Third Party Data Processing Agreement Template for England and Wales

Generate a bespoke document

What is a Third Party Data Processing Agreement?

A Third Party Data Processing Agreement is required whenever an organization (controller) engages another party (processor) to process personal data on its behalf. This agreement, governed by English and Welsh law, is mandated by Article 28 of the UK GDPR and the Data Protection Act 2018. It sets out the processor's obligations, including data security, confidentiality, sub-processing restrictions, and breach notification requirements. The agreement is essential for demonstrating compliance with data protection regulations and establishing clear accountability between parties.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Third Party Data Processing Agreement

When your organisation engages third-party service providers to handle personal data, you need a robust legal framework to ensure compliance with UK data protection laws. A Third Party Data Processing Agreement serves as this critical legal instrument, establishing clear obligations and responsibilities between data controllers and processors under England and Wales jurisdiction.

When do you need this document?

You must implement this agreement whenever you engage external parties to process personal data on your behalf. This includes cloud storage providers handling customer information, payroll companies managing employee data, marketing agencies processing prospect details, or IT support teams accessing systems containing personal information. The UK GDPR explicitly requires written contracts between controllers and processors, making this agreement legally mandatory rather than optional. Without proper documentation, you risk significant regulatory penalties and potential data breaches that could damage your business reputation and customer trust.

Key legal considerations

The agreement must address several critical legal requirements to ensure compliance. Processor obligations under Article 28 UK GDPR form the foundation, requiring processors to act only on documented instructions from controllers. Security measures must meet appropriate technical and organisational standards, including encryption, access controls, and regular security assessments. Sub-processing arrangements require explicit controller consent, with processors remaining fully liable for sub-processor actions. Data breach notification procedures must enable processors to alert controllers within specified timeframes, typically within 72 hours of discovery. International data transfer provisions become crucial when processors operate outside the UK, requiring appropriate safeguards such as adequacy decisions or standard contractual clauses. The agreement should also specify data retention periods, deletion requirements, and audit rights to ensure ongoing compliance verification.

Legal requirements in England and Wales

Under England and Wales law, your Third Party Data Processing Agreement must comply with the UK GDPR and Data Protection Act 2018, which together form the post-Brexit data protection framework. The ICO provides specific guidance on controller-processor relationships, emphasising that controllers remain ultimately responsible for data protection compliance even when using processors. The agreement must specify the subject matter, duration, nature and purpose of processing, along with categories of personal data and data subjects involved. UK-specific provisions may include requirements for processing data within the UK or ensuring processors implement appropriate measures for international transfers. Regular compliance monitoring becomes essential, with controllers required to use only processors that provide sufficient guarantees regarding technical and organisational security measures. The agreement should also address potential changes in UK data protection law and ensure processors can adapt to evolving regulatory requirements while maintaining continuous compliance throughout the processing relationship.

GOVERNING LAW

Applicable law

This Third Party Data Processing Agreement is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The UK General Data Protection Regulation - primary legislation governing data protection in the UK post-Brexit, setting out fundamental principles for data processing, individual rights, and organizational obligations

DPA 2018: Data Protection Act 2018 - the UK's implementation of data protection law, working alongside and supplementing the UK GDPR, providing specific provisions for data processing in the UK context

PECR: Privacy and Electronic Communications Regulations 2003 - specific rules for electronic communications, including requirements for electronic marketing, cookies, and communication services

ICO Guidance: Information Commissioner's Office guidance and codes of practice - authoritative interpretation and practical guidance on how to apply data protection legislation in the UK

EDPB Guidelines: European Data Protection Board guidelines - while not binding post-Brexit, these remain influential for UK data protection practice and interpretation

UK Case Law: Relevant judicial decisions from UK courts on data protection matters, establishing precedents and interpretations of data protection legislation

International Transfer Requirements: Post-Brexit requirements for transferring personal data outside the UK, including adequate safeguards and transfer mechanisms

Article 28 Requirements: Specific requirements under UK GDPR Article 28 detailing mandatory processor obligations that must be included in data processing agreements

Article 32 Security Requirements: Data security requirements under UK GDPR Article 32 specifying technical and organizational measures for ensuring appropriate security of personal data

Sub-processor Requirements: Rules and obligations regarding the appointment and oversight of sub-processors, including required contractual terms and prior authorizations

Breach Notification Obligations: Requirements for notifying data controllers and authorities of personal data breaches, including timing and content of notifications

Data Subject Rights: Obligations regarding handling and facilitating data subject rights requests, including access, rectification, erasure, and portability

E-Commerce Regulations: Electronic Commerce (EC Directive) Regulations 2002 - relevant for electronic contracts and online service providers

Contract Law Principles: Common law principles of contract law in England and Wales that affect the overall validity and enforcement of the agreement

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.