A quiet reading corner in a modern office at blue hour, an armchair and floor lamp by tall glazing

Data protection

What a data processing agreement is for

It is the written contract UK GDPR requires whenever a supplier processes personal data on your behalf. Its job is to fix in writing that they act on your instructions and not their own purposes, and the ICO sets out a specific list of things it has to cover.

Last checked 19 September 2026

Controller and processor, and why the words matter #

UK GDPR divides responsibility between the organisation that decides why and how personal data is processed, the controller, and anyone who processes it on that organisation's behalf, the processor. For a business buying software, you are almost always the controller and the supplier is almost always the processor.

The terms the ICO says must be in it #

The ICO's guidance on contracts between controllers and processors lists the minimum a contract has to address. Read it as a checklist rather than as law, and use it to interrogate whatever a supplier has put in front of you.

  • Processing only on documented instructions. The supplier acts on what you tell it, not on its own initiative. For AI tools this is the clause that bears on whether your content can be used for the supplier's own purposes.
  • A duty of confidence. The people handling the data are bound to keep it confidential.
  • Appropriate security measures. What the supplier actually does to protect the data, rather than an assurance that it is secure.
  • Rules on using sub-processors. Most suppliers use others underneath them. The contract governs whether they can, and whether you are told.
  • Help with the rights of individuals. If someone asks for a copy of their data or asks you to delete it, you need the supplier to be able to assist.
  • Assisting the controller. Including on security, breach notification and impact assessments.
  • What happens at the end. Deletion or return of the data when the contract finishes. This is the clause businesses most often discover they needed after they leave.
  • Audits and inspections. The supplier makes available what is needed to show it is meeting its obligations.

The contract also has to record details of the processing itself: its subject matter, duration, nature and purpose, the type of personal data and the categories of people it concerns.

What this looks like for an AI tool specifically #

Two clauses do most of the work, and they are the two to read first.

  • Documented instructions

    Where you find out whether the supplier may use your content for anything other than providing the service to you. Improving a model is a purpose. If the agreement permits it, that is a separate processing operation you need your own basis for, which is the distinction the ICO draws between developing a system and using one, and which is covered in is ChatGPT GDPR compliant.

  • End of contract

    Where you find out whether leaving is clean. A tool holding years of your correspondence, with no stated deletion process, is a practical problem as much as a legal one, and it is one of the forms of lock in that businesses notice too late.

How to find out whether you already have one #

  1. List every tool that personal data goes into

    Include the ones staff signed up for themselves, which is usually where the gaps are.

  2. For each, search the supplier's site for a data processing addendum or agreement

    Larger suppliers publish one; some require you to accept it explicitly rather than applying it automatically.

  3. Check whether it applies to your plan

    This is the step people skip, and consumer terms are frequently not written to serve as one.

  4. Save a copy with the date

    An agreement you cannot produce is not much use when somebody asks.

Doing this once for the handful of tools that matter takes an afternoon and resolves the most common gap we see. The rest of the duties that come with it are in what UK GDPR asks of a business using AI.

When you are the supplier #

If you handle personal data for your own clients, the same logic runs in the other direction and your clients may reasonably ask you these questions. Being able to answer them quickly is a competitive advantage in professional services, where procurement increasingly asks before the work starts rather than after.

You can see the shape of a plain version of this on our own privacy notice, which names the processors we use and what each one does. The list of questions worth asking in the other direction is in questions to ask an AI supplier.

The proportionate conclusion #

A business does not need a bespoke agreement drafted for every tool. It needs to know which tools hold personal data, to have accepted the supplier's terms where those exist, to have read the two clauses above, and to have written down what it found. That is a realistic standard, and it is a great deal better than the common position of having no idea.

Questions people ask

What is a data processing agreement in plain terms?
It is the written contract UK GDPR requires whenever somebody else handles personal data on your behalf. It records that they act on your instructions rather than for their own purposes, and it sets out what happens to the data while they have it and when the relationship ends.
Do I need one for a tool I pay for monthly by card?
If personal data goes into it, yes. The size of the invoice is irrelevant. Most established suppliers publish terms intended to serve this purpose, often as a separate document you accept alongside the main terms.
Who is responsible if the supplier has a breach?
Both parties have obligations, and the contract is part of how each one demonstrates it met them. As the controller you remain accountable for choosing a processor that offers sufficient guarantees, which is why the choosing is a decision to take deliberately rather than by default.
What if there is no agreement available at all?
That is a meaningful signal about the supplier. It does not necessarily make the tool unusable for work that involves no personal data, but it does mean you should not put anyone else's information into it.

Where these numbers come from

  1. ICO, Contracts and liabilities between controllers and processors , read 19 September 2026 . Sets out the minimum terms a controller to processor contract must include.
  2. ICO, Accountability and governance , read 19 September 2026

Last checked 19 September 2026.

Our workings are on the methodology page .

Free audit

Find out what the repeated work costs you

The audit counts every job the business repeats, ranks them by the hours they eat, and maps the five worth automating first. It is free, you keep everything, and there is no obligation at the end of it.

AI automation, explained

Plain answers to what businesses ask before they automate anything.

All of ai automation, explained

Read next