Controller and processor, and why the words matter #
UK GDPR divides responsibility between the organisation that decides why and how personal data is processed, the controller, and anyone who processes it on that organisation's behalf, the processor. For a business buying software, you are almost always the controller and the supplier is almost always the processor.
The terms the ICO says must be in it #
The ICO's guidance on contracts between controllers and processors lists the minimum a contract has to address. Read it as a checklist rather than as law, and use it to interrogate whatever a supplier has put in front of you.
- Processing only on documented instructions. The supplier acts on what you tell it, not on its own initiative. For AI tools this is the clause that bears on whether your content can be used for the supplier's own purposes.
- A duty of confidence. The people handling the data are bound to keep it confidential.
- Appropriate security measures. What the supplier actually does to protect the data, rather than an assurance that it is secure.
- Rules on using sub-processors. Most suppliers use others underneath them. The contract governs whether they can, and whether you are told.
- Help with the rights of individuals. If someone asks for a copy of their data or asks you to delete it, you need the supplier to be able to assist.
- Assisting the controller. Including on security, breach notification and impact assessments.
- What happens at the end. Deletion or return of the data when the contract finishes. This is the clause businesses most often discover they needed after they leave.
- Audits and inspections. The supplier makes available what is needed to show it is meeting its obligations.
The contract also has to record details of the processing itself: its subject matter, duration, nature and purpose, the type of personal data and the categories of people it concerns.
What this looks like for an AI tool specifically #
Two clauses do most of the work, and they are the two to read first.
-
Documented instructions
Where you find out whether the supplier may use your content for anything other than providing the service to you. Improving a model is a purpose. If the agreement permits it, that is a separate processing operation you need your own basis for, which is the distinction the ICO draws between developing a system and using one, and which is covered in is ChatGPT GDPR compliant.
-
End of contract
Where you find out whether leaving is clean. A tool holding years of your correspondence, with no stated deletion process, is a practical problem as much as a legal one, and it is one of the forms of lock in that businesses notice too late.
How to find out whether you already have one #
-
List every tool that personal data goes into
Include the ones staff signed up for themselves, which is usually where the gaps are.
-
For each, search the supplier's site for a data processing addendum or agreement
Larger suppliers publish one; some require you to accept it explicitly rather than applying it automatically.
-
Check whether it applies to your plan
This is the step people skip, and consumer terms are frequently not written to serve as one.
-
Save a copy with the date
An agreement you cannot produce is not much use when somebody asks.
Doing this once for the handful of tools that matter takes an afternoon and resolves the most common gap we see. The rest of the duties that come with it are in what UK GDPR asks of a business using AI.
When you are the supplier #
If you handle personal data for your own clients, the same logic runs in the other direction and your clients may reasonably ask you these questions. Being able to answer them quickly is a competitive advantage in professional services, where procurement increasingly asks before the work starts rather than after.
You can see the shape of a plain version of this on our own privacy notice, which names the processors we use and what each one does. The list of questions worth asking in the other direction is in questions to ask an AI supplier.
The proportionate conclusion #
A business does not need a bespoke agreement drafted for every tool. It needs to know which tools hold personal data, to have accepted the supplier's terms where those exist, to have read the two clauses above, and to have written down what it found. That is a realistic standard, and it is a great deal better than the common position of having no idea.