Third Party Processor Agreement Template for England and Wales
Generate a bespoke document
What is a Third Party Processor Agreement?
This Third Party Processor Agreement is essential when an organization (the controller) engages another organization (the processor) to process personal data on its behalf. Under English and Welsh law, particularly the UK GDPR and Data Protection Act 2018, such arrangements must be governed by a written contract specifying the processor's obligations, security requirements, and compliance measures. The agreement is crucial for establishing clear accountability, ensuring data protection compliance, and managing risk in data processing relationships.
Frequently Asked Questions
Is a Third Party Processor Agreement legally binding in England and Wales?
Yes, a Third Party Processor Agreement is legally binding in England and Wales when properly executed. Under the UK GDPR and Data Protection Act 2018, data controllers are legally required to have written contracts with data processors that meet specific regulatory requirements. Failure to have a compliant agreement can result in ICO fines up to £17.5 million or 4% of annual turnover.
Can the ICO fine my company for missing a Third Party Processor Agreement?
Yes, the ICO can impose significant penalties for operating without a compliant processor agreement. Under Article 28 of the UK GDPR, data controllers must have written contracts with processors containing mandatory clauses. ICO enforcement action can include administrative fines, enforcement notices, and prosecution in serious cases, making proper documentation essential for regulatory compliance.
How does a Third Party Processor Agreement differ from a Data Sharing Agreement under UK law?
A Third Party Processor Agreement governs relationships where one party processes data on behalf of another (controller-processor), while a Data Sharing Agreement covers situations where both parties act as independent controllers. The processor agreement requires stricter controls, including processing only on documented instructions, while data sharing agreements allow more autonomy but require joint controller arrangements under UK GDPR.
How long does it typically take to negotiate a Third Party Processor Agreement in England and Wales?
Standard processor agreements typically take 2-4 weeks to negotiate and finalise, depending on the complexity of data processing activities. Simple arrangements using established templates may be completed within days, while complex multi-jurisdictional processing or high-risk data categories can take 6-8 weeks. The negotiation timeline often depends on both parties' legal review processes and risk tolerance.
Which UK GDPR clauses must be included in every Third Party Processor Agreement?
Under Article 28 UK GDPR, processor agreements must include specific mandatory clauses: processing only on documented instructions, ensuring processor personnel confidentiality, implementing appropriate technical and organisational measures, not engaging sub-processors without written authorisation, assisting with data subject requests, and deleting or returning data when processing ends. Missing any mandatory clause renders the agreement non-compliant.
Can I get in trouble for using a US-based processor without proper safeguards in my agreement?
Yes, using processors in countries without UK adequacy decisions requires additional safeguards in your agreement. Since the US lacks a general adequacy decision, you must implement Standard Contractual Clauses (SCCs) or alternative transfer mechanisms. The ICO actively monitors international transfers, and non-compliant arrangements can result in suspension orders and significant fines under UK data protection law.
Most common mistakes people make when drafting Third Party Processor Agreements in the UK?
The most frequent errors include failing to specify the subject matter and duration of processing, not defining data categories and data subject types clearly, omitting mandatory security requirements, and inadequate sub-processor provisions. Many also forget to include data breach notification timeframes (typically 24-72 hours) and fail to address data subject rights assistance obligations, both of which are UK GDPR requirements.
About the Third Party Processor Agreement
A Third Party Processor Agreement is a legally required contract that governs the relationship between your organisation (the data controller) and any external company that processes personal data on your behalf (the data processor). Under England and Wales law, you must have this written agreement in place before any data processing begins, ensuring compliance with UK GDPR and Data Protection Act 2018 requirements.
When do you need this document?
You need this agreement whenever you engage external service providers to handle personal data. This includes cloud storage providers, payroll companies, marketing agencies, IT support services, or any vendor that processes customer information, employee records, or other personal data for your business. The agreement is also essential when working with sub-processors who may handle data on behalf of your main processor. If you're expanding internationally and need to transfer data between the UK and EU, this agreement becomes crucial for demonstrating adequate data protection safeguards. Even temporary processing arrangements require this documentation to meet regulatory compliance.
Key legal considerations
The agreement must clearly define the scope and purpose of processing, specifying exactly what data will be processed and for what legitimate business purposes. You need to include detailed security measures that the processor must implement, including technical and organisational safeguards to protect personal data. The contract should address data breach notification procedures, requiring the processor to notify you immediately of any security incidents. Include provisions for data subject rights, ensuring the processor assists you in responding to individual requests for access, correction, or deletion. Consider liability and indemnification clauses that protect your organisation if the processor fails to comply with data protection requirements. The agreement must also cover international data transfers if the processor operates outside the UK, ensuring appropriate transfer mechanisms are in place.
Legal requirements in England and Wales
Under UK GDPR Article 28, you must ensure your processor agreement includes specific mandatory elements: instructions for processing, confidentiality obligations, security measures, use of sub-processors, data subject rights assistance, and deletion or return of data upon contract termination. The Data Protection Act 2018 reinforces these requirements and adds specific provisions for certain types of processing. Your agreement must comply with PECR 2003 if electronic communications data is involved, particularly for email marketing or telecommunications services. The contract should reference the upcoming Data Protection and Digital Information Bill, which may introduce new compliance requirements. You must conduct due diligence on your processor's data protection capabilities and maintain records demonstrating compliance with your contractual obligations.
GOVERNING LAW
Applicable law
This Third Party Processor Agreement is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it