separate legal regime, and is enforced by the UK Information Commissioner’s Office (ICO).

Applied GDPR. “Applied GDPR” isn’t a statutory title; it’s a practical shorthand some practitioners use for the UK’s post‑Brexit version of the GDPR (i.e., UK GDPR). In other words, when you see “Applied GDPR,” read it as the UK’s GDPR as it applies in the UK.

What does a GDPR Representative do?

Your EU/UK Representative is a local point of contact for data subjects and regulators. They are mandated in writing to be addressed ‘in addition to or instead of’ you on GDPR matters and hold your Article 30 Records of Processing Activity (RoPA) for inspection. Appointing a representative does not remove your own responsibilities or liability under the GDPR/UK GDPR.

See our pages about appointing us as your EU Representative, UK Representative or Swiss Representative.

Do we need a Data Protection Representative?

If you’re not established in the EU, but you offer goods/services to individuals in the EU or monitor their behaviour, and you process their personal data, you will generally need to appoint an EU Representative (with limited exceptions) under EU GDPR. Similarly, under UK GDPR, If you’re not established in the UK but offer goods/services to people in the UK or monitor their behaviour, UK GDPR requires you to appoint a UK Representative.

Try taking our self-assessment tools to see whether you might need an EU Representative and/or UK Representative, or book a free consultation.

What counts as ‘processing’ data?

Under the GDPR/UK GDPR, ‘processing’ means pretty much any operation you perform on personal data — electronic or manual — including collecting, recording, organising, storing, viewing, using, sharing, aligning/combining, restricting, deleting or destroying it. Even simply holding data in storage, backing it up, or looking at it counts as processing. The rules cover automated data (e.g., in systems, apps, email) and paper records that form part of a structured filing system.

What does ‘established’ in the EU/UK mean under GDPR?

Think “real activity, on a stable footing” — not just a postal address or a website. You’re considered established where you genuinely carry out activities on a stable basis in the EU/UK. The exact legal form (branch, subsidiary, agent, etc.) doesn’t decide it by itself. It’s also about the link between your local activity and the data processing. Regulators look at whether the processing happens “in the context of the activities” of that local presence — i.e., is there a practical, in-practice link between what your EU/UK presence does and the processing?

Simply running a website that’s visible in the EU doesn’t create an establishment. There has to be more than mere accessibility. Sometimes even a small footprint can count – in some cases, a single employee or agent working in the EU with enough stability can amount to an establishment — if the processing is closely tied to what they do locally. In short: established means you’re really operating in the EU/UK in a stable way, and your data processing is connected to those local activities.

If you’re unsure, book a free consultation.

What are Article 30 records (RoPA)? Does this mean you hold all our customer data?

Article 30 “Records of Processing Activities” (RoPA) are your internal inventory of how personal data is handled. As a data controller, you must document items such as: purposes, categories of data subjects/data, recipients, international transfers, retention periods, and a general description of security measures. Data processors have parallel recordkeeping duties about what they do for each controller. Records must be in writing (including electronic) and be available to the regulator on request. keeping duties about what they do for each controller.

No – this does not mean we hold all your customer data. As your EU/UK Representative, our role is to act as your local point of contact and to hold/produce the RoPA (i.e., metadata about your processing, not your full datasets) for supervisory authorities if requested, and to facilitate communications with data subjects. We don’t need your underlying customer databases to perform this function.

Do I need a GDPR representative if I already have a DPO? Do I need a GDPR representative if I don’t need a DPO?

No. A DPO and a Data Protection Representative are different roles with different triggers. A DPO is about internal oversight and is required mainly for public authorities or large‑scale monitoring/special‑category processing; a Representative is about territorial reach when you process EU/UK data without being established there. Having (or not having) a DPO doesn’t change the separate obligation to appoint a Representative if Article 27 applies.

See our pages about appointing us as your EU Representative, UK Representative or Swiss Representative.

Can our DPO be our Data Protection Representative?

Best practice (and regulator guidance) says no. The roles can conflict: a DPO must be independent, whereas a Representative acts on your behalf and may be addressed by authorities instead of you. Guidance from the European Data Protection Board (the body consisting of regulators in all the EU member states) (EDPB) and regulator commentary indicate the roles are not compatible for the same organisation.

Consequently, we would normally only accept an appointment as Data Protection Representative if we are not also acting as your outsourced DPO. See our pages about appointing us as your EU Representative, UK Representative or Swiss Representative.

Are there any exemptions from appointing a GDPR representative?

Yes — but they’re narrow. You don’t need a Representative if your processing is occasional, doesn’t involve large‑scale special‑category or criminal‑offence data, and is unlikely to result in a risk to people’s rights and freedoms; or if you’re a public authority or body. Most non‑EU/UK organisations engaging regularly with EU/UK users won’t meet this exemption.

If you’re unsure, book a free consultation.

Do we need a Data Protection Representative in every country where we have data subjects located?

EU: No. You appoint one EU Representative located in one Member State where the relevant data subjects are, provided data subjects in other Member States can easily reach the Representative. Best practice guidance is that if the majority of the relevant data subjects are located in one particular Member State, your Representative should also be located there.

UK: If you also process UK personal data without a UK establishment, you need a separate UK Representative (an EU Representative doesn’t cover the UK).

Where should my GDPR Representative be based?

EU: In one of the Member States where the data subjects whose data you process are located; the EDPB suggests choosing the country with a significant proportion of your data subjects to keep the contact point practical. We can advise on the optimal location for your profile.

UK: Your UK Representative must be established in the UK.

Does my Data Protection Representative need to be an individual?

No. The Representative may be an individual or an organisation established locally and designated in writing to act for you.

We are based in a country which has an ‘adequacy’ ruling from the EU about its data protection laws, or our country is covered by the data privacy framework. Do we need a Data Protection Representative?

Yes, if Article 27 applies. Adequacy (or frameworks like the EU–US DPF) concerns international transfer mechanisms; it does not change the territorial scope rule or the representative obligation for non‑EU/UK organisations that target or monitor individuals in the EU/UK. You must still appoint an EU and/or UK Representative where required.

Is the obligation to appoint a representative under Swiss data protection law the same as under EU or UK GDPR?

No – Switzerland’s rule is similar in concept but has different triggers and thresholds. Many organisations that need an EU/UK representative will only need a Swiss representative if extra conditions are also met. In practical terms, if you already have an EU and/or UK representative, you’ll only need to add a Swiss representative if your Swiss-facing processing is large scale, regular, and high risk, in addition to offering services/monitoring data subjects in Switzerland. Many organisations still choose to appoint one voluntarily for efficiency and clarity with the FDPIC (the Swiss regulator) and data subjects.

Need help deciding? We can quickly triage your EU/UK/Swiss exposure and tell you whether a Swiss representative is mandatory or advisable in your case. Contact us for further help.

Do you support clinical trial sponsors?

Yes. Willans DPS is a leading provider of EU/UK Representative services to clinical trial sponsors worldwide and can work with Willans LLP on consent forms, DPAs, governance, and outsourced DPO arrangements. See our services for the bio-sciences sector.

Do you support sporting organisations and federations?

Yes. Many international federations process substantial personal and sensitive data (performance monitoring, youth events, health measures), often without an EU/UK establishment. Willans DPS provides EU/UK Representative solutions for this sector – see our services.

Who are Willans Data Protection Services and how do you work with Willans LLP?

Willans Data Protection Services (Willans DPS) is a specialist provider of GDPR and NIS compliance services — including EU/UK Representative solutions, DPO services, and training. The business is affiliated with UK law firm Willans LLP, enabling you to access broader legal advice (audits, policies, contracts, bespoke advice) alongside representative/DPO services.

Are you regulated by the UK Solicitors’ Regulation Authority (SRA)?

Willans DPS is not regulated by the SRA. Its affiliated firm, Willans LLP, is authorised and regulated by the SRA (ID 488471).

Still have a question?

No problem. Send us a message and we will get back to you.