How to Use This Checklist
Click each checkbox to mark items as complete. Your progress is automatically saved to your browser. Use this checklist to verify every requirement before, during, and after creating your Data Processing Agreement.
✅ Preparing Your Data Processing Agreement
1. Before starting: Gather all relevant documentation and information before starting
2. While completing: Verify every section against all 64 compliance points
3. Before signing: Review all sections for completeness before finalising
⚠️ Key Data Processing Agreement Requirements
📋 Key Purpose: A Data Processing Agreement is a legally required contract between a data controller and data processor under UK GDPR Article 28. It sets out the terms for processing personal data on behalf of the controller.
⚖️ Legal Framework: Required by UK GDPR Article 28 and the Data Protection Act 2018. The ICO can take enforcement action against controllers who fail to have adequate processing agreements in place.
🚫 Critical Requirements: Must specify the subject matter and duration of processing, nature and purpose, types of personal data, categories of data subjects, and the obligations and rights of the controller.
📝 Best Practice: Include detailed security measures, sub-processor approval mechanisms, data breach notification timelines, audit rights, and clear data deletion or return provisions upon termination.
🔵 Understanding Importance Levels
🔴 Critical: Must have — legally required or essential for enforceability
🟡 Important: Should have — protects your position and prevents disputes
🔵 Recommended: Nice to have — best practice for comprehensive coverage
Controller and Processor Identified
Clearly identifies who is the Controller (determines purposes/means) and who is the Processor (processes on Controller's instructions). Required by UK GDPR Article 28(3). Essential for establishing legal roles and responsibilities.
🔴 Critical
Key UK GDPR Terms Defined
Defines essential terms: Personal Data, Processing, Data Subject, UK GDPR, Data Protection Laws, Sub-processor. Ensures both parties understand technical terminology. Prevents disputes over interpretation.
🔴 Critical
Principal Agreement Referenced
References the underlying service agreement that the DPA supplements (e.g., Master Services Agreement, SaaS Agreement). Shows DPA doesn't stand alone. Links data processing obligations to commercial contract.
🟡 Important
Interpretation Clause
Explains how to interpret headings, singular/plural, statutory references. Standard contract interpretation rules. Reduces ambiguity in legal construction.
🔵 Recommended
Effective Date Stated
Clear commencement date showing when DPA obligations begin. Essential for audit trail. Demonstrates when Article 28 compliance commenced.
🟡 Important
⚠️ UK GDPR Article 28(3) Requirement
UK GDPR Article 28(3) requires you to specify: (1) subject matter of processing, (2) duration, (3) nature and purpose of processing, (4) type of personal data, and (5) categories of data subjects. Vague descriptions like "business operations" are insufficient and constitute a compliance breach.
Subject Matter & Purpose Described
Clearly describes what the Processor will do with personal data and why (e.g., "email marketing service provision", "cloud hosting", "payroll processing"). Required by UK GDPR Article 28(3)(a). Shows legitimate business need.
🔴 Critical
Duration of Processing Specified
States how long processing will occur: duration of Principal Agreement, specific time period, or "until termination". Required transparency under Article 28(3). Sets temporal scope of processor obligations.
🔴 Critical
Nature of Processing Activities
Describes what operations will be performed: collection, storage, organization, structuring, retrieval, consultation, use, disclosure, deletion. Shows comprehensive understanding of processing scope.
🟡 Important
Personal Data Categories Listed
Lists specific categories of personal data to be processed: contact details, financial data, employment information, transaction history, technical data (IP addresses), etc. Required by Article 28(3). Be specific, not vague.
🔴 Critical
Data Subject Categories Identified
Identifies whose data will be processed: customers, employees, suppliers, website visitors, job applicants, etc. Required disclosure under Article 28(3). Shows scope of affected individuals.
🔴 Critical
Special Category Data (if applicable)
If processing special category data (health, race, religion, biometrics, etc.), this MUST be explicitly stated with additional safeguards. Article 9 UK GDPR requires heightened protection. Higher risk requires specific authorization.
🔴 Critical
⚠️ Core Article 28(3) Requirements
UK GDPR Article 28(3) mandates that Processors: (1) only process on documented instructions, (2) ensure personnel confidentiality, (3) implement appropriate security, (4) respect sub-processing rules, (5) assist with data subject rights, (6) assist with security and breach obligations, (7) delete/return data post-termination, (8) make information available for audits.
Process Only on Documented Instructions
Processor commits to process personal data ONLY on documented written instructions from Controller. Cannot use data for own purposes. Article 28(3)(a) fundamental requirement. Prevents unauthorized processing.
🔴 Critical
Personnel Confidentiality Obligations
Processor ensures all personnel with access to personal data are bound by confidentiality obligations. Article 28(3)(b) requirement. Prevents unauthorized disclosure by employees/contractors.
🔴 Critical
Notification of Unlawful Instructions
Processor must immediately inform Controller if instructions would violate UK GDPR or Data Protection Act 2018. Article 28(3)(a) obligation. Protects Controller from inadvertent non-compliance.
🔴 Critical
No Data Transfer to Third Countries Without Authorization
Processor cannot transfer personal data outside UK/EEA without explicit Controller authorization and appropriate safeguards. Article 28(3)(a) read with Chapter V. Prevents unauthorized international transfers.
🔴 Critical
Records of Processing Activities
Processor maintains records of all processing activities carried out on behalf of Controller. Article 30(2) requirement. Essential for demonstrating accountability and audit trail.
🟡 Important
Cooperation with Controller
Processor commits to cooperating with Controller in meeting UK GDPR obligations: impact assessments, ICO consultations, compliance monitoring. Shows collaborative accountability approach.
🟡 Important
Controller Authorization Required
Processor cannot engage sub-processors without prior specific or general written authorization from Controller. Article 28(2) fundamental requirement. Controller retains control over data processing chain.
🔴 Critical
Sub-Processor Notification Procedure
If general authorization given, Processor must inform Controller of changes to sub-processors with reasonable notice period. Controller has right to object. Article 28(2) transparency requirement.
🔴 Critical
Sub-Processor Same Obligations
Processor imposes same data protection obligations on sub-processors via written contract. Article 28(4) flow-down requirement. Ensures consistent protection throughout processing chain.
🔴 Critical
Processor Remains Liable
Processor remains fully liable to Controller for sub-processor's failure to meet obligations. Article 28(4) accountability principle. Controller not prejudiced by sub-processing arrangements.
🔴 Critical
Appropriate Technical and Organizational Measures
Processor implements appropriate technical and organizational security measures considering state of the art, costs, nature/scope/context/purposes of processing, and risk. Article 28(3)(c) and Article 32 requirement. Core security obligation.
🔴 Critical
Specific Security Measures Listed
Lists specific security measures: encryption (in transit and at rest), access controls, pseudonymization where appropriate, regular security testing, incident response procedures, staff training. Article 32 examples.
🟡 Important
Regular Security Assessments
Processor commits to regular testing, assessment, and evaluation of security measures' effectiveness. Article 32(1)(d) requirement. Demonstrates ongoing security vigilance.
🟡 Important
Security Documentation Available
Processor makes information about security measures available to Controller for compliance verification. Article 28(3)(h) transparency. Enables Controller to demonstrate accountability.
🟡 Important
Security Incident Response Plan
Processor maintains documented incident response procedures for detecting, investigating, and responding to security events. Best practice for Article 32 compliance. Shows preparedness for breach scenarios.
🔵 Recommended
⚡
Instant Download
You've Done the Research. Now Finish It.
Complete data processing agreement template – all clauses included, professionally drafted.
Fill in your details in minutes and you're done.
£20 – Own It Forever
Create Your Data Processing Agreement Now
→
✅ 30-day money-back guarantee*
Preview before you buy • Lifetime updates • No subscription
Assistance with Rights Requests
Processor assists Controller in responding to data subject rights requests: access, rectification, erasure, restriction, portability, objection. Article 28(3)(e) requirement. Essential for Controller's compliance with Chapter III rights.
🔴 Critical
Response Timeframe for Assistance
Specifies reasonable timeframe for Processor to assist with rights requests (typically within 5-10 business days to allow Controller to meet 1-month deadline). Shows practical commitment to assistance obligation.
🟡 Important
Direct Requests to Controller
If Processor receives direct request from data subject, Processor redirects to Controller without undue delay. Maintains proper controller-processor roles. Prevents confusion over responsibility.
🟡 Important
Immediate Breach Notification
Processor notifies Controller without undue delay (typically within 24-48 hours) upon becoming aware of personal data breach. Article 28(3)(f) and Article 33 requirement. Critical for Controller to meet 72-hour ICO notification deadline.
🔴 Critical
Breach Information Requirements
Notification includes: nature of breach, categories/numbers of data subjects and records affected, likely consequences, measures taken/proposed to address breach. Article 33(3) required details. Enables Controller assessment.
🔴 Critical
Breach Contact Point
Processor designates specific contact point for breach notifications available 24/7. Shows operational readiness. Ensures no delay in critical communications.
🟡 Important
Breach Documentation
Processor documents all breaches including facts, effects, and remedial action taken. Article 33(5) requirement. Essential for demonstrating accountability and learning from incidents.
🟡 Important
Assistance with DPIAs
Processor assists Controller with Data Protection Impact Assessments when required under Article 35. Article 28(3)(f) obligation. Processor has relevant technical knowledge to contribute.
🔴 Critical
Prior Consultation Support
Processor assists if Controller must consult ICO prior to processing under Article 36. Provides necessary technical/organizational information. Shows comprehensive cooperation commitment.
🟡 Important
Controller Audit Rights
Controller has right to audit Processor's compliance with DPA obligations. Article 28(3)(h) fundamental requirement. Essential for Controller to demonstrate accountability and oversee processing.
🔴 Critical
Audit Frequency and Notice
Specifies reasonable audit frequency (e.g., annually, or as needed if breach/complaint occurs) and advance notice period (e.g., 30 days). Balances oversight with operational practicality.
🟡 Important
Information Access for Audits
Processor makes available all information necessary to demonstrate compliance. Article 28(3)(h) transparency. Includes policies, procedures, logs, security documentation.
🟡 Important
Third-Party Auditor Option
Controller may appoint independent third-party auditors. Recognizes Controller may lack internal audit resources. Standard in commercial DPAs for larger organizations.
🔵 Recommended
Transfer Restrictions
Processor cannot transfer personal data outside UK/EEA without Controller's prior authorization and appropriate Article 46 safeguards. Chapter V requirement. Controller retains control over international data flows.
🔴 Critical
Transfer Mechanisms Specified
If transfers occur, specify mechanism: UK adequacy decision, International Data Transfer Agreement (IDTA), Standard Contractual Clauses (SCCs), binding corporate rules, or other Article 46 safeguard. Required Chapter V compliance.
🔴 Critical
Sub-Processor Transfer Obligations
Same transfer restrictions and safeguards apply to sub-processors. Ensures consistent protection throughout processing chain regardless of geographic location.
🟡 Important
Deletion Upon Termination
Upon termination of services, Processor deletes or returns all personal data to Controller and deletes existing copies (unless required by law to retain). Article 28(3)(g) requirement. Ensures data doesn't persist unnecessarily.
🔴 Critical
Controller's Choice
Controller specifies whether data should be returned (in common format) or deleted. Gives Controller flexibility based on ongoing needs. Standard commercial practice.
🟡 Important
Timeframe for Return/Deletion
Specifies reasonable timeframe (e.g., within 30 days of termination) for return/deletion. Provides clarity and ensures prompt action.
🟡 Important
Certification of Deletion
Processor provides written certification that all personal data has been deleted or returned. Demonstrates compliance and provides audit evidence.
🔵 Recommended
⚡
Instant Download
You've Done the Research. Now Finish It.
Complete data processing agreement template – all clauses included, professionally drafted.
Fill in your details in minutes and you're done.
£20 – Own It Forever
Create Your Data Processing Agreement Now
→
✅ 30-day money-back guarantee*
Preview before you buy • Lifetime updates • No subscription
Processor Liability for Breaches
Processor liable for damages caused by processing that violates UK GDPR or fails to comply with lawful Controller instructions. Article 82 establishes liability framework. Essential for enforcement.
🔴 Critical
Indemnification Provisions
Processor indemnifies Controller for losses arising from Processor's breach of DPA, including ICO fines, compensation claims, legal costs. Standard commercial protection for Controller.
🟡 Important
Limitation of Liability
May reference liability caps in Principal Agreement, but note UK GDPR liabilities cannot be completely excluded. Balances commercial practicality with legal requirements.
🔵 Recommended
DPA Term
States DPA remains in force for duration of Principal Agreement or until all personal data deleted. Aligns DPA lifecycle with processing relationship. Prevents gaps in protection.
🟡 Important
Termination for Breach
Controller may terminate DPA immediately if Processor commits material breach of data protection obligations. Protects Controller from continuing non-compliant relationship.
🟡 Important
Survival of Obligations
Certain obligations survive termination: confidentiality, data deletion, audit rights for terminated period, indemnification. Ensures complete compliance even post-relationship.
🔵 Recommended
Notices Procedure
Specifies how notices must be given: writing, delivery methods (email, post, hand delivery), deemed receipt times. Ensures effective communication between parties.
🟡 Important
Amendment Procedure
Changes to DPA must be in writing and signed by both parties. Prevents unilateral modifications. Standard contract protection.
🟡 Important
Entire Agreement Clause
DPA (together with Principal Agreement) constitutes entire agreement on data processing, superseding prior agreements. Prevents disputes over contradictory terms.
🔵 Recommended
Severability
If any provision invalid/unenforceable, remaining provisions continue in force. Courts will interpret to give maximum effect. Standard contract resilience clause.
🔵 Recommended
Waiver Provision
Failure to enforce any right doesn't constitute waiver. Party can still enforce later. Protects rights from inadvertent loss.
🔵 Recommended
Counterparts Clause
Agreement may be executed in counterparts, each an original, all together constituting one instrument. Facilitates practical execution.
🔵 Recommended
Supplementary Nature
DPA supplements Principal Agreement and doesn't replace or supersede it. Clarifies relationship between contracts. Both remain in effect.
🟡 Important
Conflict Resolution
In event of conflict between DPA and Principal Agreement regarding personal data processing, DPA terms prevail. Ensures data protection requirements take priority.
🟡 Important
Governing Law Specified
States which UK jurisdiction's law governs the DPA: England & Wales, Scotland, or Northern Ireland. Essential for legal certainty and enforcement.
🔴 Critical
Jurisdiction Specified
Parties agree which courts have exclusive jurisdiction to settle disputes. Typically courts of England & Wales, Scotland, or Northern Ireland. Prevents forum shopping.
🔴 Critical
Signature Blocks for Both Parties
Provides signature blocks for Controller and Processor with spaces for: signature, name, position, date. Essential for contract formation and evidence.
🔴 Critical
Witness Requirements
Includes witness signature sections if required by your jurisdiction or preference. Adds evidentiary weight. Particularly important for significant contracts.
🔵 Recommended
⚡
Instant Download
You've Done the Research. Now Finish It.
Complete data processing agreement template – all clauses included, professionally drafted.
Fill in your details in minutes and you're done.
£20 – Own It Forever
Create Your Data Processing Agreement Now
→
✅ 30-day money-back guarantee*
Preview before you buy • Lifetime updates • No subscription
Next Steps
Now that you've reviewed the compliance checklist, you have three options:
✅ Use Our Ready-Made Template
Save hours of research and drafting. Our professionally-crafted Data Processing Agreement template covers all 64 compliance points with comprehensive UK GDPR Article 28-compliant provisions, security measures, sub-processor controls, breach notification procedures, and data return/deletion clauses. Structured following ICO guidance. Available in both Smart Interview (guided) and Classic Editor (direct editing) modes for just £20.
✔ UK Law Only | ✔ Instant Download | ✔ Lifetime Updates | ✔ No Subscriptions
✅ 30-day money-back guarantee*
📝 Draft Your Own Data Processing Agreement
Use this checklist as your guide, but remember: processing personal data without an adequate DPA is a direct breach of UK GDPR. The most common mistakes are: missing mandatory Article 28 clauses, inadequate sub-processor provisions, and unclear data breach notification timelines.
Disclaimer: This checklist is for general informational purposes only and does not constitute legal advice. While we strive to keep information accurate and up to date, the law is complex and subject to change. Every situation is unique. This checklist applies to data processing agreements in England and Wales. Last updated: May 2026.