Data Protection Addendum Template for England and Wales
Generate a bespoke document
What is a Data Protection Addendum?
The Data Protection Addendum is essential when organizations engage in activities involving the processing of personal data in the United Kingdom. This document supplements existing commercial agreements to ensure compliance with UK data protection laws, particularly the UK GDPR and Data Protection Act 2018. It defines roles, responsibilities, and obligations regarding data processing activities, security measures, and breach management. The Data Protection Addendum is particularly crucial when one party processes personal data on behalf of another, establishing clear guidelines for data handling and protection.
Trusted by high-performance teams
About the Data Protection Addendum
A Data Protection Addendum is a crucial legal document that establishes binding obligations between organizations when personal data is processed in England and Wales. This addendum supplements your existing commercial agreements to ensure full compliance with UK data protection legislation, including the UK GDPR and Data Protection Act 2018. It clearly defines the roles and responsibilities of data controllers and processors, establishing a framework for lawful data handling.
When do you need this document?
You need a Data Protection Addendum whenever you engage a third party to process personal data on your behalf, or when you process personal data for another organization. This includes cloud service providers handling customer data, marketing agencies processing contact lists, payroll companies managing employee information, or IT support firms accessing user accounts. The document is also essential when establishing data sharing arrangements between organizations, implementing new software systems that handle personal data, or engaging international service providers that may transfer data outside the UK.
Key legal considerations
The addendum must clearly define whether each party acts as a data controller, processor, or joint controller under UK GDPR. You should specify the categories of personal data being processed, the purposes of processing, and the duration of the arrangement. Security measures are critical and must include appropriate technical and organizational safeguards to protect personal data. The document should address data subject rights, including how requests for access, deletion, or rectification will be handled. Breach notification procedures must be established, requiring processors to notify controllers within 72 hours of becoming aware of a breach. If data transfers occur internationally, you must include appropriate transfer mechanisms such as adequacy decisions or Standard Contractual Clauses.
Legal requirements in England and Wales
Under UK GDPR and the Data Protection Act 2018, data processing agreements must meet specific statutory requirements. The addendum must ensure lawful bases for processing are clearly identified and documented. For special category data, additional safeguards and explicit consent mechanisms may be required. The document must comply with Privacy and Electronic Communications Regulations (PECR) if electronic communications are involved. Data controllers remain fully liable for compliance even when using processors, making clear contractual obligations essential. The Information Commissioner's Office (ICO) expects detailed records of processing activities, and your addendum should facilitate this requirement. Penalties for non-compliance can reach £17.5 million or 4% of annual global turnover, making proper documentation crucial for regulatory protection.
GOVERNING LAW
Applicable law
This Data Protection Addendum is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

