Data Transfers and Representatives

Compliance

Data Transfers

The UK has  left the EU. It is for data protection purposes a ‘third’ country.

The UK retains a version of the GDPR. Europe still has the original version.

Organisations that process the personal data of individuals in the UK and Europe may have to comply with both versions!

European organisations who wish to send personal data to the UK have to do so in accordance with the European GDPR. As the UK has now been deemed to have an adequate data protection regime then personal data can be sent to the UK as before Brexit.

European Representatives

UK organisations who offer goods/ services to or monitor individuals in the EEA have to ensure that they comply with the European GDPR when they process personal data. They may also need to appoint a representative in Europe. This representative is the contact point for data subjects and the European regulators.

Compliance 2

UK Representatives

Compliance

If you are a Data Controller or a Data Processor based outside of the UK and you do not have any offices, branches or other establishments in the UK but you are offering goods or services to individuals in the UK or monitoring the behaviour of individuals in the UK then you may need to appoint a UK representative.

You will need to put in place an appropriate written mandate for that representative to act on your behalf. Information about the representative should be provided to data subjects, for example, in your privacy notice. It should also be made easily accessible to the UK data regulator – the Information Commissioner’s Office – for example by publishing it on your website.

You will need to authorise the representative, in writing, to act on your behalf regarding your UK GDPR compliance, and to deal with the ICO and data subjects in this respect.

DPA/OK can represent you regarding your obligations under the UK GDPR.

U

Gap Analysis / Auditing

~

Data Protection Officer

s

Data Breach Service

Software Licensing

Information Security

Legal Services

Documentation

Marketing To Individuals

i

Compliance

Training

b

Data Subject Right Service

w

GDPR Representatives

Please contact us to arrange a free no obligation telephone discussion.