Data processing agreement for a call centre or answering service
A data processing agreement for a call centre or telephone answering service to use with clients, drafted for the provider with the privacy notice, £795 in five working days.
Data processing agreement for a call centre or answering service
A data processing agreement for an outsourced call handling, answering or customer service provider, drafted for the provider, covering the callers' data and the client's customers, the mandatory terms for scripted and unscripted handling, call recording, the announcement and the retention, the telephony platform, the CRM access and the sub-processors, agents, home working and the agent abroad, and payments over the phone, breaches and the liability for a mishandled call. £795 with the privacy notice, delivered in five working days.
Buy now, £795An answering service or call centre takes the client's calls, records them, enters the caller's details into the client's system or its own, and passes messages and orders back, with agents who may be at home or in another country. It is the client's processor for all of that, every client is legally required to have a data processing agreement with it, and the agreement has to cover scripted and unscripted calls, the recordings and their retention, the telephony and CRM platforms, the agents' locations, the payments some clients want taken by phone, and the liability for the call that goes wrong. A fixed £795 covers the data processing agreement and the privacy notice, drafted for the business with a note on the operational steps they assume and delivered in five working days.
Who this is for
Telephone answering services, outsourced customer service and contact centres, virtual receptionist providers and out-of-hours call handlers in England and Wales.
What matters in a call centre's data processing agreement
The callers' data and the client's customers
Every call brings the caller's name, number, reason for calling and whatever they say, which the provider collects on the client's behalf and passes on, and the provider also receives the client's customer records to answer calls from, so that it processes two flows of the client's data as the client's processor under Article 4 of the UK GDPR; A written contract with the terms listed in Article 28 of the UK GDPR is mandatory for every controller and processor relationship, and the provider should supply its own DPA with its service terms, because clients range from a sole trader with no idea what a DPA is to a regulated business with a forty-page one of its own.
The mandatory terms for scripted and unscripted handling
The DPA must set out what is processed and for how long, why and how, which types of data and which categories of individuals, and what the controller must do and may require, and for a call handler the schedule should describe the callers and the client's customers, the contact, enquiry, order, complaint, account and (where the client's business involves it) health or financial data callers disclose, the answering, message taking, order taking, booking and customer service the provider performs, and the instructions (the service terms, the client's scripts and knowledge base, the escalation rules); the provider must process on documented instructions only, ensure confidentiality, meet the Article 32 security standard, engage sub-processors only when authorised and on flow-down terms, assist the client with rights requests and its security, breach and impact assessment obligations, return or delete the data at the end, and supply the information and audit access that demonstrate compliance.
Call recording, the announcement and the retention
Recording calls is processing the caller's data (and special category data where the call concerns health or other sensitive matters), and the DPA should say whether calls are recorded, on whose decision (the client's, as controller, with the provider recording on instruction), for what purpose (quality, training, dispute resolution), with the announcement the caller hears at the start (which the client's privacy notice should also cover), the retention period after which recordings are deleted, who may access them and how the client obtains a recording; the Information Commissioner's guidance expects the purpose and retention to be stated and the recordings secured, and a caller's subject access request extends to the recording of their call, which the DPA should provide for.
The telephony platform, the CRM access and the sub-processors
The provider's telephony and recording platform, its ticketing system and the client's CRM where the provider enters data into it are the places the data lives, and the DPA should say whether the provider works in the client's systems (as the client's authorised user, with access removed on termination) or its own (with its platforms as sub-processors under Article 28(2) and (4) needing authorisation and flow-down), should list the categories of sub-processor, and should state the international transfers under Article 46 of the UK GDPR for platforms hosted abroad; the client's privacy notice has to say that calls are handled by a third party, and the DPA should remind the client of that.
Agents, home working and the agent abroad
Agents handling the client's calls must be vetted, trained and bound to confidentiality, and the DPA should cover the provider's recruitment checks, its training on the client's scripts and on data protection, the security of home-working agents (a quiet and private space, a locked device, no recording of calls on personal devices, no writing down of card or account details), and the location of agents, because an agent in another country is an international transfer of the client's data needing the safeguards under Article 46 of the UK GDPR or an adequacy regulation, which the client must have authorised; a client that discovers its calls are answered abroad has a transfer it did not know about.
Payments over the phone, breaches and the liability for a mishandled call
Where the provider takes card payments by phone, the DPA and the service terms should require the payment card industry standard's controls (pause-and-resume recording, no card numbers written down or stored, a compliant payment platform), should say that the payment processor is a controller for its own purposes, and should allocate the risk of a card data breach; breach notification to the client without undue delay within a stated period, in time for the client's seventy-two hours under Article 33, covers the mishandled call (a message given to the wrong caller, a customer's details read out to someone else), and data protection liability sits within the service terms' cap with Article 82 of the UK GDPR making each party liable for what it got wrong; the provider's own privacy notice covers its own clients' data and its staff.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Do we have to tell callers we record calls?
The client, as controller, decides whether calls are recorded and must tell callers (the announcement and the client's privacy notice); the provider records on instruction, states the purpose and retention in the DPA, and secures the recordings. A caller can ask for the recording of their call.
Some of our agents work from home. What does the DPA need to say?
The security the client can rely on: a private space, a locked device, no recordings on personal devices, no card or account details written down, and the agents' locations stated, because an agent abroad is an international transfer.
Can we take card payments by phone for clients?
With the payment card industry controls (pause-and-resume recording, no card numbers written down or stored, a compliant platform) and the risk allocated in the DPA and the service terms. Without them, the recording system becomes a store of card numbers.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Data processing agreement for a virtual assistant
- Data processing agreement for an IT support provider
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.