GuideLevel: IntermediateUK GDPRData ProtectionComplianceContract Law

Data Processing Agreement (DPA) – When You Need One

And when a different contractual arrangement is required under UK law

7 min read · Updated on

A Data Processing Agreement (DPA) is frequently demanded from every service provider and signed without adequate scrutiny. Both approaches carry substantial compliance risks: in certain arrangements a DPA is a mandatory statutory requirement, in others it is the incorrect legal vehicle — and under no circumstances does a signed contract absolve an employer of its ongoing duty to audit vendor security.

When a DPA Is Required

Processing ActivityDPA Required?Legal Classification
Cloud software for time tracking or HR managementYesProcessor (Art. 28 UK GDPR)
Cloud hosting, infrastructure, and data centre servicesYesProcessor (Art. 28 UK GDPR)
External payroll bureau processing employee wagesYesProcessor (Art. 28 UK GDPR)
External IT support and maintenance with potential data accessYesProcessor (Art. 28 UK GDPR)
Confidential document destruction and physical archivingYesProcessor (Art. 28 UK GDPR)
Email marketing, survey platforms, and communication SaaSYesProcessor (Art. 28 UK GDPR)
Legal counsel, solicitors, and barristersNoIndependent Controller
Statutory financial auditors and tax advisersNoIndependent Controller
Occupational health providers and company medical advisersNoIndependent Controller
Commercial banks, Royal Mail, and courier servicesNoIndependent Controller
Office cleaning and facilities services without system accessNoNot personal data processing

Independent professionals are frequently misclassified in commercial arrangements. Solicitors, barristers, chartered accountants, and occupational health practitioners operate under distinct professional rules and legal obligations; they act as independent controllers rather than processors. A DPA is only relevant if an advisory firm provides purely technical data storage or IT hosting facilities detached from professional advisory work.

Mandatory Contractual Clauses

Article 28(3) UK GDPR sets out mandatory contractual provisions that must be incorporated into every DPA:

  • Subject matter and duration of the processing operations,
  • Nature and purpose of the data processing,
  • Categories of personal data and types of data subjects (e.g., employees, contractors),
  • Instruction requirement — processing strictly on documented instructions from the controller,
  • Duty of confidentiality binding all personnel authorised to process the data,
  • Technical and organisational measures (TOMs) to ensure security appropriate to the risk under Article 32 UK GDPR,
  • Sub-processors — rules governing prior written authorisation and the flow-down of equivalent data protection terms,
  • Assistance obligations — supporting the controller with Data Subject Access Requests (DSARs), personal data breach notifications, and Data Protection Impact Assessments (DPIAs),
  • Deletion or return of all personal data at the choice of the controller upon termination of services,
  • Audit and inspection rights — making available all information necessary to demonstrate compliance and allowing for audits by the controller or an appointed auditor.

If any of these statutory elements are omitted, the agreement is defective, exposing the employer to enforcement action and administrative fines from the Information Commissioner's Office (ICO).

Sub-processors

A processor cannot engage a sub-processor without prior specific or general written authorisation from the data controller. For SaaS and multi-tenant cloud platforms, general written authorisation is standard commercial practice.

Operational compliance is critical: under Article 28(2) UK GDPR, the vendor must actively notify the controller of any intended changes concerning the addition or replacement of sub-processors, giving the controller a fair opportunity to object. Contractual clauses granting the vendor carte blanche to modify sub-processors without advance notification are legally unenforceable under UK data protection law.

International Data Transfers

Where employee data is transferred or hosted outside the United Kingdom, employers must satisfy Chapter V of the UK GDPR (Sections 17A–17C Data Protection Act 2018). Transfers require:

  • A UK Adequacy Decision (or adequacy regulations made by the Secretary of State) covering the recipient territory (e.g., the EU/EEA or certified territories),
  • An approved transfer mechanism: the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Commission Standard Contractual Clauses (SCCs), supported by a documented Transfer Risk Assessment (TRA),
  • The UK Extension to the EU-US Data Privacy Framework (the UK-US Data Bridge) for eligible US vendors certified with the US Department of Commerce, or
  • Statutory derogations under Article 49 UK GDPR, which apply strictly to non-repetitive, exceptional circumstances and cannot justify standard SaaS operations.

When contracting with US-based software vendors, organisations must verify and document that the vendor maintains an active certification under the UK Extension to the Data Privacy Framework or has executed the UK IDTA/Addendum alongside an up-to-date Transfer Risk Assessment.

The Duty of Due Diligence and Auditing

Trade Union & Employee Consultation Considerations

When deploying software that includes workforce monitoring capabilities — such as automated time recording, activity logging, or location tracking — employers must consider their workplace consultation obligations:

  1. Information and Consultation of Employees (ICE) Regulations 2004: If an organisation has formal employee consultation arrangements or an established Information and Consultation body, introducing technological systems that monitor workforce performance or change working arrangements requires prior information and consultation.
  2. Recognised Trade Unions: Where a collective bargaining agreement exists with a recognised trade union, changes to working conditions and digital monitoring systems frequently require formal consultation or collective agreement.
  3. ICO Guidance on Workplace Monitoring: The Information Commissioner's Office (ICO) Employment Practices guidance requires employers to conduct a Data Protection Impact Assessment (DPIA) before implementing employee monitoring technologies, ensuring the measure is necessary, proportionate, and transparently communicated to staff.

While the commercial DPA itself is concluded directly between the employer and the vendor, transparently briefing employee representatives on data processing locations, security standards, retention schedules, and access controls fosters workforce trust and ensures full compliance with UK employment standards.

UK Statutory and Regulatory Framework

Status of review: August 2026. This guidance is provided for informational purposes only and does not constitute formal legal advice.

Frequently asked questions

A DPA is mandatory under Article 28 UK GDPR whenever a third-party service provider processes personal data on behalf of and strictly under the documented instructions of the data controller, without pursuing any independent purposes of its own — such as with cloud HR software, time tracking SaaS, or external data centre hosting.
Generally no. Professional service providers (such as chartered accountants, solicitors, and tax advisers) acting under their own statutory duties and professional standards qualify as independent data controllers. A DPA is only required if they provide purely technical IT hosting or data storage services.
Where two or more organisations jointly determine the purposes and means of processing personal data, they act as joint controllers. Under Article 26 UK GDPR, they must enter into a formal joint controllership arrangement transparently allocating their respective compliance duties, particularly concerning data subject rights.
No. Under Article 28(1) UK GDPR, the data controller remains under a statutory duty of due diligence to verify that the processor provides sufficient guarantees of implementing appropriate technical and organisational measures (TOMs). This audit must be actively documented using certifications or audit reports.
Author
PlainStaff Editorial Team
HR Editorial Team
Updated on