🔹 Data Processing Agreement (UK GDPR) — Free Template (2026)

A) UK organisations that share personal data with suppliers (processors) should have a written Data Processing Agreement (DPA). This solicitor-structured template helps you meet UK GDPR Article 28 requirements and align with the Data Protection Act 2018.

B) Designed for SMEs, startups, SaaS providers, agencies, consultants, and any business using third-party vendors to process personal data.

C) Suitable for use in:

  • ✔ England & Wales
  • ✔ Scotland
  • ✔ Northern Ireland

D) Fully updated for UK GDPR, Data Protection Act 2018, and ICO-facing compliance expectations (2026-ready).


Data Processing Agreement (UK GDPR) Template Preview — Free Version (2026)

View Image Bucket (Preview Files)


What the Free Template Covers

E) Core UK GDPR DPA controls, including:

  • ✔ Controller / Processor roles and scope of processing
  • ✔ Documented instructions and processing restrictions
  • ✔ Confidentiality obligations for staff and authorised persons
  • ✔ Technical & organisational security measures
  • ✔ Sub-processor approvals and flow-down obligations
  • ✔ Assistance with DSARs and data subject rights
  • ✔ Personal data breach notification and cooperation
  • ✔ International transfers and appropriate safeguards
  • ✔ Audits, compliance evidence, and record-keeping
  • ✔ Deletion/return of data at end of services

Sample Clause Extracts

F) Processor Instructions — The Processor shall process personal data only on documented instructions from the Controller, unless required by law.

G) Security Measures — The Processor shall implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse.

H) Sub-Processors — The Processor shall not appoint a sub-processor without prior written authorisation and must impose equivalent data protection obligations.

I) Breach Notification — The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach and shall cooperate with investigation and mitigation.

J) End of Processing — On termination, the Processor shall delete or return personal data (at the Controller’s option), unless retention is required by law.


Download Free Data Processing Agreement

K) Fully editable Word document + PDF reference. No login required.

Download Free DPA (Word & PDF)


Prefer Auto-Customisation?

L) Generate a tailored Data Processing Agreement in minutes using AI:

  1. Register free
  2. Select £1 or £5 plan
  3. AI builds the DPA based on your services, data types, and vendor setup

Launch AI Contract Builder


AI Lawyer — Data Protection & UK GDPR Legal Agent

M) Instant general guidance on DPAs, Article 28 compliance, sub-processors, breach handling, international transfers, audits, and vendor risk.

Open AI Lawyer — Data Protection & UK GDPR

Speak to a Human Solicitor (Telelegal)


Data Processing Agreement FAQs — UK (UK GDPR)

  1. 1. When do I need a DPA?
    When a supplier processes personal data on your behalf (e.g., hosting, payroll, CRM, email, analytics, customer support).
  2. 2. What must a UK GDPR DPA include?
    Article 28 terms: instructions, confidentiality, security, sub-processors, assistance, breaches, deletion/return, and audit/cooperation.
  3. 3. Can I rely on a vendor’s standard DPA?
    Often yes, but you must ensure it matches your processing, transfer setup, and security requirements.
  4. 4. Do DPAs cover international transfers?
    They can reference transfer safeguards (e.g., UK IDTA / Addendum) where data is accessed outside the UK.
  5. 5. Who is the Controller and who is the Processor?
    The Controller decides why/how data is processed; the Processor processes data on the Controller’s documented instructions.
  6. 6. What is a sub-processor?
    A third party the Processor uses to help deliver services (e.g., cloud providers, support tools) that also processes personal data.
  7. 7. How often should I update a DPA?
    Whenever your vendors, processing activities, security measures, or transfer arrangements materially change.

Who Should Use This Template?

N) Suitable for:

  • ✔ UK SMEs and startups using third-party vendors
  • ✔ SaaS and cloud services (B2B / B2C)
  • ✔ Agencies, consultants, and outsourced service providers
  • ✔ E-commerce and subscription businesses
  • ✔ Any organisation sharing personal data with processors

Legal Information

O) This page provides general legal information only and does not constitute legal advice. DPAs must be tailored to your processing activities, security controls, and transfer setup. For high-risk processing, obtain advice from a qualified UK solicitor or data protection professional.

<