Supplier Data Processing Agreement Template for England and Wales
Generate a bespoke document
What is a Supplier Data Processing Agreement?
The Supplier Data Processing Agreement is essential when an organization (controller) engages a supplier (processor) to process personal data on its behalf. This agreement, governed by English and Welsh law, is required under Article 28 of the UK GDPR and must be in place before any data processing begins. It defines the scope of processing, security requirements, confidentiality obligations, and procedures for handling data breaches. The agreement is particularly crucial in ensuring compliance with data protection regulations and establishing clear accountability between parties.
Trusted by high-performance teams
About the Supplier Data Processing Agreement
When your organization engages suppliers or third parties to handle personal data, you need a robust legal framework to ensure compliance with UK data protection laws. A Supplier Data Processing Agreement creates this essential protection under England and Wales law, establishing clear obligations and responsibilities between your organization as the data controller and your supplier as the data processor.
When do you need this document?
You must have a Supplier Data Processing Agreement in place whenever you engage external suppliers to process personal data on your behalf. This includes cloud service providers handling customer databases, payroll companies processing employee information, marketing agencies managing customer communications, or IT support companies accessing systems containing personal data. The agreement is also required when working with subcontractors who may access personal data during service delivery, or when engaging consultants who need to process personal data as part of their work. Under UK GDPR, this contract must be executed before any data processing activities begin.
Key legal considerations
The agreement must clearly define the subject matter, duration, nature and purpose of processing, along with the categories of personal data and data subjects involved. Your supplier must only process data according to your documented instructions and cannot use the data for their own purposes. Security measures are crucial - the agreement should specify technical and organizational measures to protect personal data, including encryption, access controls, and regular security assessments. Data breach notification procedures must be established, requiring your supplier to notify you without undue delay of any security incidents. The agreement should also address data subject rights, ensuring your supplier assists with responding to access requests, corrections, or deletions. International data transfers require special attention, with appropriate safeguards if your supplier processes data outside the UK.
Legal requirements in England and Wales
Under UK GDPR Article 28, processing by a processor must be governed by a contract that sets out specific mandatory requirements. The Data Protection Act 2018 supplements these obligations with additional UK-specific requirements. Your agreement must include the processor's obligation to assist with data protection impact assessments and prior consultations with the ICO where required. The contract should specify liability arrangements and ensure compliance with the ICO's guidance on data processing agreements. You must conduct due diligence on your supplier's data protection practices and monitor ongoing compliance throughout the relationship. The agreement should also address the return or destruction of personal data at the end of the contract, ensuring no unauthorized retention occurs. Regular reviews of the agreement ensure it remains current with evolving data protection requirements and your business needs.
GOVERNING LAW
Applicable law
This Supplier Data Processing Agreement is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

