A DPA, or data processing agreement, is a legal contract between a data controller and a data processor. It explains how personal data should be handled, protected, stored, and deleted under UK GDPR rules.
If another company processes data for your business, you will usually need a DPA in place.
A DPA involves two main parties: the data controller and the data processor.
For example, if a business uses payroll or HR software, the employer stays the controller while the software provider becomes the processor. The UK ICO says controllers must only use processors that can meet UK GDPR security and compliance requirements.
You need a DPA whenever another company handles personal data on your behalf. Under UK GDPR, businesses must have a written agreement in place before sharing that data with a processor.
You will usually need a DPA if you:
The right DPA helps clarify responsibilities, reduce compliance risks, and protect sensitive employee or customer information.
A GDPR data processing agreement should clearly explain how personal data will be handled and protected. Under UK GDPR, certain details must legally be included in the contract.
A DPA should usually cover:
The UK ICO also requires processors to only act on the controller’s instructions and keep appropriate security measures in place.
A Bristol-based ecommerce business outsourced customer support to an external agency in Leeds. The support team needed access to customer names, email addresses, and order details to handle queries and refunds.
Before sharing the data, both companies signed a DPA. The agreement covered:
This gave the business clearer accountability and helped maintain UK GDPR compliance.
Without a proper DPA, your business could face GDPR breaches, ICO investigations, financial penalties, and damaged customer trust.
If a third party mishandles personal data, you may still be held responsible as the data controller.
The ICO reported more than 12,400 personal data breach cases in 2024/25 alone, showing how common compliance failures have become. UK GDPR fines can also reach up to £17.5 million or 4% of annual global turnover for serious breaches.
Many UK SMEs assume their software provider already covers GDPR compliance, but that is not always true. Common DPA mistakes include:
The ICO has repeatedly warned that poor supplier management and weak data-sharing practices increase the risk of data breaches and compliance failures.
A DPA focuses on how personal data is processed and protected under UK GDPR rules. An NDA protects confidential business information from being shared publicly.
Both the data controller and the data processor must sign the agreement. If sub-processors are involved, they should also be covered either through separate agreements or within the main DPA. This helps ensure every party handling personal data follows the same GDPR responsibilities and security standards.
Yes, a template can be a useful starting point. The UK ICO provides guidance on what a compliant DPA should include. However, every business processes data differently, so the agreement should always be tailored to your specific services, systems, and processing activities.
Yes. If a third party outside the UK processes personal data on your behalf, a DPA is still required under UK GDPR. This commonly applies when UK businesses work with offshore teams, remote staff, payroll providers, or outsourcing partners in countries like India. The location of the processor does not remove your GDPR responsibilities as the data controller.
With Black Piano, UK businesses can hire and manage remote talent confidently, with compliant processes, secure data handling, and clear agreements built into the partnership. Speak to the team to learn more.
