What it means
A recruitment agency stores candidate records in a cloud platform; the agency decides why the records are collected, while the provider handles them to deliver the service. A DPA can define the provider's duties for that processing relationship.
Start with roles, not contract labels, because a provider acting only on instructions may be a processor while another organisation deciding its own purposes may be an independent controller, and calling both a processor cannot change how they actually use the data. Describe the subject matter, duration, nature and purpose of processing, and list the types of personal data and people involved, since a generic line saying 'customer information' may not capture sensitive applicant files or payroll records.
Document what the provider may do: under the UK GDPR Article 28 framework, the processor acts on the controller's documented instructions unless a specified legal requirement applies. Set confidentiality duties for people with access, and define appropriate technical and organisational security rather than assuming a marketing claim about encryption answers every risk.
Cover sub-processors, because a cloud provider may rely on hosting, support or analytics vendors, and the UK ICO guidance explains specific or general written authorisation, notice of changes and a chance to object under its framework. Check geographic processing and transfers by assessing where data and support access go and which additional terms or safeguards apply.
Define incident assistance and notice, since a provider should tell the customer about a personal-data breach without undue delay under the relevant processor rule and provide facts needed for the customer's assessment, with operational contacts and escalation times agreed in the contract. Address requests from individuals, because the provider may need to help locate, correct or delete records when the controller handles a rights request, and specify how assistance works and any reasonable cost or technical limitation.
Include deletion or return at the end of the service, subject to lawful retention requirements, and clarify backups and timing, since a promise of instant deletion everywhere may be technically inaccurate if encrypted backup cycles persist for a stated period. Provide for information and audits to demonstrate compliance, balancing verification with security and confidentiality for other customers.
The ICO lists Article 28 minimum terms for UK controller-processor contracts: instructions, confidentiality, security, sub-processors, rights assistance, assistance to the controller, end-of-contract arrangements and audits. Its guidance may be revised after legislative change, so check the current rule before execution.
The European Commission publishes standard clauses for controller-processor relationships in the EU/EEA, and these Article 28 clauses are distinct from the separate standard contractual clauses often used as a transfer mechanism for data sent outside the region, so do not confuse the two sets. Keep the DPA aligned with the main service agreement, because if the service scope changes to include AI model training or new analytics the old processing description may no longer fit, and both commercial permissions and privacy obligations should be reviewed before switching on a feature.
Maintain a vendor inventory of providers that handle personal data, their roles, signed terms and review dates; this helps find gaps but does not prove a provider follows its security obligations. A DPA is not a privacy notice or an excuse to share any data, since the business still needs a lawful basis, transparency, data minimisation and suitable oversight, so use the agreement to make the operational relationship visible and ask a privacy specialist to check jurisdiction-specific clauses before relying on a template.
In practice
Real-world examples.
Example
A payroll processor signs terms covering staff records, security and breach assistance. The terms name the categories of employee data and the purposes allowed. The company checks that the breach-notice period is workable for its own reporting duties.
Example
A CRM provider lists sub-processors and gives notice before changing them. The customer's privacy lead reviews each new sub-processor and may object within the agreed period. The contract also records where support staff are located.
Example
An exit clause covers return of active data and a realistic backup-deletion schedule. The provider returns exports within an agreed time and confirms deletion of live copies. Encrypted backups age out over a stated period.
Formula
Calculation
Illustrative signed-term coverage = providers in scope with current signed DPAs / all providers in scope x 100.
Worked example. Fourteen of sixteen providers have current signed terms, so coverage is 14 / 16 x 100 = 87.5%, often rounded to 88%. Signatures alone do not prove adequacy, so confirm the denominator and the content of the terms. The two missing providers, or 12.5%, should be listed with owners and a signing deadline.Case study
Seen in the real world.
This entirely fictional example follows Dune Recruitment, an invented agency. Its vendor list showed two tools processing candidate data without current terms. It confirmed each provider role, updated the agreements and changed its onboarding checklist. The example does not claim an audit pass or that a DPA alone prevents mishandling.
Dune later reviewed its register and found 14 of 16 providers with current signed terms, an 87.5% coverage rate, and set a deadline for the other two. Its onboarding checklist now requires role confirmation before any candidate data is shared. The figures are illustrative.
Watch out
Common mistakes.
- Treating every data recipient as a processor without checking who decides the purpose.
- Ignoring sub-processors or international-access arrangements.
- Counting a signed template as sufficient without checking processing scope and safeguards.
Questions
People also ask.
What is a data processing agreement?
Terms governing personal-data processing carried out on another organisation's behalf.
Who signs it?
Usually the controller and processor, after checking their actual roles.
Is it required?
Many controller-processor regimes require it; check the applicable law and relationship.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
