Data Processing Agreement (DPA) template
Overview
A data processing agreement (DPA) is the contract required by Article 28 of the UK GDPR (the retained EU GDPR, as it forms part of UK law under the Data Protection Act 2018) whenever a controller instructs a processor to process personal data on its behalf. Article 28(3) sets out an exhaustive list of terms that must be included: the subject matter, duration, nature and purpose of processing; the categories of personal data and data subjects; the controller's and processor's obligations and rights; and specific processor obligations, including processing only on documented instructions, ensuring confidentiality, implementing appropriate technical and organisational security measures, engaging sub-processors only with authorisation and equivalent contractual protections, assisting the controller with data subject rights requests and breach notifications, deleting or returning data at the end of the engagement, and submitting to audits. A UK-specific point that has no equivalent in an EU DPA is international transfers post-Brexit: the UK GDPR and EU GDPR are now separate legal regimes. A transfer of personal data from the UK to a country without a UK adequacy regulation from the Secretary of State requires an appropriate safeguard — most commonly the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, rather than the EU Standard Contractual Clauses alone, which do not by themselves cover a UK-outbound transfer. Where the processor is itself established outside the UK, or subcontracts hosting to a non-UK provider, the transfer mechanism must be checked and documented separately from the EU position. When to use it: whenever any supplier processes personal data on behalf of a customer as part of delivering a service — hosting, SaaS, payroll, marketing platforms, IT support with data access, and so on. It is typically referenced as a schedule to, or executed alongside, the main services agreement. Parties: the controller (the customer, who determines the purposes and means of processing) and the processor (the supplier, who processes data only on the controller's documented instructions). Key clauses: subject matter, duration, nature and purpose of processing; categories of personal data and data subjects; processing on documented instructions only; confidentiality of personnel; security measures (Article 32 UK GDPR); sub-processing authorisation; assistance with data subject rights and Data Protection Impact Assessments; personal data breach notification, without undue delay; end-of-contract deletion or return of data; audit rights; and international transfer safeguards (IDTA / UK Addendum where relevant). Pitfalls to avoid: relying on EU Standard Contractual Clauses alone for a UK-outbound transfer without the UK Addendum, which leaves the transfer without a valid UK safeguard; allowing sub-processors without a documented authorisation and flow-down of equivalent obligations; and omitting a concrete breach notification timeframe, which leaves the controller unable to meet its own 72-hour ICO notification duty under Article 33 UK GDPR.
Information to customize
Controller's registered name
Controller's registered office address
Processor's registered name
Processor's registered office address
Reference to the main services agreement
Subject matter and purpose of processing
Duration of processing
Categories of personal data
Categories of data subjects
Technical and organisational security measures
Authorised sub-processors (name, location, purpose)
Breach notification period (hours)
Should allow the controller to still meet its own 72-hour ICO deadline.
International transfer safeguard used, if any
E.g. IDTA, UK Addendum to the EU SCCs, or UK adequacy regulation.
Period for data deletion/return at end of contract
Date of signature
Customize your template
Should allow the controller to still meet its own 72-hour ICO deadline.
E.g. IDTA, UK Addendum to the EU SCCs, or UK adequacy regulation.
Signature recipient
Frequently asked questions
- Is a data processing agreement always required alongside a UK services contract?
- Yes, wherever a supplier processes personal data on behalf of a customer, Article 28 UK GDPR requires a written contract with specific mandatory terms — an informal understanding is not sufficient.
- Can we just use the EU Standard Contractual Clauses for a UK data transfer?
- No. Since Brexit, the UK GDPR and EU GDPR are separate regimes. A transfer of personal data out of the UK needs a UK-specific safeguard — the ICO's International Data Transfer Agreement or the UK Addendum to the EU SCCs — the EU SCCs alone do not cover it.
- How quickly must a processor notify a personal data breach?
- The agreement should set a concrete notification window (commonly 24-48 hours) that leaves the controller enough time to meet its own duty to notify the ICO without undue delay and, in any event, within 72 hours of becoming aware of the breach.
- Can a processor engage sub-processors freely?
- No. The processor needs either specific prior authorisation for each sub-processor, or a general authorisation with a right for the controller to object to new sub-processors, and must flow down equivalent data protection obligations to them.
- What happens to the data when the main contract ends?
- The processor must, at the controller's choice, delete or return all personal data and delete existing copies within an agreed period, unless the law requires it to retain some data for longer.
Related templates
Information about this template
- Last updated
- 29 August 2026
- Country
- GB
- Legal notice
- This template is provided for guidance only and must be adapted to your circumstances. It does not constitute legal advice.