Privacy Shield companies and Brexit

The UK is now in a transition period that is said to end on 31 December 2020 (but could be extended). During this transition period, the UK will continue to apply the GDPR and all data transfer mechanisms remain the same. But what will happen after the transition period? What impact will this have on US Privacy Shield companies and what actions need to be taken?
This article focuses on helping US Privacy Shield companies anticipate the impact of Brexit once the transition period ends (i.e. 31 December 2020 – or later if there’s an extension), guiding them towards actions that should be taken before this date.
1. Brexit and Privacy Shield companies: which actions to take for data transfers?
As per the advice published by the US Government for Privacy Shield companies (see link below in the “References” section), Privacy Shield companies seeking to receive personal data from the UK in reliance on the Privacy Shield must have taken the following steps by 31 December, 2020:
“(i) A Privacy Shield organization will have to update its public commitment to comply with the Privacy Shield to include the UK. Public commitments must state specifically that the commitment extends to personal data received from the UK in reliance on Privacy Shield. If an organization plans to receive Human Resources (HR) data from the UK in reliance on Privacy Shield, it must also update its HR privacy policy. Model language for these updates is provided below:
(INSERT your organization name) complies with the (INSERT EU-U.S. Privacy Shield Framework [and the Swiss-U.S. Privacy Shield Framework(s)]) (Privacy Shield) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the (INSERT European Union and the United Kingdom and/or Switzerland, as applicable) to the United States in reliance on Privacy Shield. (INSERT your organization name) has certified to the Department of Commerce that it adheres to the Privacy Shield Principles with respect to such information. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view the certification, please visit https://www.privacyshield.gov/.
An organization that does not modify its commitment as directed above will not be able to rely on the Privacy Shield Framework to receive personal data from the United Kingdom after December 31, 2020.
(ii) Second, organizations must maintain a current Privacy Shield certification, recertifying annually as required by the Framework.
The Department of Commerce encourages Privacy Shield participants who receive personal data from the United Kingdom to use the Transition Period as an opportunity to prepare any needed updates to their privacy policies. We will continue to monitor the United Kingdom’s withdrawal from the European Union and update this guidance as needed”.
Text by : https://www.privacyshield.gov/article?id=Privacy-Shield-and-the-UK-FAQs
2. Privacy Shield companies and the EU and/or UK Representative(s): what happens after the end of the transition period?
What happens after the transition period will depend on the result of the negotiations between the EU and the UK. The current position is that the GDPR will be implemented into UK law as the “UK GDPR”, alongside the UK Data Protection Act 2018.
Depending in which country a company is located, there are 12 different scenarios that could apply with respect to the requirement to appoint an EU and/or UK based Representative.
Please find below a table which summarizes all possible scenario’s, including specific details relating to Privacy Shield companies under scenarios 7 to 12.

If your US company has an establishment in the UK:

Scenario 7: I am a US-based company and I only sell goods/provide services in the UK or target the UK
As long as we’re in the transition period, your company only needs to appoint one Representative in the EU. In this case, the EU Representative should be in the UK. After the transition period, if you continue to only sell and/or target in the UK and not in any EU country, then the appointment of an EU Representative will not be required but you will need to appoint a UK Representative as per UK law. You can of course appoint your current EU Representative in the UK as your UK Representative (but remember to modify the appointment contract to reflect UK law).
Scenario 8: I am a US-based company and I only sell goods/provide services in the EU/EEA or target the EU/EEA (i.e. not in the UK)
Your company’s situation will not change, regardless of Brexit. The GDPR will continue to apply to all other EU Member States. Therefore, you will still need to appoint an EU Representative*.
Scenario 9: I am a US-based company and I sell goods/provide services in the UK & EU/EEA or I target the UK & EU/EEA
You will continue to fall under the scope of the GDPR. If your current EU Representative is located in the UK, this appointment will no longer be valid in the EU. You can however appoint this person/entity as your UK Representative as per UK law (but remember to modify the appointment contract to reflect UK law). You will also have to appoint an EU Representative* in one of the Member States. This means that you will have two representatives: one in the EU and one in the UK.
Scenario 10:I am a US-based company and I have an establishment in the UK
Before Brexit, you didn’t have to appoint an EU Representative because you had an establishment in the EU. Once the transition period is over, you will no longer have an establishment in the EU so you will have to appoint an EU Representative* in an EU/EEA country.
Scenario 11: I am a US-based company and I have an establishment in the EU/EEA
As a US-based company with an establishment in the EU/EEA, the obligation to appoint an EU Representative does not apply to you. However, if you sell goods/provide services in the UK or target the UK, you will have to appoint a UK Representative as per UK law.
Scenario 12: I am a US-based company and I have an establishment in the UK & EU/EEA
No action is needed. As a US-based company with an establishment in the UK and in the EU& EEA, the obligation to appoint an EU Representative or a UK Representative does not apply to you.
* Unless you’re a public authority or body or if the processing is occasional, does not include, on a large scale, processing of special categories of data or processing of personal data relating to criminal convictions and offences, and the processing is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing.
3. How can EDPO help your US-based company?
To mitigate risks and to prepare for the obligation to appoint a Representative in the UK, EDPO has opened an office in London, in addition to its headquarters in Brussels and its offices in Paris, Dublin, Berlin and Madrid. We can therefore act as your Representative in the UK and in the EU. For clients who will need both an EU and a UK Representative and who sign up with us before the end of the transition period, we will provide UK Representative services at no additional cost.
Still don’t know if your company needs to appoint an EU Representative? Click here to take EDPO’s assessment test for more insight.
Click here to read our article on 4 of the most common mistakes made about the GDPR by Privacy Shield companies.
References
- Agreement on arrangements between Iceland, the Principality of Liechtenstein, the Kingdom of Norway and the United Kingdom of Great Britain and Northern Ireland following the withdrawal of the United Kingdom from the European Union, the EEA Agreement and other agreements applicable between the United Kingdom and the EEA EFTA States by virtue of the United Kingdom’s membership of the European Union:
https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/766995/Agreement_on_arrangements_between_Iceland__the_Principality_of_Liechtenstein__the_Kingdom_of_Norway_and_the_United_Kingdom_of_Great_Britain_and_Northern_Ireland_following_the_withdrawal_of_the_United_Kingdom_from_the_European_Union_.pdf
- EDPB’s Information note on BCRs (Binding Corporate Rules) for companies which have ICO as BCR Lead Supervisory Authority:
https://edpb.europa.eu/sites/edpb/files/files/file1/edpb-2019-02-12-infonote-bcrs-brexit_en.pdf
- Explainer for the agreement on arrangements between Iceland, the Principality of Liechtenstein and the Kingdom of Norway, and the United Kingdom of Great Britain and Northern Ireland, following the withdrawal of the United Kingdom from the European Union:
https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/766998/Explainer_-_UK-EEA_EFTA_Separation_Agreement.pdf
- ICO’s Guidance on Data Protection and Brexit:
https://ico.org.uk/for-organisations/data-protection-and-brexit/
- Privacy Shield official Government’s website on Brexit:
https://www.privacyshield.gov/article?id=Privacy-Shield-and-the-UK-FAQs
5 GDPR mistakes US companies make in 2025 – and how to avoid them
The General Data Protection Regulation (GDPR) continues to apply to many US companies in 2025, even if they do not have a physical presence...
GDPR and US companies: Up close with a Privacy Shield official
On Tuesday 26 May, EDPO hosted an exclusive webinar on GDPR and US companies with a Privacy Shield official. Rochelle Osei-Tutu shared her...
Are your Data Processors fit to be EU Representative under Article 27 GDPR ?
Appoint your data processor as EU Representative and tick off article 27 GDPR? The Croatia Personal Data Protection Agency(“AZOP”) says no....
Follow us on Linkedin for daily breaking GDPR news!
The General Data Protection Regulation (GDPR) continues to apply to many US companies in 2025, even if they do not have a physical presence in the European Union. Despite years of guidance and enforcement, the same misunderstandings keep reappearing. Here are five of the most common GDPR mistakes US companies make — and how to avoid them.
Mistake 1 – Confusing the Data Protection Officer (DPO) with the EU GDPR Representative
An EU GDPR Representative is a local contact point for data protection authorities and individuals in the EU. Non-EU companies that are subject to the GDPR must appoint a representative to ensure smooth communication and compliance.
A Data Protection Officer (DPO) is responsible for overseeing a company’s internal data protection strategy and ensuring compliance with the GDPR. The DPO monitors data processing, conducts audits, and trains staff.
The DPO works inside the organisation, while the GDPR Representative is based in the EU and acts as an external contact point. Many US companies confuse the two roles, but under the GDPR, they are separate obligations and sometimes both are required.
Mistake 2 – Misunderstanding the extraterritorial scope of the GDPR
The GDPR applies to non-EU companies if they offer goods or services to individuals in the EU or monitor their behaviour online. This applies regardless of where the company is located.
Selling products to EU customers, operating an EU-facing website in EU languages, accepting payments in euros, or tracking EU visitors with cookies or analytics tools can all trigger GDPR obligations.
Mistake 3 – Incorrectly relying on the Privacy Shield (now EU-US Data Privacy Framework)
The Privacy Shield was an agreement that allowed certified US companies to transfer personal data from the EU to the US. In 2020, it was invalidated by the Court of Justice of the European Union in the Schrems II decision.
In 2023, the EU-US Data Privacy Framework (DPF) replaced the Privacy Shield. While participation in the DPF can help facilitate transatlantic data transfers, it does not exempt companies from GDPR compliance.
US companies must ensure that data transfers are lawful under the GDPR. This may involve joining the DPF, using Standard Contractual Clauses (SCCs), or implementing other approved safeguards.
Mistake 4 – Incomplete or unclear privacy policies
The GDPR requires privacy policies to be clear, accessible and transparent. They must explain what personal data is collected, how it is used, the legal basis for processing, and the rights of data subjects.
Many US companies omit details such as data retention periods, contact information for the EU Representative, or instructions on how to exercise data subject rights.
Mistake 5 – Underestimating GDPR fines and enforcement
Data protection authorities have issued fines to companies of all sizes, including non-EU businesses. In 2025, penalties for non-compliance remain high — up to €20 million or 4% of annual global turnover, whichever is higher.
Regular compliance reviews Data Protection Impact Assessments (DPIAs), staff training, and appointing an EU GDPR Representative can help mitigate risks.
How EDPO can help your business stay GDPR compliant
EDPO acts as your official EU GDPR Representative, ensuring compliance with Article 27 of the GDPR and facilitating communication with EU authorities.
For companies targeting the UK market, EDPO also offers UK GDPR Representative services to ensure compliance with the UK’s data protection regime.

