← Return to Menu
🏢
What is the Data Controller's legal name?
The party that determines purposes and means of processing
Controller Full Legal Name *
Continue
📍
Controller's registration and contact details
Address and company registration information
Controller Address *
Company Registration Number (optional)
Contact Email
Back
Continue
🔧
What is the Data Processor's legal name?
The third party processing data on your behalf
Processor Full Legal Name *
Back
Continue
📮
Processor's registration and contact details
Address and company registration information
Processor Address *
Company Registration Number (optional)
Contact Email
Back
Continue
📅
When is the agreement dated?
The official date this DPA comes into effect
Agreement Date *
Back
Continue
⏱️
What is the term of this agreement?
Most DPAs run indefinitely until the service contract ends
♾️
Indefinite (Until termination)
📆
Fixed Term (Specific end date)
GDPR Tip: DPAs typically run indefinitely and terminate when the underlying service agreement ends. This ensures continuous GDPR compliance throughout the business relationship.
Back
Continue
📋
What is the subject matter of processing?
GDPR Article 28(3) requirement - describe the services provided
Subject Matter of Processing *
GDPR Article 28(3): You must clearly describe what the processor will do with the data. Be specific about the services provided.
Back
Continue
⚙️
What is the nature of processing?
Describe the type of processing operations
Nature of Processing *
Examples: Storage, retrieval, analysis, transmission, encryption, deletion, backup, archiving, monitoring, reporting.
Back
Continue
🎯
What is the purpose of processing?
Why the processing is necessary
Purpose of Processing *
GDPR Tip: Purpose must align with your lawful basis for processing. Be clear and specific.
Back
Continue
📊
What types of personal data will be processed?
List all categories of personal data
Types of Personal Data *
Be Comprehensive: List ALL data types. This affects data subject rights and breach notification requirements.
Back
Continue
👥
Who do the data subjects include?
Categories of people whose data is being processed
Categories of Data Subjects *
Examples: Customers, employees, website visitors, prospective customers, contractors, suppliers, business contacts.
Back
Continue
🛡️
What security measures are in place?
GDPR Article 32 - technical and organisational measures
Security Measures *
ICO Guidance: Security measures must be appropriate to the risk. Be specific - generic statements are non-compliant.
Back
Continue
🔗
Will the processor use sub-processors?
GDPR Article 28(2) requires written authorisation
✅
General Authorisation (with list)
GDPR Requirement: Controller must have opportunity to object before new sub-processors are engaged. 30 days is standard.
Back
Continue
🌍
Will data be transferred outside UK/EEA?
GDPR Chapter V requires safeguards for international transfers
🇬🇧
No - All processing within UK/EEA
✈️
Yes - International transfers occur
Post-Brexit: UK-EEA transfers don't require additional safeguards. Transfers to US require SCCs/IDTA even under EU-US Data Privacy Framework.
Back
Continue
🔍
How much notice for audits?
GDPR Article 28(3)(h) gives controllers right to audit
Audit Notice Period (days) *
Balance: 30 days is standard - enough time for processor to prepare, but not so long that compliance issues go undetected.
Back
Continue
🗑️
When should data be deleted after termination?
GDPR Article 28(3)(g) requires deletion or return of data
Best Practice: 30 days allows for transition period while ensuring timely deletion. Immediate deletion may be impractical for complex systems.
Back
Continue
⚖️
What is the liability cap?
GDPR Article 82 allows unlimited liability by default
♾️
Unlimited (GDPR default)
💰
Annual fees paid to processor
Important: Liability caps don't apply to ICO fines or data subject compensation claims under GDPR Article 82.
Back
Continue
⚖️
Which governing law and jurisdiction?
Choose the UK jurisdiction for this agreement
Governing Law *
England and Wales
Scotland
Northern Ireland
Jurisdiction *
English Courts
Scottish Courts
Northern Irish Courts
Back
Generate Agreement