UK data protection for a foreign-owned subsidiary
The subsidiary needs its own registration with the Information Commissioner, and moving personal data to the parent abroad needs a lawful basis and a transfer agreement. Both are cheap to do and expensive to be caught without.
ICO registration and data moving to the parent
A UK subsidiary holds staff and customer records from its first week, and group systems generally move that data to the parent as a matter of architecture rather than decision. Both require documentation, and a UK enterprise customer's procurement team asks to see it.
What you get
- ICO registration and annual fee
- Records of processing
- Transfer paperwork to the parent
- Privacy notice for UK staff
- Representative requirement assessed
What we do
ICO registration
The subsidiary needs its own registration and annual fee. The parent's registration at home does not cover it, and the register is public.
Transfer paperwork to the parent
Sending UK personal data to a country without a UK adequacy decision needs an approved agreement between the two companies, plus a risk assessment. Signed once, asked for often.
Records of processing
What personal data the company holds, why, and how long it keeps it.
A UK employee privacy notice
Separate from the customer-facing one and required from the moment someone is hired.
Subject access requests
A route for handling a request from an individual, which carries a one-month deadline.
The DPO question, answered
Whether one is required depends on what the company does rather than its size. We record the assessment rather than assuming.
UK data protection law applies to the subsidiary from its first employee and its first customer record. Two obligations catch foreign-owned companies in particular, and neither is difficult.
Registration with the Information Commissioner
Most organisations that process personal data must register with the Information Commissioner's Office and pay an annual data protection fee. The fee is tiered by size and turnover and is small. Not paying it is an offence with a financial penalty, and the register is public, so it is visible to anyone doing diligence on the company. The subsidiary needs its own registration; the parent's registration in its own country does not cover it.
Sending personal data to the parent
Staff records, customer lists and support tickets often move from a UK subsidiary to a parent abroad, often through the group's own systems without anyone deciding to do it. Sending UK personal data to a country outside the UK needs a lawful transfer route. Where the parent's country has been recognised by the UK as providing adequate protection, the transfer is straightforward. Where it has not, and that includes the United States except through specific certification, and India, the transfer needs an approved agreement between the two companies, usually the UK's international data transfer agreement or the addendum to the standard contractual clauses, plus an assessment of the risk. This is a piece of paperwork the group signs once, which is one of the first things a UK enterprise customer's procurement team asks to see.
What else the subsidiary needs
- A record of what personal data it holds, why, and how long it keeps it.
- A privacy notice for UK employees, which is separate from the customer-facing one and is required from the moment someone is hired.
- A route for handling a request from an individual for their data, which has a one-month deadline.
- A decision on whether a data protection officer is required, which depends on what the company does rather than its size.
Buzz handles the registration, the fee, the records and the transfer paperwork as part of the ongoing service. Where the company's processing is high risk, for example large-scale health or financial profiling, that needs a specialist and we will say so rather than improvise.
Common questions
Our parent is already registered at home. Does that cover the UK company?
No. The UK subsidiary is a separate controller and needs its own registration with the Information Commissioner and its own annual fee.
Can we just use the group's global privacy policy?
For customers, often with UK amendments. For UK employees you need a separate notice, and for data leaving the UK you need a transfer agreement between the two companies, which a policy is not.
Do we need a data protection officer?
Only where the company's core activities involve large-scale regular monitoring or large-scale processing of special category data. Most subsidiaries do not, and the assessment is recorded either way.
Related services
Setting up a UK subsidiary
QuotedIncorporation and the registrations that follow
Incorporation, the ownership register, identity verification for each director, then corporation tax, PAYE and VAT registrations. One fee, everything a new UK company must have.
Registering a UK branch (a UK establishment)
QuotedA UK branch of the existing company, registered at Companies House
Registration within the one-month deadline, the parent's constitution and accounts filed, the branch registered for corporation tax, VAT and PAYE, and the annual filings kept up.
HMRC registrations for a new UK company
QuotedCorporation tax, PAYE, VAT and the other HMRC registrations
Every registration the company needs, applied for in the right order and at the right time, with the references held on file rather than lost in the post.
Get a fixed quote
Tell us where the parent company is and what the UK operation has to do.