Compliance, Standards and Contracts
Data Processing Agreement: The 8 Clauses UK Law Requires
A data processing agreement is the written contract UK GDPR requires whenever one organisation hands personal data to another to process on its behalf. It is not optional, it is not a formality, and the eight terms it must contain are set out in law rather than left to negotiation. Most of the templates circulating online were drafted before the Data (Use and Access) Act 2025 changed the surrounding framework, and one of those changes took effect on 19 June 2026 in a way that touches almost every processor relationship. This page covers what the contract must say, when you actually need one, and what to check on renewal.
When you need one, and when you do not
The trigger is the controller-processor relationship, not the sensitivity of the data or the size of the contract. If you decide why and how personal data is processed, you are the controller. If someone else processes it on your instructions, they are your processor, and Article 28 requires a written contract between you.
In practice that catches far more suppliers than most small businesses expect:
- Your cloud hosting provider, if customer data sits on their infrastructure
- Your payroll bureau
- Your email marketing platform
- Your IT support company, if they can access systems holding personal data
- Your CRM, helpdesk and backup providers
- An offsite shredding company handling paper records
- A marketing agency running campaigns against your customer list
What it does not catch is a supplier acting as a controller in their own right. Your accountant deciding independently what records to keep to meet their own professional obligations is not your processor for that activity. Neither is a bank processing a payment under its own regulatory duties. Getting this wrong in either direction is common: businesses sign processor terms with organisations that are actually joint controllers, which leaves the real relationship undocumented.
The other thing worth being clear about: the obligation to have a contract sits with both parties. Article 28 places direct duties on processors too, so a processor operating without a contract is exposed, not merely inconvenienced.
The eight clauses Article 28(3) requires
The contract must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subject, and the controller’s obligations and rights. Then it must contain all eight of the following. You can read the operative text yourself on legislation.gov.uk.
| What Article 28(3) requires | What to actually check | |
|---|---|---|
| (a) | The processor processes personal data only on the controller’s documented instructions | Is “documented instructions” defined and located, or does the clause float free of any schedule? |
| (b) | Staff authorised to process the data are bound by confidentiality | Applies to contractors and temporary staff, not just employees |
| (c) | The processor takes all security measures required by Article 32 | Vague “industry standard” wording tells you nothing; look for named controls |
| (d) | Sub-processors are engaged only with your authorisation, on back-to-back terms | Look for the notice period and whether you can actually object |
| (e) | The processor helps you respond to data subject rights requests | Check the response time and whether they charge for it |
| (f) | The processor assists with security, breach notification, DPIAs and prior consultation | Breach notification to you should be in hours, not “promptly” |
| (g) | The processor deletes or returns all personal data at the end of the service | Backups are the gap; ask how long deleted data persists in them |
| (h) | The processor gives you the information needed to demonstrate compliance, and allows audits | An audit right you can never afford to exercise is not a control |
Clause (d) is where most disputes actually arise. Sub-processing is how a simple two-party relationship becomes a chain of five, and the contract must require the processor to impose the same Article 28(3) obligations on anyone it engages. A generic authorisation for sub-processors is permitted, but only if the processor tells you about changes and gives you a genuine chance to object. If a template gives you general authorisation with no notification mechanism, that clause is doing nothing.
Clause (h) is the one people sign without reading. The right to audit is meaningful for a large controller with a supplier assurance team and mostly theoretical for a ten-person business. For smaller organisations the practical substitute is insisting the processor provides its current certification or independent assurance report on request, which is a right you might actually use.
What changed in June 2026, and why it affects your contracts
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and its data protection provisions were commenced in stages. The one to know about took effect on 19 June 2026: individuals now have a statutory right to complain directly to a controller about how it has handled their personal data, and controllers must have a procedure in place to deal with those complaints.
The mechanics matter for supplier contracts. A controller has to acknowledge a complaint within 30 days, investigate and respond without undue delay, keep the individual informed, and tell them about their right to go to the ICO. Now consider a complaint about processing you have outsourced. The complaint arrives with you. The facts sit with your processor. If your data processing agreement obliges the processor to assist with data subject rights requests but says nothing about complaint investigations, you have a 30-day clock and no contractual lever to get the information you need.
The sensible response is not to reopen every contract. Existing processor agreements written against the old framework are not invalid. Add three things to your renewal checklist instead:
- A complaints assistance obligation, sitting alongside the existing rights-request assistance clause, with a response time short enough to fit inside your own deadline.
- A check on international transfer wording. The Act replaced the adequacy assessment with a data protection test asking whether protection in the destination is “materially lower” than in the UK. Contracts that quote the old test are describing a standard that no longer exists in that form.
- A check on automated decision-making clauses, since the Act altered the rules there too.
The ICO has said its own guidance on controller-processor contracts is under review because of the Act, so a template that has not been touched since 2024 is quoting a moving target. Our page on the UK GDPR and the Data Protection Act 2018 sets out how the pieces fit together.
Where DPAs go wrong in practice
Having a contract and having an effective one are different things. The failures we see repeatedly:
The unsigned online terms. A supplier’s DPA sits behind a link in their standard terms and updates unilaterally. You have a contract, but you have no record of what it said on the day the incident happened. Save a dated copy each time you renew.
Schedules left blank. The eight clauses are pristine and Schedule 1, which is supposed to state the categories of data and data subjects, says “as agreed between the parties”. That schedule is not decoration. It is what defines the documented instructions in clause (a), and without it clause (a) has no content.
No record of who your processors are. A DPA per supplier is useless if nobody can list the suppliers. Article 30 records and a supplier register are the same exercise done once. Our guide to running a GDPR audit covers building that list from scratch.
Treating the DPA as the whole compliance job. A contract allocates responsibility; it does not create security. Data protection by design and by default is a separate obligation, and it means building the safeguards into the system rather than papering over them afterwards. A signed DPA with a supplier whose access controls you have never checked is a document, not a control.
Mismatched lawful basis. The processing your processor carries out has to be covered by the lawful basis you rely on as controller. If the schedule describes processing wider than your basis supports, the contract has documented your own non-compliance. Our page on choosing a lawful basis for processing personal data works through the six options.
A practical review sequence
- List every supplier that touches personal data. Include anything with system access, not only anything holding a database.
- Classify each one: processor, joint controller, or independent controller. Write down why.
- For each processor, confirm a written contract exists and that you hold a dated copy.
- Check the eight clauses are all present, then check the schedules are actually completed.
- Add the June 2026 items to whichever contracts come up for renewal first: complaints assistance, the transfer test, automated decision-making.
- Diary the sub-processor notification route so a change of sub-processor does not pass you unnoticed.
- Test one clause for real. Ask a processor for its security assurance documentation under clause (h). What comes back tells you more than the contract does.
If a breach does occur, the contract determines who does what and how fast. Our pages on GDPR data breach types and who enforces GDPR in the UK cover what follows, and the GDPR fine calculator puts the statutory maximums in context. This page is general information about UK data protection law, not legal advice on your contracts.
Frequently asked questions
Is a data processing agreement a legal requirement in the UK? Yes. Article 28 of the UK GDPR requires a written contract, or other binding legal act, whenever a controller uses a processor. The obligation applies regardless of the size of either organisation or the value of the contract, and it binds both parties rather than just the controller.
What is the difference between a DPA and a data sharing agreement? A data processing agreement governs a controller-to-processor relationship, where one party processes on the other’s instructions. A data sharing agreement covers controller-to-controller sharing, where each party decides its own purposes. The legal requirements differ, and using the wrong document leaves the actual relationship undocumented.
Can I use a free data processing agreement template? You can start from one, but check its date. Many circulating templates predate the Data (Use and Access) Act 2025 and quote the superseded international transfer test, and few include a complaints assistance obligation to match the rules that took effect on 19 June 2026. Templates also routinely ship with the schedules blank, which is where the substance lives.
Who signs the DPA, the controller or the processor? Both. Article 28 imposes direct obligations on processors as well as controllers, so a processor operating without a signed agreement carries its own regulatory exposure. In practice the party with more negotiating power usually supplies the draft, which is why processor-supplied templates tend to be light on audit rights.
Do I need a DPA with a supplier outside the UK? Yes, and you need more besides. The Article 28 contract is required whoever the processor is, and a transfer of personal data outside the UK needs its own safeguard. Under the Data (Use and Access) Act the question is whether protection in the destination is materially lower than in the UK, which is a different test from the one older contracts refer to.
What happens if we do not have a data processing agreement? It is a breach of Article 28 by both parties and can be enforced by the ICO independently of whether any data has been lost. Practically, the bigger exposure is what the missing contract causes: no defined instructions, no breach notification deadline, no deletion obligation and no route to the information you need when something goes wrong.