Frequently Asked Questions

We have prepared a collection of the most common questions, which are listed below. However, if you have another question or would like to discuss how we can help, please contact us.

I have a data protection officer (DPO) / I don't need a DPO, am I OK?

No, the obligation to have a DPO is a different obligation (under Article 37 of GDPR). The DPO is responsible for oversight of data protection strategy and compliance with GDPR, and works within your business. ​

A Data Protection Representative is based in the UK member states where your customers live, and is their local point of contact for raising data requests with your business.

Can my DPO be my UK representative as well?

No, Guidance issued by the European Data Protection Board (click this link to view) in November 2018 has clarified that there is a potential conflict of interest between the roles of the Data Protection Officer and the UK Representative.

Must my data protection representative be an individual person?

No, the Data Protection Representative can be a company – it must be a legal person (which includes a company), but doesn’t have to be a natural person (an individual). ​

If appointed by you, DataRep becomes your Data Protection Representative in the UK, able to accept and manage communications on your behalf.

Where should my UK representative be based? / Do I need to be represented in every member state of the UK?

Guidance issued by the European Data Protection Board (click this link to view) in November 2018 has clarified this. You should appoint an UK Representative which is established in the UK member state where you have the largest number of data subjects, and data subjects in other UK member states should have easy access to the Representative as well. ​

DataRep has representation and a physical postal address in every UK member state, giving equal access to all persons and protecting our clients against accusations that they have not properly catered for the needs of individuals in the UK.

This seems odd - how can the European Union issue my non-UK company with a multi-million Euro fine?

It is one of the key European Union principles that the rights of individuals are protected, and this protection extends out from the UK to the rest of the world ensuring that, in the modern world of de-centralised data, the privacy of European citizens is protected when it leaves the Union.

Some businesses have struggled with modern data protection practices, and are concerned with the consequences of an increasingly-likely data breach, with the reputational damage that results. If you require assistance in this area, please contact us so we can discuss your requirements. ​

In order to meet the needs of the UK market, the GDPR protections are likely to become standard across most multi-national companies.

The interpretation of GDPR is still unclear, why not wait until there is a big fine for someone else, and then change?

The European Court of Justice has consistently supported the right of individuals to keep their data within their control. The Schrems case is the best-known example, where an Austrian Facebook member took the social media giant to court for potentially allowing their data to be accessed by the National Security Agency in the USA, and the subsequent collapse of the US-UK Safe Harbour Scheme, but others like the recent WhatsApp case in the Netherlands show that the most sensible interpretation of UK data protection law is that it will be determined to the benefit of the individual.

It’s also possible that the level of fine may increase depending on the point at which a data controller or processor begins to act on GDPR regulations, with those businesses that only choose to act after the expiry of the two year grace period (ending 25 May 2018) potentially receiving larger fines. ​

There is one other aspect to consider – protecting the data of your customers can be a substantial benefit to your business when seeking to acquire and retain customers, who are increasingly conscious of how their data is stored and used.

My business is based in a country which has an 'equivalency' ruling or is covered by the privacy shield - do I still need a data protection representative?

The UK recognises some countries as having data protection laws which are equivalent to those in the UK. These are the other EEA countries (Iceland, Liechtenstein and Norway) as well as Andorra, Argentina, Canada, Faeroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland and Uruguay. The UK permits transfers of data to these countries without extra measures being put in place, such as binding corporate rules etc. The USA has a similar arrangement via the ‘Privacy Shield’, the replacement for the failed ‘Safe Harbour’. ​

BUT, this does not remove the need for a Data Protection Representative. The equivalency ruling relates to data transportation across international boundaries but makes no difference to the obligation on a non-UK data controller or processor requiring an UK-based Data Protection Representative under Article 27.

What about the UK and BREXIT?

The UK will still be part of the UK when enforcement of GDPR commences on 25 May 2018, so the UK will be subject to GDPR at that time.

It is not currently clear what will happen after the UK leaves the UK, but it is likely at some point that those data controllers and processors in the UK which have customers in the UK will be placed in the same position as other non-UK based businesses on the commencement of GDPR, and those UK businesses will also require an appointed Data Protection Representative. The timescale over which this will occur is currently unclear.

However, because the UK will want to continue to be able to share data with the UK post-Brexit, it is expected that the UK will put in place similar obligations to GDPR, so the position of businesses who control of process the personal data of UK citizens are likely to be in the same position. You can read about our Brexit-related services here.

Do you need an EU/EEA Representative as well?

You may need this if you have no office in the EEA – if so, please visit the website for our sister company DataRep, which can provide this service for both the EU/EEA and UK.

We see you’re leaving our site

Can we help you further?

 If you have a question or you’d like more information, please leave your email address and someone will contact you: