Our man in Europe… Requirement for EU Representation post Brexit
If you are based in the UK and do business with, or monitor the behaviour of EU citizens after the end of the Brexit transition period, you’ll likely need to appoint someone based in the EU to be a contact for EU citizens and the EU regulators.
Even when (if?) the UK GDPR is given adequacy status, we’ll still have a few extra hurdles to overcome compared being an actual EEA member state. We’ll be very much like Israel or Canada in the eyes of EU GDPR.
For third countries, data can flow without additional safeguards, however it is noted that it still may be harder for EU citizens and the EU regulators to enforce their subjects rights where a controller is based in a third country. To compensate for this, controllers in third countries must appoint a representative who is based inside one of the EU member states that they trade with, to represent the controller to citizens and regulators.
The good news is that you don’t need to open an office and start employing staff to do this. You can appoint a representative to act on your behalf as long as that appointment is under a written contract.
I can’t personally recommend a specific provider, as it will depend on your needs and risk profile, but if you search online for GDPR EU Representative service you’ll find a number of different service providers, from specialist law firms, to web-based subscription services that meet the requirement.
Not everyone will need to do this - you are exempt if you can justify this position:
…your processing is only occasional, of low risk to the data protection rights of individuals, and does not involve the large-scale use of special category or criminal offence data.
Source: European representatives | ICO
In practice this is probably a cost/risk judgement for smaller organisations. There’s some extra information on the ICO website about a number of post Brexit data protection issues. This is worth a read as it’s not’s too long.
If you think this affects your operations and you would value some support in any aspect of Data Protection post Brexit then please give me a call on 020-3393 1899 , or drop me an email - oliver@oliverwestmancott.com