What Is a Data Processing Agreement (DPA)? When You Need One and What It Must Include
- Joe Stock

- Jul 1
- 3 min read
If you've ever signed up to a CRM, payroll system, cloud hosting provider or marketing platform, you've probably been presented with a Data Processing Agreement (DPA).
But what is a DPA, when do you need one, and what should it contain?
A Data Processing Agreement is one of the most important documents in UK GDPR compliance. It governs how a third party handles personal data on your behalf and helps ensure both organisations understand their responsibilities.
In this guide, we'll explain:
What a Data Processing Agreement is
When a DPA is required
What needs to be included in a DPA
Common examples of DPAs in everyday business
Mistakes organisations frequently make
What Is a Data Processing Agreement?
A Data Processing Agreement (DPA) is a contract between:
A data controller (the organisation deciding why and how personal data is used); and
A data processor (the organisation processing personal data on behalf of the controller).
The UK GDPR requires controllers to have a written contract in place whenever they appoint a processor to handle personal data on their behalf. The contract must contain specific requirements set out in Article 28 UK GDPR.
In simple terms, a DPA sets the rules for how personal data will be handled, protected and managed by the processor.
When Do I Need a DPA?
A DPA is required whenever another organisation processes personal data on your behalf.
For most businesses, this happens more often than they realise.
Examples include:
Customer Relationship Management Systems
If you use software such as HubSpot, Salesforce or Pipedrive to store customer information, those providers are typically acting as processors.
Payroll Services
An outsourced payroll provider processes employee data on your behalf and usually requires a DPA.
Cloud Storage Providers
Services such as Microsoft 365, Google Workspace and Dropbox process personal data stored within their platforms.
Marketing Platforms
Email marketing services often process customer names, email addresses and marketing preferences.
IT Support Providers
Managed service providers frequently have access to employee and customer information as part of service delivery.
When Is a DPA Not Required?
A common misconception is that every data sharing arrangement needs a DPA. Not necessarily.
If another organisation uses personal data for its own purposes, rather than solely on your instructions, it may be acting as a separate controller.
Examples could include:
Banks processing payment transactions
Insurers handling claims
Accountants fulfilling legal obligations
Solicitors providing legal advice
In these situations, a DPA may not be the correct document. The key question is always:
Are they processing personal data on your behalf, or for their own purposes?
What Needs to Be Included in a DPA?
One of the most common GDPR-related searches is:
"What must be included in a Data Processing Agreement?"
Under Article 28 UK GDPR, a compliant DPA must include specific information and obligations.
Description of the Processing
The agreement must set out:
The purpose of the processing
How long processing will continue
The categories of personal data involved
The categories of individuals whose data is being processed
The parties' rights and responsibilities
Processing Only on Instructions
The processor must only process data on documented instructions from the controller.
Confidentiality
Anyone handling the data must be subject to confidentiality obligations.
Security Measures
The processor must implement appropriate technical and organisational measures to protect personal data.
Use of Sub-Processors
The agreement should explain whether other processors can be appointed and how the controller will be informed.
Support with Data Subject Rights
The processor should assist the controller in responding to requests such as:
Subject Access Requests
Deletion requests
Rectification requests
Data Breach Assistance
Processors must assist controllers where necessary in relation to personal data breaches and security incidents.
Data Deletion or Return
The agreement should explain what happens to personal data when the contract ends.
Audit Rights
Controllers should be able to obtain assurance that processors are complying with their obligations.
Common DPA Examples
Many businesses already have multiple Data Processing Agreements in place.
Examples include:
Microsoft 365 DPA
Google Workspace DPA
HubSpot DPA
Mailchimp DPA
Xero DPA
QuickBooks DPA
Salesforce DPA
In fact, if your organisation uses more than a handful of cloud services, you are likely relying on numerous processor agreements every day.
Frequently Asked Questions
What does DPA stand for?
DPA stands for Data Processing Agreement. They may also be referred to as a Data Processing Contract.
Is a DPA legally required?
Yes, where a processor is handling personal data on behalf of a controller, Article 28 UK GDPR requires a written agreement.
Do small businesses need DPAs?
Yes. UK GDPR applies regardless of organisation size where personal data is processed.
Do I need a DPA with every supplier?
No. Only suppliers acting as data processors require a DPA.
Can I use the supplier's standard DPA?
In many cases, yes. Most major software providers publish standard Article 28-compliant DPAs for customers to accept. However, they should still be reviewed as part of supplier due diligence.



