Data processing agreement for a cleaning or facilities contractor with site access
Data protection terms for a cleaning, security or facilities contractor with site access, with a DPA for the services that need one, drafted for the contractor, £795 in five working days.
Data processing agreement for a cleaning or facilities contractor with site access
Data protection terms for a cleaning, security or facilities contractor whose staff have access to a client's premises, drafted for the contractor, covering incidental access and why it is usually not processing, the services that are processing and need a DPA, confidentiality, clear desks and the obligations for everything else, keys, alarms, CCTV and the data the contractor itself generates, staff vetting, subcontractors and the agency labour, and the terms the client's procurement team will send and what to accept. £795 with the privacy notice, delivered in five working days.
Buy now, £795A cleaner who empties the bins in an office sees the papers on the desks, the screens left on and the files in the recycling, and a client's procurement team often responds by sending a data processing agreement written for an IT supplier. Incidental access of that kind is not usually processing on the client's behalf and does not need a DPA; it needs confidentiality obligations and the clear-desk and security practices that protect the client. Some facilities services are processing (confidential waste, archive handling, reception and visitor management, CCTV monitoring) and do need one. The terms have to draw that line, give the client what it needs for each, and tell the contractor what to accept from a procurement template. The business receives the data processing agreement, the privacy notice and a note on the operational steps they assume within five working days for a fixed £795.
Who this is for
Cleaning companies, security contractors, facilities management providers, maintenance contractors and other businesses in England and Wales whose staff work inside clients' premises.
What matters in a facilities contractor's data protection terms
Incidental access and why it is usually not processing
Processing under Article 4 of the UK GDPR is an operation performed on personal data, and a contractor whose staff may see documents or screens while cleaning, repairing or guarding premises is not performing any operation on the client's data on the client's behalf; a contractor whose access is incidental is neither a processor nor a controller of what it may see, so that Article 28 does not apply and the right instrument is a confidentiality obligation and security practices in the service contract; a client that insists on a DPA for incidental access is applying the wrong rule, and the contractor's terms should explain the distinction.
The services that are processing and need a DPA
Where the contractor's service involves operations on the client's data (collecting and destroying confidential waste, moving or storing archive boxes, managing reception and the visitor log, monitoring the client's CCTV, handling post, managing access control records), the contractor is a processor for that service, A controller and its processor must have a written contract containing the terms Article 28 of the UK GDPR lists, and the DPA should define those services and carry the mandatory terms: the duration, nature and purpose of the processing, the categories of data and of data subjects, and the controller's obligations and rights, with the contractor obliged to process only on the client's documented instructions, keep the data confidential, apply the security Article 32 requires, engage sub-processors only with authorisation and on the same terms, assist the client with data subject requests and with its own security, breach and impact assessment obligations, delete or return the data at the end, and make available the information needed to demonstrate compliance and allow audits.
Confidentiality, clear desks and the obligations for everything else
For the incidental access the service contract should contain the contractor's confidentiality obligation (nothing seen on the premises is disclosed, copied, photographed or discussed), the staff's individual confidentiality undertakings, the practices the contractor will follow (no reading of documents, no use of client equipment, no photographs on the premises, reporting of anything found unsecured), the client's own obligations (a clear-desk policy, screens locked, confidential waste secured, the contractor told which areas are restricted), and the position where a member of staff does see and misuse information (the contractor's liability for its staff's deliberate acts, within the contract's cap); the client is responsible for its own security under Article 32 of the UK GDPR, and the contractor's obligations are the support for it, not a substitute.
Keys, alarms, CCTV and the data the contractor itself generates
The contractor holds keys, alarm codes and access cards (security obligations, with a log and a procedure for loss and for leavers), may operate or be captured by the client's CCTV (processed by the client as controller, with the contractor's staff told), and generates its own data on the client's premises (its staff's attendance records, its body-worn cameras or vehicle trackers, its incident reports), for which it is the controller and needs its own staff privacy notice; the terms should allocate each.
Staff vetting, subcontractors and the agency labour
The client's security depends on who the contractor sends, and the terms should state the vetting the contractor carries out (identity, right to work under the Immigration, Asylum and Nationality Act 2006, references, disclosure checks where the site's security requires them and the role is eligible), the training on confidentiality and the site rules, the uniform and identification, the supervision, and the position of subcontractors and agency staff (bound to the same obligations, with the client told and able to object), with the contractor's own data protection obligations to its staff under its own notice; a contractor that subcontracts a client's site without saying so has broken the client's assumption about who is in its building.
The terms the client's procurement team will send and what to accept
Large clients send facilities contractors a DPA from their supplier template with audit rights, breach notification within hours, uncapped liability and obligations written for a data centre, and the contractor should accept the terms that apply to the services it provides (confidentiality, security practices, the DPA for the services that are processing), should ask for the processor obligations to be limited to those services, should align breach notification with what it can do (report an incident on the premises promptly, with the client deciding whether it is a breach), and should keep data protection liability within the contract's cap under Article 82 of the UK GDPR for its own failures; the note that comes with the documents lists the points to raise, and the review service covers a client's DPA where the contractor wants it marked up.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our cleaning client wants us to sign a data processing agreement. Do we need one?
Not for incidental access while cleaning, which is not processing on the client's behalf; confidentiality and security practices are the right terms. A DPA is needed where the service involves operations on the client's data, such as confidential waste or reception. The terms explain the distinction.
Our staff could see confidential papers on desks. Who is responsible?
The client, for its own security (a clear-desk policy, locked screens, secured waste), supported by the contractor's confidentiality obligations and practices. The terms set both sides' obligations.
Do we need to DBS check our cleaners?
Only where the site's security requires it and the role is eligible for a check; otherwise identity, right to work and references. The terms state the vetting the contractor carries out so that the client knows.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Contractor agreement for a cleaner working through a cleaning company
- Reviewing a customer's data processing agreement
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.