Hatch resource banner image for How to draft a data processing agreement template

How to draft a data processing agreement template

Protect your business and meet your legal obligations by formalising how you handle your clients' personal data.

If you handle personal information on behalf of a client—such as processing their payroll or managing their bookkeeping records—you are legally required under UK GDPR to have a written Data Processing Agreement (DPA) in place. This document acts as a binding contract that outlines your responsibilities and ensures both you and your client are protected and compliant with data protection laws.

Why a DPA is essential

In the world of accountancy and professional services, your client is typically the Data Controller (the one who decides why the data is being processed), and you are the Data Processor (the one carrying out the work). Article 28 of the UK GDPR states that a processor must not engage in processing unless they have a written contract with the controller.

Having a solid DPA template not only keeps you on the right side of the law but also demonstrates to your clients that you take their security and privacy seriously, which is vital for building a professional reputation.

What your DPA template must include

To be legally compliant, your DPA needs to be specific. It shouldn't just be a vague promise to "keep data safe." It must include the following details:

  • The Subject Matter: What exactly are you doing? (e.g., "Monthly payroll processing").
  • Duration: How long will the processing last? (e.g., "For the duration of the service contract").
  • Nature and Purpose: Why are you processing the data? (e.g., "To ensure employees are paid and tax is reported to HMRC").
  • Types of Personal Data: Be specific. This might include names, home addresses, National Insurance numbers, and salary details.
  • Categories of Data Subjects: Who does the data belong to? (e.g., "The client's employees" or "The client's customers").

Standard Mandatory Clauses

In addition to the specifics above, the law requires you to include several "Standard Clauses" where you, as the processor, agree to:

Clause Type What you are promising
Duty of Confidence You ensure all staff handling the data have committed to confidentiality.
Security Measures You have appropriate technical and organisational measures to keep data secure.
Sub-processors You will not hire another person to help with the data without the client's written permission.
Data Breaches You will notify the client immediately if you discover a data breach.
Deletion or Return You will delete or return all data at the end of the contract.

How to create and use your template

  1. Start with a reputable base: You don't need to write this from scratch. The Information Commissioner's Office (ICO) provides standard contractual clauses, and most professional accounting bodies provide templates for their members.
  2. Customise for your niche: If you specialise in a specific area, make sure the "Types of Data" section reflects the actual work you do.
  3. Integrate with your onboarding: The most efficient way to use a DPA is to include it as a schedule or appendix to your main contract. This ensures it gets signed at the same time as you begin the relationship.

Top Tip: Even if you are a solo practitioner, these rules apply. Don't fall into the trap of thinking you are "too small" for a DPA; the law applies to everyone processing personal data in a business context.

Created by hatch. • Updated on May 14, 2026