Setting up in the UK from abroad

UK data protection for a foreign-owned subsidiary

The subsidiary needs its own registration with the Information Commissioner, and moving personal data to the parent abroad needs a lawful basis and a transfer agreement. Both are cheap to do and expensive to be caught without.

ICO registration and data moving to the parent

A UK subsidiary holds staff and customer records from its first week, and group systems generally move that data to the parent as a matter of architecture rather than decision. Both require documentation, and a UK enterprise customer's procurement team asks to see it.

What you get

  • ICO registration and annual fee
  • Records of processing
  • Transfer paperwork to the parent
  • Privacy notice for UK staff
  • Representative requirement assessed

What we do

ICO registration

The subsidiary needs its own registration and annual fee. The parent's registration at home does not cover it, and the register is public.

Transfer paperwork to the parent

Sending UK personal data to a country without a UK adequacy decision needs an approved agreement between the two companies, plus a risk assessment. Signed once, asked for often.

Records of processing

What personal data the company holds, why, and how long it keeps it.

A UK employee privacy notice

Separate from the customer-facing one and required from the moment someone is hired.

Subject access requests

A route for handling a request from an individual, which carries a one-month deadline.

The DPO question, answered

Whether one is required depends on what the company does rather than its size. We record the assessment rather than assuming.

Home › Corporate governance

UK data protection law applies to the subsidiary from its first employee and its first customer record. Two obligations catch foreign-owned companies in particular, and neither is difficult.

Registration with the Information Commissioner

Most organisations that process personal data must register with the Information Commissioner's Office and pay an annual data protection fee. The fee is tiered by size and turnover and is small. Not paying it is an offence with a financial penalty, and the register is public, so it is visible to anyone doing diligence on the company. The subsidiary needs its own registration; the parent's registration in its own country does not cover it.

Sending personal data to the parent

Staff records, customer lists and support tickets often move from a UK subsidiary to a parent abroad, often through the group's own systems without anyone deciding to do it. Sending UK personal data to a country outside the UK needs a lawful transfer route. Where the parent's country has been recognised by the UK as providing adequate protection, the transfer is straightforward. Where it has not, and that includes the United States except through specific certification, and India, the transfer needs an approved agreement between the two companies, usually the UK's international data transfer agreement or the addendum to the standard contractual clauses, plus an assessment of the risk. This is a piece of paperwork the group signs once, which is one of the first things a UK enterprise customer's procurement team asks to see.

What else the subsidiary needs

  • A record of what personal data it holds, why, and how long it keeps it.
  • A privacy notice for UK employees, which is separate from the customer-facing one and is required from the moment someone is hired.
  • A route for handling a request from an individual for their data, which has a one-month deadline.
  • A decision on whether a data protection officer is required, which depends on what the company does rather than its size.

Buzz handles the registration, the fee, the records and the transfer paperwork as part of the ongoing service. Where the company's processing is high risk, for example large-scale health or financial profiling, that needs a specialist and we will say so rather than improvise.

Common questions

Our parent is already registered at home. Does that cover the UK company?

No. The UK subsidiary is a separate controller and needs its own registration with the Information Commissioner and its own annual fee.

Can we just use the group's global privacy policy?

For customers, often with UK amendments. For UK employees you need a separate notice, and for data leaving the UK you need a transfer agreement between the two companies, which a policy is not.

Do we need a data protection officer?

Only where the company's core activities involve large-scale regular monitoring or large-scale processing of special category data. Most subsidiaries do not, and the assessment is recorded either way.

Get a fixed quote

Tell us where the parent company is and what the UK operation has to do.

Peter Allen
Peter Allen
Co-founder — answers these himself

Get a fixed quoteBook a call