Service Overview

UK GDPR Representative (Article 27)

The UK GDPR came into force on 1 January 2021, retaining the core framework of the EU GDPR as part of UK domestic law following Brexit. One of its key requirements is that certain organisations not established in the United Kingdom designate a local representative. Lionheart provides Article 27 UK GDPR representative services through Lionheart Squared Limited — our England and Wales registered entity, with over eight years of continuous UK data protection practice.

Service Detail

What this service covers

Our focus

Genuine UK establishment since 2017

You are appointing a firm with a genuine, long-standing UK compliance footprint, not a post-Brexit address of convenience.

Applies to controllers and processors

Unlike some jurisdictions where the representative obligation is limited to controllers, Article 27 UK GDPR applies to both data controllers and data processors. If your organisation processes UK personal data on behalf of clients as a processor — and is not established in the UK — you may still be required to designate a representative. Lionheart serves both roles under a single mandate.

Coordinated with your EU and international obligations

Many organisations subject to the UK GDPR are also subject to the EU GDPR, and potentially the Swiss FADP or Serbian PDPL. Lionheart coordinates all mandates under a single engagement, with consistent procedures and a unified escalation path — avoiding the operational complexity of managing separate representatives in multiple jurisdictions.

Our services include

Custom email address

A dedicated @LionheartSquared.co.uk address published in your privacy notice and records of processing activities, monitored year-round.

UK physical address

Lionheart's Hampshire address is available for inclusion in your privacy documentation and regulatory filings, satisfying the Article 27 UK GDPR establishment requirement.

Data Protection Authority liaison

Acting as the formal contact point for the Information Commission (IC) on your behalf — receiving, logging and forwarding all IC correspondence without delay.

Unlimited data subject enquiries

Receiving and forwarding access, erasure, rectification, restriction and objection requests from individuals in the UK to your privacy team for handling.

Escalation procedures

Defined escalation paths and service levels for time-sensitive regulatory communications, including data breach notifications to the Information Commission. Activity reporting available on request.

ROPA record-keeping

Lionheart holds a copy of your Records of Processing Activities (ROPA) as required under Article 30 UK GDPR, available to the Information Commission upon request.

Legal basis: Article 27, UK General Data Protection Regulation

Get started

Not sure if you are in scope?

Use the guided self-check tool to map which representative obligations may apply.