Compliance

Voice AI UK Representative: An Article 27 Guide

A UK representative under Article 27 of the UK GDPR is a UK-based contact that a controller or processor outside the UK must appoint when it targets or monitors UK callers. Dilr Voice is enterprise voice AI built for regulated deployments; this guide explains who is caught, the exemptions, and the penalties for getting it wrong.

DILR.AI ENGINEERING / COMPLIANCE The UK Representative Article 27, and the voice AI vendor outside the UK VENDOR / CONTROLLER Established outside UK ARTICLE 27 Designate a UK rep ICO + CALLERS Addressed here

Most enterprise voice AI is built and operated by companies that are not established in the United Kingdom. A UK bank, insurer or NHS trust puts an AI voice agent on its phone lines, and the platform underneath, along with the company that runs it, often sits in the United States or elsewhere. That is a commercial detail until a caller in Manchester asks who is accountable for the recording of their call, or the Information Commissioner's Office writes to ask the same question. At that point a quiet clause in the UK GDPR becomes load bearing: Article 27, the duty to appoint a UK representative.

McKinsey's 2025 State of AI survey found around 88% of organisations now use AI somewhere in the business, yet only about 6% capture material, enterprise-wide value from it. The gap is rarely the model. It is the operating detail: who is on the hook, under which law, for the personal data an AI system touches. Article 27 is one of those details, and it is widely missed because it does not sit with the obvious rights (access, erasure, objection) that get the attention. It sits with territorial scope, and it bites the party you might not have thought to check: your vendor.

This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system, which maps this obligation before a line goes live.

What is a UK representative under Article 27 of the UK GDPR?

A UK representative is a named person or organisation, based in the United Kingdom, that a controller or processor outside the UK designates in writing to be addressed by the ICO and by data subjects on all matters relating to its processing. It is not an office, a lawyer on retainer for disputes, or a postbox. Under Article 27 it is the local point of contact that makes an overseas voice AI operator reachable and accountable in the UK.

The duty flows from the post-Brexit wording of the UK GDPR. Article 27(1) requires that, where the targeting rule in Article 3(2) applies, the controller or the processor must designate in writing a representative in the United Kingdom. That wording is the post-Brexit version: the reference to the United Kingdom was substituted for the reference to the Union on 31 December 2020 by the EU-exit regulations. Article 27(4) sets out what the representative is for: it must be mandated to be addressed, in addition to or instead of the controller or processor, by the Commissioner and by data subjects on all issues related to processing. In plain terms, a caller or the ICO can go to the representative and get a real answer, not a redirect to a support queue in another time zone.

This matters for voice specifically because a call is dense with personal data: the recording, the transcript, the caller's number, whatever they disclose in the conversation, and often special-category data such as health or financial detail. If the entity processing that data is not in the UK, the caller needs somewhere in the UK to turn. Article 27 is the mechanism. For a fuller picture of the surrounding duties, our enterprise guide to AI voice agents sets out where record-keeping, transparency and accountability obligations attach across a deployment.

When does Article 27 apply to a voice AI deployment?

Article 27 applies only when the UK GDPR reaches an entity through its targeting rule, Article 3(2). That rule catches a controller or processor not established in the UK where its processing relates to offering goods or services to people in the UK, or monitoring their behaviour in the UK. A voice AI vendor with a genuine UK establishment does not need one; one operating from outside the UK, aimed at UK callers, generally does.

Article 3(2) has two limbs. The offering limb catches processing related to offering goods or services to people in the UK, irrespective of whether the data subject has to pay. The monitoring limb catches processing related to monitoring their behaviour, as far as that behaviour takes place within the UK. A UK-facing AI voice line that books, sells, advises or handles service calls plainly offers a service to people in the UK. Behavioural analytics on those calls, sentiment scoring, or profiling of callers can independently satisfy the monitoring limb. The establishment test in Article 3(1) is the off-switch: real establishment in the UK, and Article 27 falls away for that processing.

The sequence below is the assessment we run before a regulated line goes live. It is the post's own framework, not a survey, so it encodes the statutory tests rather than any percentages.

The Article 27 applicability test for a voice AI deployment
01Not established in the UKA genuine UK establishment switches Article 27 off for that …02Targeting or monitoring UK peopleOffering goods or services to, or monitoring the behaviour o…03Which hat, which processingController-hat purposes, its own monitoring, or processing r…04Article 27(2) exemption checkOccasional low-risk processing, or a public authority or bod…05Designate and document a UK representativeIn writing, mandated, named in the privacy notice
Each step narrows the question; only an entity that clears all of them owes a UK representative. This encodes the UK GDPR Article 3 and Article 27 tests, not survey data.

There are two carve-outs in Article 27(2). The obligation does not apply to processing that is occasional, does not include large-scale processing of special-category or criminal-offence data, and is unlikely to result in a risk to people's rights and freedoms. It also does not apply to a public authority or body. A production voice line handling UK callers every day is, almost by definition, not occasional, so most enterprise deployments cannot lean on the first exemption. Our DPIA template for voice AI is the right place to record that assessment.

Is your non-UK voice AI vendor required to appoint a UK representative?

Often, yes, and it is the first diligence question a UK buyer should ask. The decision to target UK callers is made by whoever acts as controller, so a non-UK vendor is caught when it wears the controller hat: training its own models on your call data, running its own analytics, or signing up UK users. Even as a pure processor, its processing related to your targeting is caught. Either way, an Article 27 representative can be owed.

Start with the broad rule, because getting it backwards is the common error. The European Data Protection Board, interpreting the identically worded EU GDPR in its Guidelines 3/2018 on territorial scope, states that "a decision to target individuals in the Union can only be made by an entity acting as a controller". But it is equally clear that where a controller's processing relates to targeting, any processor instructed to carry out that processing "will fall within the scope of the GDPR by virtue of Art 3(2) in respect of that processing", and that controllers or processors caught this way are under the duty to designate a representative. The ICO applies the equivalent test for the UK GDPR, reading "the UK" for "the Union". So a processor does not escape simply by pointing at its client.

That said, the cleanest, least contested triggers for a voice AI vendor are the two where it is unambiguously acting on its own account. First, the controller hat: a platform that uses call recordings to improve its own models, or that runs a self-serve tier where UK businesses sign themselves up, is making its own decisions about UK data and is squarely a controller for that processing. Second, its own monitoring: in the EDPB's worked example, a processor that develops customised outputs from behavioural data "directly monitors data subjects in the EU" and is caught for that reason. Sentiment analysis, propensity scoring and caller profiling all live here.

So the practical diligence question is not "does my vendor touch UK data", it is "which hat is my vendor wearing, for which processing, and where it is caught, has it appointed a UK representative". Many self-serve voice platforms, Vapi, Retell AI, Bland AI and Synthflow among the names UK teams evaluate, are operated by companies established outside the UK and run exactly the kind of own-account processing (model improvement, self-serve onboarding, analytics) that puts them in controller territory. That is not a mark against them; it is a question to put in the procurement pack. This sits next to, but is distinct from, the contract questions in our note on the processor and controller split under Article 28, and the transfer questions in our guide to international data transfers. If you are scoping a vendor now, it is worth a short scoping call before you sign.

Does a UK company selling voice AI into the EU need an EU representative?

Yes, the duty runs both ways. A UK-established voice AI provider that offers services to, or monitors the behaviour of, people in the EU or EEA falls under EU GDPR Article 3(2) and must appoint an EU representative under EU GDPR Article 27. Establishment in the UK protects you from the UK's version of the duty, not the EU's. If your AI voice agents handle callers in Dublin or Frankfurt, the mirror obligation is live.

There is one trap worth naming precisely, because it is easy to import a rule from the wrong side of the Channel. In the EU GDPR, Article 27(3) requires the representative to be established in one of the Member States where the affected data subjects are, and the EDPB guidance builds on that sub-paragraph. In the UK GDPR, Article 27(3) was omitted on 31 December 2020 by the EU-exit regulations, so there is no equivalent "must be based in the specific area where the people are" test for a UK representative; a UK representative simply needs to be in the United Kingdom. Read each regime against its own text. Where an AI voice line spans both the UK and the EU, you may need a representative on each side, and the transfer analysis in our cross-border data transfer guide then runs alongside it.

What happens if you do not appoint a UK representative?

Failing to designate a representative when Article 27 applies is itself a breach, not a technicality. It falls in the standard maximum fine tier: under Article 83(4), the controller and processor obligations in Articles 25 to 39, which include Article 27, carry administrative fines up to £8,700,000, or 2% of total worldwide annual turnover if higher. Just as important, appointing a representative does not buy down your own exposure.

The statute is explicit on that last point. UK GDPR Article 27(5) provides:

"The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves."

In other words, a representative is a point of contact, not a lightning rod. The controller and processor remain fully liable for their processing; the representative makes them reachable, it does not absorb the risk. The ICO can still enforce against the overseas entity directly, and a missing representative is often the first sign to a regulator that an operator has not thought its UK footprint through. Preparing for that scrutiny is exactly what our note on ICO audit preparation for voice AI covers. The commercial reading is simple: the cost of appointing a representative is trivial next to a standard-tier fine and the reputational damage of being found unreachable.

How do you appoint and document a UK representative?

You designate the representative in writing, through a mandate authorising it to be addressed by the ICO and data subjects on all processing matters, and make its identity easy to find. In practice the role sits with a law firm, a consultancy or a specialist provider under a service contract, and one provider can act for several controllers and processors. What turns a name into a working representative is a clear mandate and a real, staffed channel behind it.

Recital 80 of the UK GDPR frames the mandate: the representative should be explicitly designated by a written mandate of the controller or processor to act on its behalf with regard to its obligations, and the designation does not affect the responsibility or liability of the controller or processor. The representative can be a natural or a legal person established in the UK, so a company or partnership is fine as long as a specific individual is named as the lead contact for each entity represented. Once designated, the representative's details belong in your privacy notice so callers can actually reach it, which is why this dovetails with our guidance on privacy notice transparency under Article 13. Building the representative into the operating model, rather than bolting it on after go-live, is the pattern we use in our AI execution office engagements, and it is far cheaper than retrofitting accountability under regulatory pressure. This is the sort of governance plumbing Dilr Voice is designed to make visible rather than hide.

What is the best way to handle Article 27 for a voice AI programme in 2026?

The best approach is not a single vendor, it is a discipline: map every processing activity to a controller-or-processor hat, appoint a UK representative wherever a non-UK entity is caught, and name it in the privacy notice. The fastest route is to make the representative question part of vendor selection, so it is answered before a contract is signed, not during an ICO enquiry. Dilr Voice treats this as part of the deployment, not an afterthought.

There is an honest exception, and it is worth stating because it stops teams over-engineering. Article 27 only bites once the UK GDPR reaches the processing through Article 3(2). If you are a company running a purely internal pilot, on synthetic or non-UK data, with no UK callers in the loop, no UK representative is owed yet, and a fast self-serve build on a platform like Vapi or Synthflow is a perfectly sensible way to learn. The obligation switches on when real UK callers' data starts flowing in production. A governed platform earns its keep at that transition, when a UK-facing, regulated deployment needs the controller map, the representative, the transfer analysis and the audit trail to all hold together. Our operating model consulting exists for exactly that moment, and the broader accountability architecture is set out across the DATS methodology. The right answer scales with the stakes: light for a sandbox, governed for production.

Can the UK representative be the same as our data protection officer?

No, the two roles are incompatible. A data protection officer must act independently and, under Article 38(3), "does not receive any instructions regarding the exercise of those tasks". A representative acts under the mandate and direct instruction of the controller or processor it represents. The EDPB is explicit that the representative function cannot be combined with an independent DPO role, so our guidance on appointing a data protection officer keeps them separate.

Does appointing a representative make our vendor "established" in the UK?

No. The EDPB confirms that a controller or processor which designates a UK representative does not thereby fall within Article 3(1): the presence of a representative in the UK does not, by itself, constitute an establishment. Appointing one discharges the Article 27 duty without dragging the entity's other processing into UK scope. Dilr Voice makes this clear to buyers who worry that compliance here creates exposure elsewhere.

Is a UK representative just a mailbox address?

No. Article 27(4) requires the representative to be mandated to be addressed by the ICO and by data subjects on all issues related to processing, which means a working channel with someone behind it, not a forwarding address. A name in a privacy notice with no staffed function does not discharge the duty. For a voice AI operator, the representative must be able to field a real caller complaint or a regulator's enquiry and route it to a decision.

Want to get this right before you deploy? Try Dilr Voice live, book an AI placement diagnostic, read the DATS methodology, or see our approach to placing AI inside regulated systems.

Service
AI Placement Diagnostic
Service
AI Operating Model
Product
Dilr Voice
Talk to the operators

Know who is accountable before the line goes live.

30-min scoping call · No deck · Confidential. We will map the controller, processor and representative questions for your voice deployment, and tell you where the risk actually sits.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

voice AI UK representative Article 27UK GDPR Article 27 representativenon-UK voice AI vendor complianceappoint a UK data protection representativevoice AI compliance redditbest voice AI compliance approach 2026Dilr Voice

Questions this article answers

What is a UK representative under Article 27 of the UK GDPR?

A UK representative is a named person or organisation, based in the United Kingdom, that a controller or processor outside the UK designates in writing to be addressed by the ICO and by data subjects on all matters relating to its processing. It is not an office, a lawyer on retainer for disputes, or a postbox. Under Article 27 it is the local point of contact that makes an overseas voice AI operator reachable and accountable in the UK.

When does Article 27 apply to a voice AI deployment?

Article 27 applies only when the UK GDPR reaches an entity through its targeting rule, Article 3(2). That rule catches a controller or processor not established in the UK where its processing relates to offering goods or services to people in the UK, or monitoring their behaviour in the UK. A voice AI vendor with a genuine UK establishment does not need one; one operating from outside the UK, aimed at UK callers, generally does.

Is your non-UK voice AI vendor required to appoint a UK representative?

Often, yes, and it is the first diligence question a UK buyer should ask. The decision to target UK callers is made by whoever acts as controller, so a non-UK vendor is caught when it wears the controller hat: training its own models on your call data, running its own analytics, or signing up UK users. Even as a pure processor, its processing related to your targeting is caught. Either way, an Article 27 representative can be owed.

Does a UK company selling voice AI into the EU need an EU representative?

Yes, the duty runs both ways. A UK-established voice AI provider that offers services to, or monitors the behaviour of, people in the EU or EEA falls under EU GDPR Article 3(2) and must appoint an EU representative under EU GDPR Article 27. Establishment in the UK protects you from the UK's version of the duty, not the EU's. If your AI voice agents handle callers in Dublin or Frankfurt, the mirror obligation is live.

What happens if you do not appoint a UK representative?

Failing to designate a representative when Article 27 applies is itself a breach, not a technicality. It falls in the standard maximum fine tier: under Article 83(4), the controller and processor obligations in Articles 25 to 39, which include Article 27, carry administrative fines up to £8,700,000, or 2% of total worldwide annual turnover if higher. Just as important, appointing a representative does not buy down your own exposure.

How do you appoint and document a UK representative?

You designate the representative in writing, through a mandate authorising it to be addressed by the ICO and data subjects on all processing matters, and make its identity easy to find. In practice the role sits with a law firm, a consultancy or a specialist provider under a service contract, and one provider can act for several controllers and processors. What turns a name into a working representative is a clear mandate and a real, staffed channel behind it.

What is the best way to handle Article 27 for a voice AI programme in 2026?

The best approach is not a single vendor, it is a discipline: map every processing activity to a controller-or-processor hat, appoint a UK representative wherever a non-UK entity is caught, and name it in the privacy notice. The fastest route is to make the representative question part of vendor selection, so it is answered before a contract is signed, not during an ICO enquiry. Dilr Voice treats this as part of the deployment, not an afterthought.

Can the UK representative be the same as our data protection officer?

No, the two roles are incompatible. A data protection officer must act independently and, under Article 38(3), "does not receive any instructions regarding the exercise of those tasks". A representative acts under the mandate and direct instruction of the controller or processor it represents. The EDPB is explicit that the representative function cannot be combined with an independent DPO role, so our guidance on appointing a data protection officer keeps them separate.

Compliance

Deploy voice AI without failing an audit

Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.

Related articles

← Previous
Voice AI Email Capture: Getting the Address Right

One email, once a month. No hype. Just what we learned shipping.