Commissioned Data Processing Agreement Template for England and Wales

Generate a bespoke document

What is a Commissioned Data Processing Agreement?

A Commissioned Data Processing Agreement is essential whenever an organization (the controller) engages another party (the processor) to process personal data on its behalf. This agreement is mandatory under UK data protection law and must be in place before processing begins. It defines the scope of processing activities, ensures compliance with UK GDPR and the Data Protection Act 2018, and protects both parties by clearly establishing their respective rights and obligations. The agreement should be used for any business relationship involving the processing of personal data, from cloud services to payroll processing.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Commissioned Data Processing Agreement

When your business needs to engage a third party to handle personal data on your behalf, you must establish a formal legal relationship through a Commissioned Data Processing Agreement. This contract is not optional under England and Wales law—it's a mandatory requirement that must be in place before any personal data processing begins. The agreement creates clear boundaries between you as the data controller and your chosen data processor, ensuring both parties understand their legal obligations and responsibilities under UK data protection legislation.

When do you need this document?

You need a Commissioned Data Processing Agreement whenever you engage external organizations to process personal data on your behalf. This includes hiring cloud storage providers to store customer information, outsourcing payroll services that handle employee data, engaging marketing agencies that process customer contact details, or contracting IT support companies that may access your systems containing personal information. The agreement is also required when working with sub-processors, such as when your primary processor engages additional third parties to fulfill their obligations. Even temporary or project-based processing relationships require this formal documentation to ensure compliance with UK data protection law.

Key legal considerations

Your agreement must clearly define the scope and purpose of processing, specifying exactly what personal data will be processed and for what legitimate purposes. You need to establish comprehensive security measures that both parties must implement, including technical and organizational safeguards appropriate to the risk level. The contract should address data retention periods, deletion procedures, and the processor's obligations regarding data subject rights requests such as access, rectification, and erasure. Sub-processing arrangements require your explicit written authorization, and the processor must ensure any sub-processors provide equivalent protection levels. Breach notification procedures must be clearly outlined, including timescales for reporting incidents and the processor's duty to assist with regulatory notifications and investigations.

Legal requirements in England and Wales

Under the UK GDPR and Data Protection Act 2018, your processing agreement must include specific mandatory clauses covering the subject matter, duration, nature and purpose of processing, categories of personal data, and types of data subjects. The processor must only process personal data on your documented instructions and must not transfer data to third countries without appropriate safeguards and your authorization. You retain legal liability as the data controller for ensuring the processor provides sufficient guarantees regarding technical and organizational security measures. The Information Commissioner's Office (ICO) has enforcement powers to impose significant fines for non-compliance, making proper documentation essential. Your agreement must also address audit rights, allowing you to verify the processor's compliance with their obligations, and must include provisions for contract termination and return or destruction of personal data.

GOVERNING LAW

Applicable law

This Commissioned Data Processing Agreement is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The UK General Data Protection Regulation - primary legislation governing data protection in the UK post-Brexit, setting out fundamental principles for data processing

DPA 2018: Data Protection Act 2018 - the UK's implementation of data protection law, working alongside and supplementing the UK GDPR

PECR: Privacy and Electronic Communications Regulations 2003 - specific rules for electronic communications, including electronic marketing and cookies

ICO Guidance: Information Commissioner's Office guidance and codes of practice - authoritative interpretation and practical guidance on applying data protection law

EDPB Guidelines: European Data Protection Board guidelines - while not binding post-Brexit, remain influential for UK data protection practice and interpretation

Article 28 Requirements: Specific requirements under UK GDPR Article 28 for data processing agreements, including mandatory contractual terms

International Transfer Rules: Requirements for transferring personal data outside the UK, including adequacy decisions and appropriate safeguards

Security Requirements: Data security obligations under Article 32 UK GDPR, including technical and organizational measures

Breach Notification: Obligations to notify data controllers and/or authorities of personal data breaches within specified timeframes

Sub-processing Rules: Requirements for appointing and managing sub-processors, including obtaining necessary authorizations

Data Subject Rights: Obligations to assist controllers in responding to data subject rights requests under UK GDPR

Record Keeping: Requirements to maintain records of processing activities and demonstrate compliance with data protection principles

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.