Free contract template

Data processing agreement

Keep your business compliant with UK data protection laws by using a data processing agreement when working with third-party processors.

What's inside

  • Sets clear roles and responsibilities
  • Assures legal compliance
  • Safeguards personal data
  • Enables
  • Manages confidentiality and security
  • Secures proper data disposal

Word document. Drafted by Lawyerly's commercial solicitors. Last updated September 2026.

Download your free copy

Tell us who you are and the file is yours straight away.

When a data processing agreement is required

Article 28(3) of the UK GDPR requires a written contract on defined terms whenever one organisation processes personal data on another organisation's behalf. It is not optional, it is not satisfied by a clause saying the parties will comply with data protection law, and both sides can be fined where it is missing. This template is drafted to meet that article and reflects the data protection changes made by the Data (Use and Access) Act 2025 that have been in force since February 2026.

Settle who is the controller and who is the processor first

The question is decided by what each party actually does, not by what the contract calls them. A supplier who processes personal data only on the customer's instructions is a processor: a payroll bureau, a cloud host, an email platform, an outsourced call centre. Where each side decides for itself why and how the data is used, this is the wrong document. Joint controllers need an Article 26 arrangement, and controller to controller sharing needs a data sharing agreement. Accountants and most professional advisers fall into the second group, which is why their engagement terms rarely contain processor clauses.

What Article 28 requires

The contract has to record the subject matter and duration of the processing, its nature and purpose, the type of personal data and the categories of data subject, and the controller's obligations and rights. It then binds the processor to eight specific things: to process only on documented instructions, to ensure the people processing the data are under a duty of confidence, to take the security measures Article 32 requires, not to engage a sub-processor without authorisation and to pass the same terms down, to assist with data subject requests, to assist with security, breach notification and impact assessments, to delete or return the data at the end, and to make available the information needed to demonstrate compliance and allow audits.

The four schedules are not optional

Schedule 1 carries the processing details, Schedule 2 the technical and organisational security measures, Schedule 3 the approved sub-processors and Schedule 4 the contacts on each side. Complete all four before signing. Without them the agreement does not meet Article 28(3), and the schedules are the first thing an auditor or an enterprise customer's procurement team turns to. A processor contract with an empty description of the data is worse than none, because it shows the exercise was never done.

If the data leaves the UK

Use clause 13, put the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses in place, and carry out a transfer risk assessment before the data moves. That applies to a sub-processor abroad as much as to the processor itself, which catches more businesses than expected once hosting and support are followed through.

A processing agreement usually sits as a schedule to a services contract rather than standing alone, and should be read against the liability position in the main contract. Our UK GDPR and data protection solicitors handle the transfer documents, and our commercial contracts team the agreement it attaches to.

Need more than a template?

Talk to a solicitor about your situation

A template gets you started. When the facts are yours, one of our commercial solicitors will tailor it, or tell you plainly that you need something else. The first conversation is free.

Willem van der Merwe

Co-Founder

Read profile