Third Party Data Processing Agreement Template for England and Wales
Generate a bespoke document
What is a Third Party Data Processing Agreement?
A Third Party Data Processing Agreement is required whenever an organization (controller) engages another party (processor) to process personal data on its behalf. This agreement, governed by English and Welsh law, is mandated by Article 28 of the UK GDPR and the Data Protection Act 2018. It sets out the processor's obligations, including data security, confidentiality, sub-processing restrictions, and breach notification requirements. The agreement is essential for demonstrating compliance with data protection regulations and establishing clear accountability between parties.
Trusted by high-performance teams
About the Third Party Data Processing Agreement
When your organisation engages third-party service providers to handle personal data, you need a robust legal framework to ensure compliance with UK data protection laws. A Third Party Data Processing Agreement serves as this critical legal instrument, establishing clear obligations and responsibilities between data controllers and processors under England and Wales jurisdiction.
When do you need this document?
You must implement this agreement whenever you engage external parties to process personal data on your behalf. This includes cloud storage providers handling customer information, payroll companies managing employee data, marketing agencies processing prospect details, or IT support teams accessing systems containing personal information. The UK GDPR explicitly requires written contracts between controllers and processors, making this agreement legally mandatory rather than optional. Without proper documentation, you risk significant regulatory penalties and potential data breaches that could damage your business reputation and customer trust.
Key legal considerations
The agreement must address several critical legal requirements to ensure compliance. Processor obligations under Article 28 UK GDPR form the foundation, requiring processors to act only on documented instructions from controllers. Security measures must meet appropriate technical and organisational standards, including encryption, access controls, and regular security assessments. Sub-processing arrangements require explicit controller consent, with processors remaining fully liable for sub-processor actions. Data breach notification procedures must enable processors to alert controllers within specified timeframes, typically within 72 hours of discovery. International data transfer provisions become crucial when processors operate outside the UK, requiring appropriate safeguards such as adequacy decisions or standard contractual clauses. The agreement should also specify data retention periods, deletion requirements, and audit rights to ensure ongoing compliance verification.
Legal requirements in England and Wales
Under England and Wales law, your Third Party Data Processing Agreement must comply with the UK GDPR and Data Protection Act 2018, which together form the post-Brexit data protection framework. The ICO provides specific guidance on controller-processor relationships, emphasising that controllers remain ultimately responsible for data protection compliance even when using processors. The agreement must specify the subject matter, duration, nature and purpose of processing, along with categories of personal data and data subjects involved. UK-specific provisions may include requirements for processing data within the UK or ensuring processors implement appropriate measures for international transfers. Regular compliance monitoring becomes essential, with controllers required to use only processors that provide sufficient guarantees regarding technical and organisational security measures. The agreement should also address potential changes in UK data protection law and ensure processors can adapt to evolving regulatory requirements while maintaining continuous compliance throughout the processing relationship.
GOVERNING LAW
Applicable law
This Third Party Data Processing Agreement is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

