top of page

What Is a Data Processing Agreement (DPA)? When You Need One and What It Must Include

  • Writer: Joe Stock
    Joe Stock
  • Jul 1
  • 3 min read

If you've ever signed up to a CRM, payroll system, cloud hosting provider or marketing platform, you've probably been presented with a Data Processing Agreement (DPA).


But what is a DPA, when do you need one, and what should it contain?


A Data Processing Agreement is one of the most important documents in UK GDPR compliance. It governs how a third party handles personal data on your behalf and helps ensure both organisations understand their responsibilities.


In this guide, we'll explain:

  • What a Data Processing Agreement is

  • When a DPA is required

  • What needs to be included in a DPA

  • Common examples of DPAs in everyday business

  • Mistakes organisations frequently make

What Is a Data Processing Agreement?

A Data Processing Agreement (DPA) is a contract between:

  • A data controller (the organisation deciding why and how personal data is used); and

  • A data processor (the organisation processing personal data on behalf of the controller).


The UK GDPR requires controllers to have a written contract in place whenever they appoint a processor to handle personal data on their behalf. The contract must contain specific requirements set out in Article 28 UK GDPR.


In simple terms, a DPA sets the rules for how personal data will be handled, protected and managed by the processor.


When Do I Need a DPA?

A DPA is required whenever another organisation processes personal data on your behalf.

For most businesses, this happens more often than they realise.


Examples include:

Customer Relationship Management Systems

If you use software such as HubSpot, Salesforce or Pipedrive to store customer information, those providers are typically acting as processors.

Payroll Services

An outsourced payroll provider processes employee data on your behalf and usually requires a DPA.

Cloud Storage Providers

Services such as Microsoft 365, Google Workspace and Dropbox process personal data stored within their platforms.

Marketing Platforms

Email marketing services often process customer names, email addresses and marketing preferences.

IT Support Providers

Managed service providers frequently have access to employee and customer information as part of service delivery.


When Is a DPA Not Required?

A common misconception is that every data sharing arrangement needs a DPA. Not necessarily.


If another organisation uses personal data for its own purposes, rather than solely on your instructions, it may be acting as a separate controller.

Examples could include:

  • Banks processing payment transactions

  • Insurers handling claims

  • Accountants fulfilling legal obligations

  • Solicitors providing legal advice


In these situations, a DPA may not be the correct document. The key question is always:

Are they processing personal data on your behalf, or for their own purposes?


What Needs to Be Included in a DPA?

One of the most common GDPR-related searches is:

"What must be included in a Data Processing Agreement?"

Under Article 28 UK GDPR, a compliant DPA must include specific information and obligations.


Description of the Processing

The agreement must set out:

  • The purpose of the processing

  • How long processing will continue

  • The categories of personal data involved

  • The categories of individuals whose data is being processed

  • The parties' rights and responsibilities


Processing Only on Instructions

The processor must only process data on documented instructions from the controller.


Confidentiality

Anyone handling the data must be subject to confidentiality obligations.


Security Measures

The processor must implement appropriate technical and organisational measures to protect personal data.


Use of Sub-Processors

The agreement should explain whether other processors can be appointed and how the controller will be informed.


Support with Data Subject Rights

The processor should assist the controller in responding to requests such as:

  • Subject Access Requests

  • Deletion requests

  • Rectification requests


Data Breach Assistance

Processors must assist controllers where necessary in relation to personal data breaches and security incidents.


Data Deletion or Return

The agreement should explain what happens to personal data when the contract ends.

Audit Rights

Controllers should be able to obtain assurance that processors are complying with their obligations.


Common DPA Examples

Many businesses already have multiple Data Processing Agreements in place.

Examples include:

  • Microsoft 365 DPA

  • Google Workspace DPA

  • HubSpot DPA

  • Mailchimp DPA

  • Xero DPA

  • QuickBooks DPA

  • Salesforce DPA


In fact, if your organisation uses more than a handful of cloud services, you are likely relying on numerous processor agreements every day.


Frequently Asked Questions

What does DPA stand for?

DPA stands for Data Processing Agreement. They may also be referred to as a Data Processing Contract.


Is a DPA legally required?

Yes, where a processor is handling personal data on behalf of a controller, Article 28 UK GDPR requires a written agreement.


Do small businesses need DPAs?

Yes. UK GDPR applies regardless of organisation size where personal data is processed.


Do I need a DPA with every supplier?

No. Only suppliers acting as data processors require a DPA.


Can I use the supplier's standard DPA?

In many cases, yes. Most major software providers publish standard Article 28-compliant DPAs for customers to accept. However, they should still be reviewed as part of supplier due diligence.



bottom of page