Commonly-asked questions no.1 – “Am I exempt from having to appoint a data protection representative?”

Commonly-asked questions no.1 – “Am I exempt from having to appoint a data protection representative?”

In this series of articles we are unpacking some of the questions that we frequently get asked about the role of data protection representatives.

Here, our director Matthew Clayton answers the question “Is there an exemption I can claim from having to appoint a Representative under the GDPR?”

The requirement to appoint a representative arises under Article 27 of the EU General Data Protection Regulation (EU GDPR), and also under the same provision in the UK’s version of the same legislation (UK GDPR).

A ‘representative’ under these pieces of legislation can be referred to in a number of different ways – an Article 27 Representative, a GDPR Representative, a Data Protection Representative, an EU Representative or a UK Representative.

The rules in both versions of the GDPR are virtually the same, although the EU rules relate to the territory of the EEA (European Economic Area) member states – the EU member states plus Norway, Iceland and Liechtenstein – whereas the UK rules relate to the territory of the UK.

The first question to ask, before looking at exemptions, is whether you are even caught by the general requirement to appoint a data protection representative.

The obligation arises if you are processing data about individuals located within the territory (the EEA or the UK, as the case may be) for the purpose of offering them goods or services, and you are not yourself established in the EEA or the UK (as the case may be). (We will look at what is meant by being ‘established’ in the territory in another article.)
So, if you are established in the UK and you are only processing data about people located in the UK, you won’t need to appoint a UK Representative. Similarly, if you are established in the EEA, and you are only processing data about people located in the EEA, you won’t need to appoint an EU Representative. However, if you are only in the EEA but are processing data about people in the UK, you’ll need a UK Representative, and vice versa. And if you are located neither in the EEA nor in the UK, but are processing data about individuals there, you will need an EU Representative and/or a UK Representative, as the case may be.

If, as a result of the above, you would be required in principle to appoint a data protection representative, then there are some exemptions which might apply to you. However, they are fairly narrow.

Firstly, if you are a public authority or body, you don’t have to appoint a representative. A ‘public authority or body’ includes central and local government, and most publicly-funded bodies such as healthcare, education and the judiciary. The definition probably does not extend to private education and healthcare, especially where special category data (such as medical records) is concerned. However it’s worth bearing in mind that the definition could vary from country to country within the EEA.

 

The only other exemption exists if you can meet all the following requirements:

Under the DUAA, your internal procedure must:

  • your processing of data is only occasional
  • it does not include, on a large scale, processing of special category data or criminal offence data

AND

  • it is unlikely to result in a risk to people’s rights and freedoms.

 

Let’s look at each of these in turn

What is meant by ‘occasional’? Quite how the courts or supervisory authorities would interpret this is unclear, but it would probably be interpreted in favour of the individuals whose data you are processing. It is likely to mean something which is incidental to your business activities, or without which you wouldn’t suffer a material negative impact in your activities. In most cases, the use of personal data for business purposes will be more than ‘occasional’.

‘Special category’ data used to be referred to as ‘sensitive personal data’ and means personal data revealing racial or ethnic origins, political opinions, religious or philosophical beliefs, or trade-union membership; genetic data; biometric data for the purpose of uniquely identifying a natural person; data concerning health; or data concerning a natural person’s sex life or sexual orientation.

Neither EU GDPR nor UK GDPR define what is meant by ‘large scale’, and the European Data Protection Board (EDPB – the body consisting of all the national data protection regulators in the EU) has consistently refused to adopt numeric thresholds. Guidance endorsed by the EDPB suggests a number of factors would be relevant:

  • the number of individuals affected – either the absolute number, or the proportion of the relevant population affected.
  • the volume and/or variety of data – how much data is processed and how many categories of data items are included. For example, broad datasets covering multiple data types would point towards the processing being ‘large scale’.
  • the duration of processing – whether it is continuous, ongoing or conducted over an extended period. Long-term operations are more likely to be ‘large scale’.
  • geography – a wider geographic reach (regional, national, multinational) points to ‘large scale’. This factor in itself is almost self-proving – if you would otherwise need to appoint a representative because you are located outside the EEA or UK whilst processing data about people within the EEA or UK, you are by definition operating multi-nationally, and are therefore more likely to be deemed to be processing on a ‘large scale’ and hence not exempt.

‘Rights and freedoms’ in this context means the rights of individuals under the GDPR. Whether or not processing is likely to create a risk to these rights and freedoms is closely intertwined with the other criteria for exemption, in particular frequency, scope and nature. Because these conditions are cumulative, very few real world commercial operations qualify for exemption.

If processing is not to be viewed as posing a risk to individuals’ rights and freedoms, then after considering its frequency, scope and nature, it will have to meet the following requirements:

  • the processing presents no realistic possibility of physical, material, or non-material harm to individuals
  • the likelihood and severity of potential harm are both very low
  • the processing is limited, infrequent, and low‑impact
  • the data involved is non-sensitive and minimally intrusive
  • the activity does not meaningfully affect individuals, nor does it systematically monitor or profile them.

EDPB endorsed guidance notes that systematic or continuous data collection (e.g., website analytics, app tracking, cloud services) is already outside the scope of the exemption regardless of risk. This means only low impact, limited, irregular processing activities – such as a one off survey – are likely to pass the ‘unlikely to result in a risk’ condition.

 

Conclusion

National regulators emphasise that the Article 27 exemption is narrow. Unfortunately it is the case that most non‑EU/UK private organisations which are engaging regularly with EU/UK users will not fall within these exemptions, and will therefore need to appoint a data protection representative.

To discuss whether you need to appoint an EU or UK Representative, please contact us.