GDPR Local &

GDPR Article 27 · UK GDPR Article 27 · FADP Article 14

Vanta flagged it. Clear it today.

If you sell into the EU or UK without an establishment there, the law says you must appoint a representative in writing. Sign up free, and download your signed Written Agreement in minutes.

10% off for Vanta customers, applied automatically at checkout. No code needed.
No credit card
Written Agreement in minutes
Offices in the UK, EU and Switzerland

Requirement check

Which representatives do you need?

Two questions, no email required. Answers stay in your browser.

Q1Where is your company legally established? Select all that apply
In the EU
In the UK
In Switzerland
Elsewhere (i.e. United States)
Q2Do you offer goods or services to, or monitor the behaviour of, people in the EU, UK or Switzerland? Select all that apply
EU
Großbritannien
Schweiz

Partner pricing

Priced by company size, discounted
for Vanta

Pick your headcount and billing period. The Vanta rate is already applied.

Größe des Unternehmens:

GDPR Article 27 EU/UK
Representative

Schnelle Einrichtung, sofortiger Zugriff auf Ihre schriftliche Vereinbarung und unseren DSGVO -Beauftragten-Service

£ 89 /mo £ 99 /mo
Jetzt kaufen
  • Ihr Datenschutzbeauftragter in der EU und im Vereinigten Königreich
  • Sicherstellen, dass Sie Ihren rechtlichen Verpflichtungen nachkommen
  • Experten helfen Ihnen beim Umgang mit SARs, RTEs und Datenschutzverletzungen
  • als erste Anlaufstelle für Anfragen der Aufsichtsbehörde zu fungieren
  • Kostenlose Erstprüfung der Einhaltung von Artikel 27, um Ihre Sicherheit zu gewährleisten

FADP Article 14 Swiss
Representative

Erforderlich, wenn Sie sich außerhalb der Schweiz befinden und Daten verarbeiten oder Dienstleistungen für Schweizer Bürger anbieten.

£ 89 /mo £ 99 /mo
Jetzt kaufen
  • Compliance-Unterstützung durch unser Büro in der Schweiz
  • Schriftliche Vereinbarung nach dem INLB-Gesetz
  • Kostenloses Audit der Datenschutzrichtlinien
  • Kontaktaufnahme mit der örtlichen Aufsichtsbehörde in Ihrem Namen

Extend your compliance with expert-led services

*Die in verschiedenen Währungen angezeigten Preise dienen nur als Richtwerte und werden einmal täglich aktualisiert. Die endgültigen Zahlungen werden in britischen Pfund abgewickelt, sobald Sie sich angemeldet und Zugang zum Portal erhalten haben.

From Sign up to Evidence

Five steps, and the first two
take about five minutes

The order matters here, because your Written Agreement lands on day 1.

The five steps, on a time axis Steps one and two both happen on day one in about five minutes, and step two issues the signed Written Agreement that clears your Vanta control. Steps three, four and five follow afterwards at your own pace and do not hold up the evidence.

Step 01 of 05

About 2 minutes

Create your account

A few details about your company and the jurisdictions you need. No credit card, and nothing to install.

The evidence arrives at step 2, not at the end, so the compliance work that follows improves your position without holding up the paperwork your auditor is waiting for.

Why us

A real presence in every
jurisdiction we represent you in

A representative has to be established where your data subjects are. Ours are,
with staffed offices and registered addresses in each.

Working with GDPRLocal has been a game-changer for MBN Solutions. Their professionalism and expertise ensure our data is safe. They offer first-class service and a great customer experience. MBN Solutions highly recommends GDPRLocal for any business needing GDPR solutions.

Fiona Gillies Operations Manager of MBN Solutions 

Before you ask

The questions Vanta
customers actually ask us

No. You remain the controller or processor and stay responsible for your own compliance. Our role is to be the point of contact in the EU or UK that regulators and individuals can reach, to maintain a record of your processing activities, and to support you when something is raised.
Usually yes. Since Brexit the UK is outside the EU, so a UK-only company that offers goods or services to people in the EU, or monitors their behaviour, generally needs an EU representative under EU GDPR. It works the other way too: an EU-established company targeting the UK generally needs a UK representative.
There is an exemption, but it is narrow and it is not about company size. It applies where your processing is occasional, does not include large-scale processing of special category data or criminal offence data, and is unlikely to result in a risk to people's rights and freedoms. Most businesses with EU customers do not qualify, because their processing is ongoing rather than occasional.
Failure to designate a representative is an infringement of the controller and processor obligations, which carries administrative fines of up to 10 million euro or 2% of total worldwide annual turnover, whichever is higher. It is also increasingly picked up during security and privacy reviews by your own customers.
Your Written Agreement is available to download from the portal as soon as you have completed signup, so you can attach it as evidence the same day. The compliance audit that follows is about improving your position, not a condition of the appointment.
It is applied automatically at checkout when you arrive through this page, so there is no code to enter. The link carries your partner reference, which is also how we know to give you the partner rate on renewal.
Yes. The revised Swiss Federal Act on Data Protection has its own representative requirement under Article 14 for organisations outside Switzerland that process data on people there. It is a separate appointment from GDPR, and it is available as its own subscription.