Corven › Guides

Do I need a data processing agreement with my suppliers?

Corven guide, 7 October 2026

Yes, if a supplier handles personal data on your behalf. Article 28(3) of the UK GDPR requires processing by a processor to be governed by a contract, or another binding legal act, that sets out what the processor may do with the data. Article 28(9) requires it to be in writing, which includes electronic form.

Who is a processor

A processor is a supplier that processes personal data for you and on your instructions: a payroll bureau, a cloud software provider, a mailing house or an outsourced IT company. Article 28(1) also requires you to use only processors that give sufficient guarantees of appropriate technical and organisational measures.

What the agreement must say

Article 28(3) requires the contract to set out the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of people it concerns, and your obligations and rights. It must also require the processor, among other things, to act only on your documented instructions, to ensure that its staff are bound by confidentiality, to take the security measures required by Article 32, to engage another processor only with your written authorisation, to help you respond to people exercising their rights, to delete or return the data at the end of the service, and to give you the information needed to show compliance, including allowing audits.

Subcontractors

Under Article 28(4), if your processor engages another processor, it must impose the same obligations on that subcontractor, and it remains fully liable to you if the subcontractor fails.

Our data processing agreement is standard controller and processor terms, checked by a solicitor of England and Wales. The price is £195, with no VAT charged, and it comes back within 24 hours of us having everything.

Order the data processing agreement

This guide is general information about the law of England and Wales. It is not advice on your situation.