Sub Processing Agreement Template for England and Wales

Generate a bespoke document

What is a Sub Processing Agreement?

A Sub Processing Agreement is essential when a data processor wishes to engage another party (sub-processor) to carry out specific data processing activities. This agreement, governed by English and Welsh law, ensures compliance with UK data protection regulations, particularly the UK GDPR and Data Protection Act 2018. It defines the scope of processing activities, security requirements, breach notification procedures, and audit rights. The document is crucial for maintaining data protection compliance throughout the processing chain and protecting all parties' interests.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Sub Processing Agreement

A Sub Processing Agreement is a critical legal document that governs the relationship between a data processor and sub-processor when handling personal data in England and Wales. This agreement ensures that when your organisation (the processor) needs to engage another party to carry out specific data processing activities, you remain compliant with UK data protection laws while clearly defining responsibilities and obligations for all parties involved.

When do you need this document?

You need a Sub Processing Agreement whenever you're acting as a data processor and wish to engage a third-party service provider to handle personal data on your behalf. This commonly occurs when outsourcing IT services, cloud storage, customer support, or specialised data analytics. The agreement is also essential when your existing processing arrangements require additional technical expertise or capacity that you cannot provide internally. Without this document, you risk breaching your obligations to the original data controller and potentially violating UK GDPR requirements. The agreement becomes particularly crucial when processing sensitive personal data or when your sub-processor is located outside the UK, as additional safeguards and transfer mechanisms may be required.

Key legal considerations

Your Sub Processing Agreement must clearly define the scope of permitted processing activities, specifying exactly what personal data can be processed and for what purposes. The document should establish robust security measures that meet or exceed those required under UK GDPR Article 32, including technical and organisational measures to protect personal data. You must include provisions for data breach notification, ensuring your sub-processor will alert you within specified timeframes so you can meet your own notification obligations to the data controller. The agreement should grant you audit rights and the ability to conduct inspections to verify compliance. Additionally, you must ensure your sub-processor provides sufficient guarantees regarding their ability to implement appropriate technical and organisational measures, and that they understand their direct liability under UK GDPR for certain breaches.

Legal requirements in England and Wales

Under UK GDPR and the Data Protection Act 2018, you can only engage sub-processors with prior written authorisation from the original data controller, either specific or general. Your agreement must ensure the sub-processor is subject to the same data protection obligations that bind you as the processor. The document must include provisions for international transfers if your sub-processor is outside the UK, ensuring appropriate safeguards such as adequacy decisions, standard contractual clauses, or other approved transfer mechanisms. You remain fully liable to the data controller for your sub-processor's performance, making it essential that your agreement includes strong indemnification and liability clauses. The agreement must also comply with English contract law principles and include proper termination clauses that ensure secure data return or destruction when the processing relationship ends.

GOVERNING LAW

Applicable law

This Sub Processing Agreement is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The UK General Data Protection Regulation as incorporated into UK law post-Brexit, serving as the primary data protection legislation for personal data processing in the UK

Data Protection Act 2018: The UK's domestic data protection law that supplements the UK GDPR and provides additional data protection requirements specific to the UK context

PECR 2003: Privacy and Electronic Communications Regulations governing electronic communications, cookies, and direct marketing in the UK

EU GDPR: European Union's General Data Protection Regulation, relevant when processing EU residents' data or operating across UK-EU borders

UK Adequacy Decisions: Framework determining which countries are deemed to provide adequate data protection standards for international data transfers from the UK

Standard Contractual Clauses: Legal mechanisms approved by UK authorities for ensuring adequate protection when transferring personal data internationally

Binding Corporate Rules: Internal codes of conduct for multinational companies transferring data between group entities, approved by relevant supervisory authorities

ICO Guidelines: Official guidance and codes of practice issued by the Information Commissioner's Office, the UK's data protection regulator

EDPB Guidelines: European Data Protection Board guidelines that may be relevant for UK-EU data processing activities and best practices

FCA Requirements: Financial Conduct Authority's specific data protection requirements for financial services sector

NHS Data Protection: Specific data protection requirements and guidelines for handling healthcare data within the NHS framework

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.