Sub Processing Agreement Template for England and Wales
Generate a bespoke document
What is a Sub Processing Agreement?
A Sub Processing Agreement is essential when a data processor wishes to engage another party (sub-processor) to carry out specific data processing activities. This agreement, governed by English and Welsh law, ensures compliance with UK data protection regulations, particularly the UK GDPR and Data Protection Act 2018. It defines the scope of processing activities, security requirements, breach notification procedures, and audit rights. The document is crucial for maintaining data protection compliance throughout the processing chain and protecting all parties' interests.
Trusted by high-performance teams
About the Sub Processing Agreement
A Sub Processing Agreement is a critical legal document that governs the relationship between a data processor and sub-processor when handling personal data in England and Wales. This agreement ensures that when your organisation (the processor) needs to engage another party to carry out specific data processing activities, you remain compliant with UK data protection laws while clearly defining responsibilities and obligations for all parties involved.
When do you need this document?
You need a Sub Processing Agreement whenever you're acting as a data processor and wish to engage a third-party service provider to handle personal data on your behalf. This commonly occurs when outsourcing IT services, cloud storage, customer support, or specialised data analytics. The agreement is also essential when your existing processing arrangements require additional technical expertise or capacity that you cannot provide internally. Without this document, you risk breaching your obligations to the original data controller and potentially violating UK GDPR requirements. The agreement becomes particularly crucial when processing sensitive personal data or when your sub-processor is located outside the UK, as additional safeguards and transfer mechanisms may be required.
Key legal considerations
Your Sub Processing Agreement must clearly define the scope of permitted processing activities, specifying exactly what personal data can be processed and for what purposes. The document should establish robust security measures that meet or exceed those required under UK GDPR Article 32, including technical and organisational measures to protect personal data. You must include provisions for data breach notification, ensuring your sub-processor will alert you within specified timeframes so you can meet your own notification obligations to the data controller. The agreement should grant you audit rights and the ability to conduct inspections to verify compliance. Additionally, you must ensure your sub-processor provides sufficient guarantees regarding their ability to implement appropriate technical and organisational measures, and that they understand their direct liability under UK GDPR for certain breaches.
Legal requirements in England and Wales
Under UK GDPR and the Data Protection Act 2018, you can only engage sub-processors with prior written authorisation from the original data controller, either specific or general. Your agreement must ensure the sub-processor is subject to the same data protection obligations that bind you as the processor. The document must include provisions for international transfers if your sub-processor is outside the UK, ensuring appropriate safeguards such as adequacy decisions, standard contractual clauses, or other approved transfer mechanisms. You remain fully liable to the data controller for your sub-processor's performance, making it essential that your agreement includes strong indemnification and liability clauses. The agreement must also comply with English contract law principles and include proper termination clauses that ensure secure data return or destruction when the processing relationship ends.
GOVERNING LAW
Applicable law
This Sub Processing Agreement is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

