Hatch resource banner image for How to draft a data processing agreement

How to draft a data processing agreement

A Data Processing Agreement (DPA) is a vital legal document that proves your business handles personal data safely and stays compliant with UK GDPR laws.

If your business processes personal data on behalf of another company, you are legally required under UK GDPR to have a Data Processing Agreement (DPA) in place. This document is a non-negotiable for B2B contracts, as it sets out the rules for how you handle their data, ensures security standards are met, and defines your liabilities as a 'data processor'.

What is a DPA?

In the world of data protection, there are two main roles: the Controller (your client, who decides why and how data is processed) and the Processor (you, who carries out the technical processing). The DPA is the contract that binds the two. It ensures that you only use the data as instructed and provides your client with the legal assurance that you won't mishandle their information.

What to include in your DPA

To be compliant with UK law, your DPA must be specific. It cannot be a vague statement about "keeping data safe." You should include a table or a clear section detailing the following:

  • The Subject Matter: What kind of data are you processing? (e.g., customer email addresses, employee payroll info).
  • Duration: How long will you keep this data? Usually, this is for the length of the service contract.
  • Nature and Purpose: Why are you processing it? (e.g., "To provide cloud-based analytics services").
  • Categories of Data Subjects: Whose data is it? (e.g., your client's customers, or their UK-based employees).

Core processor obligations

Your DPA must explicitly state that you, as the processor, will:

  1. Only process data on the written instructions of the controller.
  2. Ensure all staff handling the data are committed to confidentiality.
  3. Implement appropriate technical and organisational measures to ensure a high level of security.
  4. Only use 'sub-processors' (like your hosting provider) with the client's prior written consent.
  5. Assist the client in responding to 'Subject Access Requests' (where individuals ask to see their data).
  6. Delete or return all personal data at the end of the contract.

Practical tips for drafting

While you can find templates online, it is often best to have a solicitor review your DPA, especially if you are dealing with sensitive data. Here are a few best practices:

DoDon't
Use plain, easy-to-understand English.Use overly dense legal jargon that confuses your clients.
Be realistic about your security capabilities.Promise "unbreakable" security that you cannot technically guarantee.
Keep a version-controlled master copy.Allow every client to rewrite your core security terms.

Note: Having a standard DPA ready to go will significantly speed up your sales process when dealing with larger corporate clients who have strict compliance departments.

Created by hatch. • Updated on April 29, 2026