GDPR Local &

GDPR Article 27 · UK GDPR Article 27 · FADP Article 14

Vanta flagged it. Clear it today.

If you sell into the EU or UK without an establishment there, the law says you must appoint a representative in writing. Sign up free, and download your signed Written Agreement in minutes.

10% off for Vanta customers, applied automatically at checkout. No code needed.
No credit card
Written Agreement in minutes
Offices in the UK, EU and Switzerland

Requirement check

Which representatives do you need?

Two questions, no email required. Answers stay in your browser.

Q1Where is your company legally established? Select all that apply
In the EU
In the UK
In Switzerland
Elsewhere (i.e. United States)
Q2Do you offer goods or services to, or monitor the behaviour of, people in the EU, UK or Switzerland? Select all that apply
UE
Regno Unito
Svizzera

Partner pricing

Priced by company size, discounted
for Vanta

Pick your headcount and billing period. The Vanta rate is already applied.

Dimensioni dell'azienda:

GDPR Article 27 EU/UK
Representative

Configurazione rapida, accesso immediato al tuo Accordo scritto e al nostro servizio di responsabile della protezione dei dati ai sensi del GDPR dell’UE

£ 89 /mo £ 99 /mo
Acquista ora
  • Il vostro agente per la protezione dei dati nell'UE e nel Regno Unito
  • Contribuire a garantire il rispetto dei vostri obblighi legali
  • Esperti per aiutarvi a gestire SAR, RTE e violazioni di dati
  • Agisce come primo punto di contatto per qualsiasi richiesta di informazioni da parte dell'autorità di regolamentazione.
  • Verifica iniziale gratuita della conformità all'articolo 27 per aiutarvi a mantenere la vostra sicurezza

FADP Article 14 Swiss
Representative

Obbligatorio se ti trovi al di fuori della Svizzera e tratti dati o offri servizi a cittadini svizzeri.

£ 89 /mo £ 99 /mo
Acquista ora
  • Supporto per la conformità dal nostro ufficio in Svizzera
  • Accordo scritto come richiesto dalla legge FADP
  • Revisione gratuita dell'informativa sulla privacy
  • Collegamento con l'autorità di regolamentazione locale per vostro conto

Extend your compliance with expert-led services

*I prezzi indicati nelle diverse valute sono solo indicativi e vengono aggiornati una volta al giorno. I pagamenti finali saranno elaborati in sterline britanniche al momento dell'iscrizione e dell'accesso al portale.

From Sign up to Evidence

Five steps, and the first two
take about five minutes

The order matters here, because your Written Agreement lands on day 1.

The five steps, on a time axis Steps one and two both happen on day one in about five minutes, and step two issues the signed Written Agreement that clears your Vanta control. Steps three, four and five follow afterwards at your own pace and do not hold up the evidence.

Step 01 of 05

About 2 minutes

Create your account

A few details about your company and the jurisdictions you need. No credit card, and nothing to install.

The evidence arrives at step 2, not at the end, so the compliance work that follows improves your position without holding up the paperwork your auditor is waiting for.

Why us

A real presence in every
jurisdiction we represent you in

A representative has to be established where your data subjects are. Ours are,
with staffed offices and registered addresses in each.

Working with GDPRLocal has been a game-changer for MBN Solutions. Their professionalism and expertise ensure our data is safe. They offer first-class service and a great customer experience. MBN Solutions highly recommends GDPRLocal for any business needing GDPR solutions.

Fiona Gillies Operations Manager of MBN Solutions 

Before you ask

The questions Vanta
customers actually ask us

No. You remain the controller or processor and stay responsible for your own compliance. Our role is to be the point of contact in the EU or UK that regulators and individuals can reach, to maintain a record of your processing activities, and to support you when something is raised.
Usually yes. Since Brexit the UK is outside the EU, so a UK-only company that offers goods or services to people in the EU, or monitors their behaviour, generally needs an EU representative under EU GDPR. It works the other way too: an EU-established company targeting the UK generally needs a UK representative.
There is an exemption, but it is narrow and it is not about company size. It applies where your processing is occasional, does not include large-scale processing of special category data or criminal offence data, and is unlikely to result in a risk to people's rights and freedoms. Most businesses with EU customers do not qualify, because their processing is ongoing rather than occasional.
Failure to designate a representative is an infringement of the controller and processor obligations, which carries administrative fines of up to 10 million euro or 2% of total worldwide annual turnover, whichever is higher. It is also increasingly picked up during security and privacy reviews by your own customers.
Your Written Agreement is available to download from the portal as soon as you have completed signup, so you can attach it as evidence the same day. The compliance audit that follows is about improving your position, not a condition of the appointment.
It is applied automatically at checkout when you arrive through this page, so there is no code to enter. The link carries your partner reference, which is also how we know to give you the partner rate on renewal.
Yes. The revised Swiss Federal Act on Data Protection has its own representative requirement under Article 14 for organisations outside Switzerland that process data on people there. It is a separate appointment from GDPR, and it is available as its own subscription.