UK Data Protection Representative Program

A simple, professional, and cost-effective way to satisfy the requirements of Article 27 of the General Data Protection Regulation of the United Kingdom (UK GDPR).

As of January 1, 2021, businesses without a physical presence in the UK are required to appoint an official Data Protection Representative in the UK.

VeraSafe has served as a trusted data protection representative for hundreds of clients, both under the EU General Data Protection Regulation and the UK GDPR post-Brexit. Our team of experienced attorneys is highly knowledgeable in the complexities of UK data protection law, which is why several of the world’s largest law firms refer their clients to VeraSafe for representative services. The VeraSafe UK Data Protection Representative Program provides a straightforward, professional, and cost-effective solution to ensure compliance with Article 27 of the UK GDPR.

Easy UK GDPR Compliance Solution

Comply with UK GDPR Article 27 requirements without establishing a physical presence in the UK.

Administered by Professionals

Our program is administered by attorneys and privacy professionals.

Cost-Effective

Initial enrollment fees are fixed and competitive.

Thank You

Thank You!

We’ll be in contact shortly.

UK Data Protection Representative Program Overview

As part of your enrollment, VeraSafe will:

  • Act as your official data protection representative in the UK;
  • Provide a web form, mailing address, and phone number for UK data subjects and regulators to use when contacting your organization;
  • Guide you on how to properly publish our contact details in your privacy notice;
  • Serve as a point of contact for regulators and data subjects on issues related to personal data processing;
  • Receive communications from the Information Commissioner’s Office (ICO) and data subjects and relay them back to your organization;
  • Help ensure that your organization complies with regulatory notification timelines established under data protection and privacy law in the UK;
  • Provide your organization with a website trust seal that visitors can click to verify your participation in the program.

Click to view verification page example

VeraSafe UK Data Protection Representative Program Pricing

Your Total Sales* Annual Enrollment Fee
Over $0 to $25 million $1,200.00
Over $25 to $50 million $2,700.00
Over $50 to $100 million $4,050.00
Over $100 to $500 million $5,400.00
Over $500 million Contact Us for Custom Quote

*Note: Fees are based on gross global revenue (USD), and generally provide coverage for a single covered entity. Additional covered entities may be included at no additional fee in limited circumstances.

UK DPR program

Do I need a UK Data Protection Representative?

  • Is your company located outside of the UK with no physical presence there?
  • Does your company process personal data in the course of offering goods or services to individuals in the UK, or does it monitor the behavior of individuals in the UK, including through online tracking and profiling such as tracking cookies?
  • If you answered “Yes” to both questions, you are required to appoint a Data Protection Representative under Article 27 of the UK GDPR. There are exceptions to this requirement. We recommend scheduling a free consultation to evaluate your specific obligations.
Other services we provide

In addition to serving as your organization’s UK DPR, our experienced attorneys and privacy consultants can help you by:

  • Establishing, maintaining, and reviewing your records of processing activities (RoPA).
  • Ensuring that your privacy notices include the information required by the UK GDPR and the UK Data Protection Act 2018.
  • Providing counsel and advice in your responses to data subject access requests (DSARs) and queries from the UK’s data protection authority, the Information Commissioner’s Office (ICO).
  • Informing you about relevant data protection issues.
UK Data Protection Representative

When you appoint VeraSafe United Kingdom as your organization’s UK Data Protection Representative, you take a critical step towards compliance with UK data protection law. Let VeraSafe help you respond to any UK data protection inquiries in a lawful, fast, and professional manner.

This UK GDPR requirement to appoint a Data Protection Representative is nearly identical to the EU GDPR’s requirement for organizations not located in the European Economic Area (EEA) to appoint a Data Protection Representative.

Click here to learn more about VeraSafe’s EU Data Protection Representative Program for Article 27 of the EU GDPR, which complements the VeraSafe UK Representative Program for the UK GDPR.

Frequently Asked Questions

What is the difference between a Data Protection Officer (DPO) and a Data Protection Representative (DPR)?

A Data Protection Officer (DPO) is a role mandated under Article 37 of the GDPR (or UK GDPR). Organizations must appoint a DPO if:

–  The core activities of the controller or the processor consist of processing operations which require regular and systematic monitoring of data subjects on a large scale;

–  The core activities of the controller or the processor consist of processing on a large scale of special categories of data or personal data relating to criminal convictions and offenses;

–  The processing is carried out by a public authority or body.

The DPO monitors compliance with the GDPR (or UK GDPR), and, if applicable, EU Member state data protection laws; oversees data protection strategies, and acts as a key contact for data subjects and regulators. In contrast, a Data Protection Representative (DPR) is a local representative required under Article 27 of the GDPR (or UK GDPR) for organizations not established in the EU or UK. The DPR serves as a point of contact for regulators and data subjects in the relevant jurisdiction. However, the DPR’s role is narrower in scope and does not include the extensive responsibilities of a DPO. Visit our Data Protection Officer Service page to learn more about outsourcing a DPO.

Why should I choose VeraSafe’s UK Data Protection Representative Program?

VeraSafe stands out as one of the few well-established privacy law firms and consulting groups offering UK Data Protection Representative services in full compliance with applicable legal requirements. VeraSafe United Kingdom Ltd is fully established in the UK. With over a decade of experience, our team of privacy attorneys supervises and coordinates all aspects of our DPR services, ensuring a professional and compliant solution.

What is included in the enrollment fee?

The enrollment fee includes the formal appointment of VeraSafe as your Data Protection Representative in the UK. You will be entitled to publish VeraSafe’s DPR contact information in any appropriate location, including your privacy notices. Regulators and data subjects can contact VeraSafe in addition to, or instead of, contacting your organization directly. VeraSafe accepts legal liability when serving as the Data Protection Representative of a foreign organization, and the enrollment fee primarily compensates VeraSafe for that risk.

Are there exceptions to the requirement to appoint a Data Protection Representative in the UK?

Every organization’s circumstances are unique. We recommend contacting VeraSafe for assistance in interpreting the UK GDPR and understanding how its requirements apply to your organization. The information provided here is not legal advice and should not be relied upon as such, as it does not account for your specific circumstances.

What additional steps are required to comply with the UK DPR requirement after enrolling?

After signing the enrollment documentation provided by VeraSafe, we will prepare a paragraph of text for inclusion in your organization’s privacy notice. This disclosure, required under Article 27 of the UK GDPR, should be added to all privacy notices that address UK data subjects.

What are the risks of not appointing a UK Data Protection Representative?

Failing to designate a representative in your public-facing privacy notice is a clear sign of noncompliance with the UK GDPR. This may draw the attention of the Information Commissioner’s Office, which oversees data protection and privacy regulation in the UK.

If my organization is based in the UK, do I need to appoint a Data Protection Representative?

Organizations based in the UK are not required to appoint a UK Data Protection Representative. However, UK-based organizations without a subsidiary or branch office in the European Union may need to appoint a Data Protection Representative in the EU. For complete compliance with GDPR Article 27, please refer to VeraSafe’s EU Data Protection Representative Program.

How can regulators and data subjects contact VeraSafe in the UK?

Regulators and data subjects can reach VeraSafe via our web contact form, telephone, or mailing address in London. These details will be provided upon enrollment.

Will VeraSafe respond to regulators or data subjects without consulting me?

Usually not. VeraSafe will receive, relay, and, only after consultation with you, respond to any communications from regulators or data subjects. If required, we can deliver legal counsel on demand to assist you in responding to such inquiries. However, there are some circumstances where it is necessary for VeraSafe to contact the requestor directly, for example if the data subject does not indicate which VeraSafe client their concern relates to, it is necessary for VeraSafe to contact the data subject to ascertain this critical information.

How can I appoint VeraSafe as my UK Article 27 Data Protection Representative?

1. Click “Enroll Now” and submit the necessary information.

2. VeraSafe will send your enrollment paperwork via email.

3. VeraSafe will contact you to provide all of the information needed to implement VeraSafe’s Data Protection Representative program in your organization. Implementation usually takes one business day.

Does VeraSafe have expertise in data protection law?

Yes. VeraSafe’s expertise lies at the intersection of law and information technology. Our multidisciplinary team includes data protection attorneys, privacy professionals, alumni of the European Data Protection Board, project managers, and IT security experts. Many team members hold certifications from the International Association of Privacy Professionals.

Additionally, VeraSafe’s UK DPR services can be complemented by our comprehensive privacy and data protection compliance services.

Where can I find the terms of service for VeraSafe’s UK Data Protection Representative Program?

To review the service terms for our UK Data Protection Representative program, please contact us. VeraSafe’s legal department will promptly send you the service terms.

What documentation is required to demonstrate compliance with the UK GDPR/Data Protection Act 2018? Does VeraSafe audit clients?

VeraSafe does not conduct proactive audits of our UK DPR clients for compliance with the UK GDPR. Currently, no formal certification exists to demonstrate compliance with the UK GDPR or the Data Protection Act 2018. However, if you wish to engage VeraSafe for assistance with UK GDPR compliance, we would be pleased to discuss your specific needs. Please contact us for further details.

UK DPR Service

Immediately Comply With Your Obligation To Appoint a Data Protection Representative in the UK

Key contacts

Matthew Joseph

Matthew Joseph

CIPP/E, CIPP/US, CIPM, FIP

Managing Director

Jim Cormier

Jim Cormier

CIPP/E, CIPM, FIP

Senior Vice President and Head of Professional Services

Do I Need Both an EU and a UK Data Protection Representative?

Do you target individuals
in the UK only?

Do you target individuals
in the EEA only? (i.e., not UK)

Do you target individuals
in the EEA and the UK?

Are you established
in the UK only?

No DPR required EEA DPR Required EEA DPR Required

Are you established
in the EU only?

UK DPR Required No DPR required UK DPR Required

Are you established only
outside of the UK and EU?

UK DPR Required EEA DPR Required Both EEA & UK DPR Required

Professional UK Data Protection Representation

Immediately comply with your obligation to appoint a Data Protection Representative in the UK.

Why VeraSafe?

Track record of successful GDPR implementations across industries.

Holistic approach: Our broad expertise ranges from privacy law to cybersecurity operations.