Data Processing Agreement
Reviews
What is a data processing agreement in the UK?
A data processing agreement is a mandatory written contract required under Article 28 of the UK GDPR by virtue of which a controller (the organisation that determines the purposes and means of processing personal data) engages a processor (an organisation processing personal data on the controller’s behalf, strictly in accordance with the controller’s instructions) to process all or some of customers’ or users’ personal data.
The present template deals with the services related to processing of personal data under the article 28-mechanism. If you are looking for a standard type of general service contract, another template should be used instead.
When does a UK business need a data processing agreement?
Having a professionally written and valid data processing agreement can be necessary for online and offline businesses in the UK. For example:
- using AI or machine learning services as a part of your business when providing services or delivering goods;
- outsourcing customer support services
- working with analytics providers who process further personal data (for example, when analysing customer behaviour on the website or marketing or promotion for specific groups of clients);
- using various SaaS platforms or tools, including CRM systems, HR platforms, accounting software, etc.
- using various tools in daily work that store or archive information containing personal data, even pseudonymised;
- In any other situation when either third party has partial or full access to personal data, your business is in control.
What should be covered in this template?
Article 28(3) of the UK GDPR sets out the mandatory content of the data processing agreement, they are as follows:
- Full identification details of the controller and a processor;
- Subject matter, duration, nature, and purpose of the processing with specific tasks and goals;
- Types of personal data and categories of data subjects (the policy must list only existing categories of data subjects, not potential or future);
- Confidentiality commitment for authorised personnel of both parties to the data processing agreement;
- Security measures in place aimed to protect personal data against disclosure or leakage (for example, encryption, access controls, MFA, backups, and incident response;
- If the processor engages subcontractors, full identification details of subcontractors must be listed in the text of the agreement, including authorisation type, notification process, right to object, and flow-down obligations;
- If the processor is to be processing or transferring part or all of personal data outside the UK, the list of these third countries should be listed;
- Data subject rights assistance clause;
- Breach notification procedure, with defined timescales and the nature of assistance provided;
- Audit and inspection rights, calibrated to be genuinely exercisable and commercially realistic;
- Duration of the contract allowing parties to enter a data processing agreement for an indefinite or defined period of time.
Important UK GDPR pitfalls your data processing agreement must address
Below are the nine most common pitfalls overlooked by businesses in the UK when creating a data processing agreement from scratch:
Generic data processing agreement
Even though UK GDPR mirrors EU GDPR, both documents are not interchangeable. The UK legal framework utilises its own statutory text, which should be aligned with domestic law, including the Data Protection Act 2018. Therefore, using a standard EU GDPR data processing agreement is the mistake number one many businesses in the UK keep making again and again.
Absence of clear definitions
Data processing agreements should never incorporate vague, unclear or overly vague provisions. Article 28(3) requires the contract to identify the subject matter, duration, nature, purpose, types of personal data, and categories of data subjects of the processing. All these 6 elements must be addressed directly in the text of the agreement.
Confusion of roles
The legal obligations that sit with the controller and processor in the UK GDPR are based not on the contractual labelling but rather on the functions both parties perform in the agreement. UK authorities continue to have regard to the well-established EU case law Wirtschaftsakademie Schleswig-Holstein (Case C-210/16), in which the Court of Justice held that the test for controller status turns on genuine influence over the purposes and means of processing — not on contractual labelling.
All in all, if the processor in a data processing agreement template starts determining the purposes and means of processing, there is a genuine risk for such a processor to be treated as a controller.
International transfers
If the processor is under the data processing agreement:
- intends to transfer data outside the UK; or
- plans to transfer such data outside the UK; or
- such data is being accessed by the personnel remotely outside the UK.
In such a case, an application of Article 28(3)(a) is being triggered, and the introduction of the international transfer clause is mandatory.
Controller’s Audit Rights
The text of the data protection agreement must equip the controller with real and effective measures of regular control and audit related to the processing of personal data. This is right as envisaged by Article 28(3)(h), which allows both technical and physical audits to ensure minimum compliance with the UK GDPR legal framework.
Consequences of termination
Parties typically fail to discuss in the provisions of the data processing agreement what shall happen with personal data once the contract ends. At the controller’s choice, such data should be either returned, deleted or retained if there are respective legal reasons for such a retention. The absence of such a clause creates a legal gap, since the absence of post-termination obligations poses a high risk towards the security and integrity of personal data in general.
What are the consequences of not having a proper data processing agreement?
When the parties fail to enter a proper written data processing agreement in line with the UK GDPR, the following negative legal consequences may arise:
Direct ICO enforcement exposure
Failing to have an Article 28-compliant contract in place is itself a compliance failure that is directly punishable by the Information Commissioner’s Office in the form of taking enforcement action, including fines, for inadequate or absent processor contracts.
It is important to remember that the sole fact of not having a properly written contract is a sufficient breach, which is independent of any underlying data breach.
Ambiguity of responsibilities
If something goes wrong, without clear documented instructions, parties cannot identify which measures should be taken next and who is responsible for them. When the leak or breach of personal data takes place, even an insufficient delay in the application of the respective safety measures may cost both parties significant fines imposed by the Information Commission Office.
Loss of liability chain
If sub-processors are involved in the processing of personal data, failure to have a proper written arrangement prevents the controller from having effective measures to make a sub-processor liable for the breach. This is because there is no contractual chain that would otherwise make both the processor and sub-processor liable simply.
Reputational and commercial damage
Nowadays almost all customers in the UK pay attention to how their personal information is being collected, stored and processed by third parties. Enterprise customers and larger contracting parties increasingly require evidence of a compliant DPA before agreeing to work with a supplier.
Typically, the absence of a proper written data processing agreement in place becomes a commercial barrier for many reputable businesses in the UK.
How do you sign the data processing agreement with your counterparty?
Follow the instructions below:
- Click the “Create Document” button to start the customisation process.
- Answer simple questions in the form.
- Select a template’s format – PDF or Word.
- E-sign the document online if you are a controller.
- Make a payment.
- Download the document template to your computer.
- Print it out and read it carefully.
- Make both parties sign the document in two copies.
- Each party must keep a signed copy of the document for their personal record.
- If you are an online business in the UK, after this document is signed by both parties, you can include a reference about the present data processing agreement directly in the website terms and conditions, cookie policy and privacy policy.
This article is reviewed by Daria Turanska, a lawyer with 15 years’ contract drafting experience. Fact checked by Sarah Collins.
Table of content
Frequently Asked Questions (FAQ)
-
1. Does a Data Processing Agreement need to include the types of personal data being processed?
Yes, this is a direct requirement of the Article 28(3). Failure to include the type of personal data and categories means incompliance with the statutory minimum.
-
2. Can a Processor use Sub-processors under a UK DPA?
Yes, but only with the controller’s prior specific or general written authorisation under Article 28(2). Where general authorisation is given, the processor must notify the controller of intended changes and give a genuine opportunity to object. The processor also remains fully liable to the controller for a sub-processor’s failures, regardless of what the sub-processor’s own contract says.
Looking for something Different?
Start typing to find out our collection of legal documents and contract templates