UK GDPR Representative (Art. 27) for Swiss Companies
You process data of individuals in the United Kingdom but are not established in the UK? Then the UK GDPR (Art. 27) requires a UK-based representative. SIDD takes on the mandate through our London company, GBP 1'200 per year, ICO compliant.
GBP 1'200 / yearLondon companyICO as supervisory authority
LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)
As an admitted solicitor in England & Wales, Dr. Staiger supports third-country companies before the ICO and has handled UK GDPR mandates since it came into force in 2021.
A UK representative (Art. 27 UK GDPR) is an entity established in the United Kingdom that represents a non-UK company before the ICO and British data subjects. It is the point of contact for enquiries, keeps the records of processing activities (ROPA) on site and enables enforcement measures within the country.
Since Brexit, the UK GDPR stands on its own, analogous to the EU GDPR, it requires a local representative so that the United Kingdom can maintain data-protection standards and be treated as an equivalent third country.
Do you need a UK representative?
This obligation applies to you if the following criteria are met.
1
You have no establishment in the United Kingdom.
2
You offer goods or services to individuals in the UK or monitor their behaviour (e.g. web tracking, apps).
3
The processing is not merely occasional or involves special-category/criminal data.
4
You are not a public authority.
Fine range for non-compliance: up to GBP 17.5 million or 4% of worldwide annual turnover (Section 157 Data Protection Act 2018).
Which tasks does SIDD undertake as UK representative?
Mandate through our London company, a legal entity with a business address, not a private individual.
Designation in your privacy notice with the London business address
Receipt and forwarding of requests from the UK (ICO, data subjects)
Maintaining the records of processing activities (ROPA) in London
Initial review of authority requests and escalation to you
Optional: hourly-rate advice on specific ICO cases
Tip: Provide your own email address in your privacy notice, that way the majority of data-subject requests reach you directly. We remain the contact point for the authorities.
What happens after the engagement is awarded?
Your UK representation set up in four steps. Typical duration: 48 hours.
Contract
Digital service agreement with a clearly defined scope as representative under Art. 27 UK GDPR.
You name our London company as UK Representative in your privacy notice.
Ongoing support
Incoming requests are forwarded to you promptly and coordinated jointly.
Why SIDD?
A UK representative is your liability-relevant point of contact towards the ICO, and SIDD provides it through its own London company, run by a solicitor admitted in England.
Our own company in London
We do not designate a third-party mailbox; instead, we provide your representative under Art. 27 UK GDPR through our own British company with a registered office in London. The address listed in the ICO register and provided to data subjects is a real address controlled by us.
UK law first-hand
Dr Dominic Staiger is Solicitor in England and Wales and admitted as an Attorney at Law in New York, holding an LL.M. (Bond). Correspondence with the ICO and questions of interpretation regarding the UK GDPR and the Data Protection Act 2018 are handled by a lawyer qualified in UK law, not translated second-hand.
Mandated within 48 hours
Once instructed, we set up the representative function within 48 hours and register the address where it must be visible under Art. 27 UK GDPR. We respond to enquiries with an initial reply within 24 hours through a designated contact person.
Designated ICO point of contact
We handle the ongoing correspondence with the ICO, receive requests from data subjects, forward them to you in a structured manner and document the process. You get a dedicated contact person rather than an anonymous ticketing system.
Swiss professional secrecy
Insofar as Dr Staiger acts in a legal capacity, the mandate relationship is subject to Swiss professional secrecy under Art. 321 SCC. This is a stronger confidentiality framework than a pure mailbox provider can offer for your processing and correspondence data.
EU and UK representation combined
Since Brexit, many controllers need both an EU representative and a UK representative in parallel. We hold mandates in CH, EU, UK and US and provide both functions in a coordinated manner through our companies in Munich and London: one billing point, one contact person, fixed annual flat rates.
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For the UK representative mandate, concretely: when handling ICO inquiries and data subject requests, LexCommand keeps research scoped strictly to UK law, UK GDPR and the Data Protection Act 2018 without mixing in the EU GDPR, and ties every statement in our initial review to its exact source.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions before engaging us
What does the UK representative cost at SIDD?
GBP 1'200 per year and per represented company. Reduced group rates apply to corporate groups. No setup fee.
Do I also need an EU representative after Brexit?
Yes, if you also sell into the EEA. Since Brexit, the EU GDPR and the UK GDPR are separate legal regimes with separate representation obligations. See EU Representative, we offer both from a single source.
Who is my supervisory authority in the UK?
The Information Commissioner's Office (ICO) in Wilmslow. We are established as a representative there and are familiar with the procedures.
Can I designate a private individual as my UK representative?
In theory yes, in practice not advisable. The private contact address would then appear in your privacy notice. We designate our London Limited as a legal entity.
How quickly is the mandate set up?
Contract signing and the handover of the business details for your privacy notice take place within 48 hours of being instructed.
What happens in the event of an ICO enquiry?
We receive the enquiry, document it, carry out an initial review and agree the response with you. For complex enquiries we recommend hourly-rate advice from Dr Staiger as a Solicitor.
UK representative within 48 hours, GBP 1'200 per year.
Order online now or book a 15-minute initial consultation with Dr Staiger (Solicitor UK).