When It Is Required
A Data Processing Agreement (DPA) is legally required whenever a third-party service provider (a data processor) processes personal data strictly on documented instructions on behalf of the data controller and does not determine any purposes or means of processing of its own. Typical examples include cloud software providers (SaaS) like HR and time tracking platforms, cloud hosting and data centre operations, outsourced payroll bureaus, and external IT support providers with potential access to employee or customer personal data.
The activities of independent professional advisers who act under their own statutory professional obligations and determine their own professional methods generally do not constitute data processing on behalf of a controller — independent legal counsel and auditors typically act as independent controllers rather than processors.
Mandatory Contractual Contents
Under Article 28(3) of the UK GDPR and the Data Protection Act 2018, a binding contract must set out specific mandatory terms, including:
- The subject matter, nature, purpose, and duration of the processing;
- The types of personal data and categories of data subjects;
- The obligations and rights of the controller;
- A requirement that the processor acts only on documented instructions from the controller;
- Ensuring that persons authorised to process the data have committed themselves to confidentiality;
- Implementing appropriate technical and organisational measures (TOMs) pursuant to Article 32 UK GDPR;
- Stringent conditions for engaging sub-processors (including prior written authorisation and flow-down of identical obligations);
- Assisting the controller in responding to data subjects exercising their statutory rights (such as Subject Access Requests);
- Assisting the controller in ensuring compliance with personal data breach notifications to the Information Commissioner's Office (ICO) and affected individuals;
- Deletion or return of all personal data at the end of the provision of services;
- Making available all information necessary to demonstrate compliance and allowing for audits and inspections conducted by the controller or an appointed auditor.
Distinction from Joint Controllership
If two or more organisations jointly determine the purposes and means of processing, the relationship is not one of controller-to-processor, but joint controllership under Article 26 of the UK GDPR. In such circumstances, rather than a standard DPA, the parties must enter into a transparent Joint Controller Agreement that specifies their respective responsibilities for compliance with UK data protection obligations — particularly regarding which party handles data subject rights and provides privacy information.
Practical Implementation
A signed DPA alone is not sufficient to satisfy statutory compliance. The data controller remains legally accountable under the UK GDPR's accountability principle to carry out and document vendor due diligence before engaging a processor. This includes assessing the processor's security credentials, verifying independent audit reports and certifications (such as ISO/IEC 27001, Cyber Essentials Plus, or SOC 2), and ensuring that the provider's technical and organisational measures adequately protect employee and company data throughout the contractual lifecycle.
- Updated on