Do You Need a Data Processing Agreement? A Plain-English UK Guide
If your business uses any third-party supplier to handle personal data on your behalf — payroll software, an email marketing tool, a customer support platform — UK GDPR doesn't just recommend a written contract for that. It requires one.
The short answer: yes, if you use a "processor"
Under UK GDPR (the retained EU version, alongside the Data Protection Act 2018), any business is either a controller (decides why and how personal data is processed) or a processor (processes data on the controller's instructions). Whenever a controller uses a processor, Article 28 UK GDPR requires a written contract — a Data Processing Agreement (DPA) — governing that relationship. This isn't optional best practice; it's a legal requirement, and both sides can be held accountable if it's missing.
Common situations that need a DPA
- Using a cloud-based payroll, HR, or CRM platform that stores employee or customer data
- Outsourcing customer support, telemarketing, or a call centre that handles customer contact details
- Using an email marketing platform (Mailchimp-style tools) that stores your subscriber list
- Hiring a web developer or IT support company with access to your systems and the personal data on them
- Using a hosting provider or SaaS product that stores personal data as part of its service
What a DPA must actually cover
Article 28(3) UK GDPR sets out mandatory contents. A compliant DPA must require the processor to:
- Process personal data only on the controller's documented instructions
- Ensure staff handling the data are bound by confidentiality
- Implement appropriate technical and organisational security measures (Article 32)
- Only engage a sub-processor with the controller's authorisation, and flow down the same obligations
- Assist the controller in responding to data subject rights requests
- Delete or return all personal data at the end of the contract
- Make available information needed to demonstrate compliance, and allow audits
What happens if you don't have one
The ICO (Information Commissioner's Office) can take enforcement action against controllers who use processors without an Article 28-compliant contract in place, independently of any actual data breach. In practice, most disputes surface when something goes wrong — a breach, a data subject request the processor won't help with — and there's no contract clarifying who's responsible for what.
Frequently asked questions
What's the difference between a controller and a processor?
A controller decides why and how personal data is processed. A processor acts only on the controller's instructions. The same business can be a controller for some data and a processor for other data.
Do I need a DPA with every supplier?
Only where that supplier processes personal data on your behalf. A supplier with no access to personal data (e.g. a stationery supplier) doesn't need one.
Is a DPA the same as a Data Sharing Agreement?
No. A DPA governs a controller-processor relationship. A Data Sharing Agreement governs two independent controllers sharing data with each other.
Does this apply to sole traders and small businesses?
Yes — UK GDPR applies regardless of business size. There's no exemption for small businesses using processors.
Can I use a generic template found online?
Only if it genuinely covers the Article 28(3) mandatory contents above — many generic templates miss the sub-processor and audit provisions, which are commonly checked in a dispute.
Need the paperwork?
Generate a compliant UK Data Processing Agreement in minutes with Legal Lift.
Browse technology & IP templates