A data processing agreement is the written contract that UK GDPR Article 28 requires between a controller and a processor, setting out what the processor may do with personal data and how it must protect it. It is often shortened to DPA, which is not the same as the Data Protection Act 2018 or Meta’s Dynamic Product Ads, both of which share the abbreviation.
How a data processing agreement works
Whenever a business hands personal data to another organisation to handle on its behalf, the two have a controller and processor relationship, and Article 28 says it must be governed by a contract. That contract has to record the subject matter, duration, nature and purpose of the processing, the types of personal data and the people it relates to. It must also commit the processor to:
- act only on the controller’s documented instructions;
- make sure everyone handling the data is bound by confidentiality;
- keep the data secure;
- use sub-processors only with the controller’s authorisation, and pass the same obligations down to them;
- help the controller respond to people exercising their rights, and with security, breach notification and impact assessments;
- delete or return the data at the end of the service;
- provide the information needed to show compliance, and allow audits.
With software you rarely negotiate this. Most CRM, analytics and email service providers publish a standard data processing addendum that forms part of their terms, sometimes accepted automatically and sometimes switched on in account settings. With an agency or freelancer, the same clauses normally sit in the engagement terms or a short schedule to them.
If the processor or its sub-processors store data outside the UK, the agreement also has to deal with international transfers, either by relying on UK adequacy regulations for that country or on a transfer mechanism such as the ICO’s International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
Why it matters for a UK business
It is a legal requirement, and the ICO can take action against a controller that uses processors without one. The more practical reasons are what the contract controls. It decides whether your email platform may use your subscriber list to improve its own products, how fast a supplier must tell you about a personal data breach, and what happens to your customer data when you cancel. Without it, you are relying on goodwill.
Clients and procurement teams increasingly ask for these agreements too. If you are a small agency or consultant handling a client’s customer data, expect to be sent one, and have your own ready.
Common mistakes
- Assuming a supplier’s agreement applies without checking whether it has to be accepted or switched on.
- Never reading the sub-processor list, so you do not know which other companies see your data.
- Giving freelancers access to a CRM or ad account with no written terms at all.
- Not checking where data is stored and how transfers out of the UK are covered.
- Losing track of which version you agreed to and when.
How to act on it
Make a list of every supplier that holds or accesses personal data for you. For each one, find its data processing addendum, usually in a legal or trust centre, accept or sign it where needed, and save a dated copy. Note the sub-processor list and how the supplier notifies changes, and record where the data is stored.
For agencies and freelancers, add a processing clause to the contract before they get access. When you commission a digital marketing strategy from me, I flag any tools in your stack that appear to have no agreement in place.
