Data Processing Agreement
A free, editable Word Data Processing Agreement (DPA) for England & Wales, a balanced controller-to-processor agreement containing the terms required by Article 28(3) of the UK GDPR, with documented instructions, security, sub-processor controls, breach assistance, UK international-transfer safeguards, return/deletion, audit rights, and an Annex 1 details-of-processing schedule.
What's inside
A complete, UK-drafted data processing agreement
- The mandatory Article 28(3) controller-to-processor terms
- Documented instructions, confidentiality, and security (Article 32)
- Sub-processor authorisation and flow-down, plus data-subject and controller assistance
- Personal data breach notification (processor → controller) and UK transfer safeguards (IDTA / Addendum)
- Return or deletion of personal data, audit rights, and Article 30(2) records
- An Annex 1 details-of-processing schedule, governed by England & Wales
How it works
- 1
Tell us where to send it
Enter your name, work email and organisation. We email you an editable Microsoft Word (.docx) file, personalised with your name.
- 2
Fill in the bracketed fields
Open it in Word, Google Docs or LibreOffice and complete every [bracketed] field with your details and commercial terms.
- 3
Review and adapt before use
Adapt the clauses to your circumstances and have it reviewed by a qualified solicitor before you sign or publish it.
This template is not legal advice. Writford is a software company, not a law firm, and is not regulated by the SRA. This document is a starting point that must be reviewed, adapted and approved by a qualified solicitor before use. It was last reviewed on 25 June 2026.
Get the free template
We email you an editable Word copy, personalised with your name. No account needed.
Looking for something else? Browse all templates.
When do I need a data processing agreement?
Whenever one organisation handles personal data on another's instructions. If you use a supplier to process data for you, or you process data for a customer, UK data protection law requires a written agreement between you, and it must cover specific points.
- What is the difference between a controller and a processor?
- The controller decides why and how personal data is used. The processor acts on the controller's instructions. A payroll bureau is usually a processor; the employer is the controller.
- Is a DPA required by law or is it good practice?
- It is required. Where a processor handles personal data for a controller, there has to be a written contract covering the subject matter, duration, purpose, security, sub-processors, deletion and audit.
- What about suppliers outside the UK?
- Sending personal data abroad needs a lawful transfer route, such as the UK addendum to the standard clauses, and a check that protection travels with the data. The template addresses transfers.
- Do I need one with every supplier?
- With every supplier that processes personal data for you. Not with one that never touches it, and not with a separate controller, where the relationship is different and a DPA is the wrong document.
- Who is responsible if the processor has a breach?
- The controller remains accountable to the people whose data it is, which is why the agreement sets out security duties, notification timescales and what the processor must do to help.