Skip to main content
UKContracts
compliance~8 min

Data Processing Agreement (UK GDPR Art. 28)

Required by UK GDPR Article 28 whenever a controller engages a processor (B2B SaaS vendor, hosting provider, marketing agency, payroll bureau, etc.). Sets out the subject matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, and the controller's instructions. Includes the eight Article 28(3) mandatory clauses on confidentiality, security, sub-processors, data-subject rights assistance, breach notification, deletion/return, audits, and international transfers.

Legal references covered (5)
  • ยงUK GDPR Article 28 โ€” Processor
  • ยงUK GDPR Article 32 โ€” Security of processing
  • ยงUK GDPR Article 33 โ€” Notification of personal data breach
  • ยงUK International Data Transfer Agreement (IDTA)
  • ยงData Protection Act 2018

๐ŸŒ Available in your language

Form labels are translated into 9 languages so you can complete documents confidently. The legal document itself is generated in English, because UK law requires the binding text to be in English.

Need help understanding the document? Use a trusted translator or consult a UK solicitor who speaks your language.

Available in
๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ต๐Ÿ‡ฑ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡ด๐Ÿ‡ท๐Ÿ‡บ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ‡ต๐Ÿ‡ฐ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ‡จ๐Ÿ‡ณ๐Ÿ‡ฌ๐Ÿ‡ช
Not legal advice. UKContracts AI Ltd provides legal document templates and information only. We are not a law firm and do not provide legal advice, legal representation, or any service requiring a solicitor's qualification. For complex matters, consult a qualified solicitor.
โ„น๏ธ Note for this template: Many SaaS vendors offer their own pre-signed DPA โ€” accept theirs if it's reasonable rather than negotiating yours, since UK GDPR Art. 28 is met either way. Use this template when you are the controller engaging a smaller supplier without their own DPA, or when you are the processor offering one to your customers.

Fill in the details

2/11 required
Parties
Scope
Sub-processors

Tick to give the processor general authorisation to use sub-processors with notice. Untick to require specific written approval for each.

Transfers

If ticked, transfers rely on the IDTA, EU SCCs (with UK Addendum), or adequacy decisions.

Breach

Standard market practice is 24โ€“48 hours, well within the controller's own 72-hour duty under Article 33.

Document