Legal Lift is a document service, not a law firm. Templates are kept current with UK law for your own use. Independent SRA-regulated solicitors available for tailored advice.

Technology

Do You Need a Data Processing Agreement? A Plain-English UK Guide

If your business uses any third-party supplier to handle personal data on your behalf — payroll software, an email marketing tool, a customer support platform — UK GDPR doesn't just recommend a written contract for that. It requires one.

The short answer: yes, if you use a "processor"

Under UK GDPR (the retained EU version, alongside the Data Protection Act 2018), any business is either a controller (decides why and how personal data is processed) or a processor (processes data on the controller's instructions). Whenever a controller uses a processor, Article 28 UK GDPR requires a written contract — a Data Processing Agreement (DPA) — governing that relationship. This isn't optional best practice; it's a legal requirement, and both sides can be held accountable if it's missing.

Common situations that need a DPA

What a DPA must actually cover

Article 28(3) UK GDPR sets out mandatory contents. A compliant DPA must require the processor to:

Controller vs. processor isn't always obvious. If two businesses are each deciding independently how to use shared data (e.g. co-marketing partners), they may both be independent controllers — that needs a data sharing agreement, not a DPA. Get this distinction wrong and the wrong document ends up governing the relationship.

What happens if you don't have one

The ICO (Information Commissioner's Office) can take enforcement action against controllers who use processors without an Article 28-compliant contract in place, independently of any actual data breach. In practice, most disputes surface when something goes wrong — a breach, a data subject request the processor won't help with — and there's no contract clarifying who's responsible for what.

Frequently asked questions

What's the difference between a controller and a processor?

A controller decides why and how personal data is processed. A processor acts only on the controller's instructions. The same business can be a controller for some data and a processor for other data.

Do I need a DPA with every supplier?

Only where that supplier processes personal data on your behalf. A supplier with no access to personal data (e.g. a stationery supplier) doesn't need one.

Is a DPA the same as a Data Sharing Agreement?

No. A DPA governs a controller-processor relationship. A Data Sharing Agreement governs two independent controllers sharing data with each other.

Does this apply to sole traders and small businesses?

Yes — UK GDPR applies regardless of business size. There's no exemption for small businesses using processors.

Can I use a generic template found online?

Only if it genuinely covers the Article 28(3) mandatory contents above — many generic templates miss the sub-processor and audit provisions, which are commonly checked in a dispute.

Need the paperwork?

Generate a compliant UK Data Processing Agreement in minutes with Legal Lift.

Browse technology & IP templates