Data protection clauses in a customer contract

The data protection clauses for a supplier's customer contracts, drafted for the supplier side with the privacy notice, for a fixed fee of £795 in five working days.

Share

Data protection clauses in a customer contract

The data protection clauses a supplier should have in its contracts with customers, drafted for the supplier side, covering the supplier's own clauses and why they beat the customer's, the processor terms a supplier can honour, the customer's obligations and the warranty the supplier needs, sub-processors, transfers and the architecture the clauses must fit, breach notification, assistance and the cost of each, and liability, the cap and the indemnity in both directions. £795 with the privacy notice, delivered in five working days.

Buy now, £795

A supplier that processes customers' data needs data protection clauses in its own customer terms, so that every customer gets the same terms the supplier can honour and the supplier is not signing each customer's version; the clauses have to contain what the law requires of a processor, limit the obligations to what the supplier's service and architecture can deliver, place on the customer the obligations only a controller can meet, and set the liability position in both directions consistently with the main terms. I draft the clauses as a schedule for the business's customer contracts, with the privacy notice, for a fixed fee of £795, delivered in five working days, with a note on the operational steps the documents assume.

Who this is for

Software vendors, agencies, consultancies, outsourcers and service providers in England and Wales whose customers' data passes through their service and who want their own terms to settle the data protection position.

What matters in customer-side data protection clauses

The supplier's own clauses and why they beat the customer's

Article 28 of the UK GDPR makes a written contract with specified terms compulsory between a controller and any processor, and a supplier that puts those terms in its own customer contract (as a schedule, or incorporated by reference to a published DPA) satisfies the customer's legal requirement on the supplier's terms, keeps the position consistent across its customer base, and reserves negotiation for the customers who insist on their own; the schedule is drafted to be compliant enough that a customer's lawyer accepts it and workable enough that the supplier's operations team can honour it, which is the balance a customer's template never strikes.

The processor terms a supplier can honour

The clauses set out the subject matter and duration of the processing, its nature and purpose, the types of personal data and categories of data subjects, and the controller's obligations and rights, by reference to the service description, and oblige the supplier to process on documented instructions only, ensure confidentiality, meet the Article 32 security standard, engage sub-processors only when authorised and on flow-down terms, assist the controller with rights requests and its security, breach and impact assessment obligations, return or delete the data at the end, and supply the information and audit access that demonstrate compliance, each drafted from the supplier's side: instructions are the contract and the service's documented functionality, security is the supplier's own schedule, audit is by certification and reports first, assistance beyond Article 28's scope is at reasonable cost, and deletion follows the supplier's backup cycle.

The customer's obligations and the warranty the supplier needs

The clauses should place on the customer the obligations only a controller can meet: that it has a lawful basis for the data it puts into the service, that it has given its own notices, that its instructions are lawful, that it has obtained any consents (for marketing, for special category data, for transfers it has asked the supplier to make), that it will not put special category or children's data into the service unless the contract provides for it, and that it indemnifies the supplier for claims and fines caused by its breach of those obligations; a supplier processing data the customer had no right to collect is exposed without the warranty, and Article 28(3)(h) itself requires the supplier to tell the customer where an instruction infringes the law.

Sub-processors, transfers and the architecture the clauses must fit

The clauses should give the supplier general authorisation for its sub-processors under Article 28(2) of the UK GDPR, with a published list, notification of changes (by email or in-product, with a stated period to object), the supplier's genuine attempt to resolve an objection, and termination with a refund of prepaid fees as the customer's remedy where it cannot be resolved; they should state the hosting locations and the transfers under Article 46 with the safeguard for each (the supplier's addendum or the data privacy framework certification), and should say that the supplier's architecture is what the customer has bought, so that a customer cannot require data localisation the service does not offer; the supplier's sub-processor contracts must match what it has promised.

Breach notification, assistance and the cost of each

The clauses should commit the supplier to notify the customer of a personal data breach affecting the customer's data without undue delay and within a stated period from the supplier's awareness (hours or a short period the supplier can meet, with the information the customer needs for its seventy-two hours under Article 33), to assist the customer with its notification to individuals and the regulator at reasonable cost, to assist with subject access requests through the service's functionality at no charge and beyond that at the supplier's rates, and to make the supplier's security documentation available for the customer's impact assessments; the supplier should not promise what its incident process cannot deliver, and the note that comes with the documents checks the clauses against the process.

Liability, the cap and the indemnity in both directions

The clauses should bring data protection liability within the main contract's cap or a stated higher cap for data protection, should make each party liable under Article 82 of the UK GDPR for its own failures, should give the supplier an indemnity from the customer for the customer's breach of its controller obligations and the customer an indemnity from the supplier limited to the supplier's breach of the clauses and within the cap, should exclude the customer's regulatory fines for the customer's own failures from the supplier's exposure, and should say that the clauses prevail over any customer DPA unless the parties sign a different one; the privacy notice drafted alongside tells the supplier's own contacts and users about the data the supplier controls, and the review service covers the customer DPA the supplier is sent despite having its own.

What it costs

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Should our customer terms contain data protection clauses or a separate DPA?

Either works: a schedule in the terms or a published DPA incorporated by reference. The point is that the terms are the supplier's, compliant enough that customers accept them and workable enough that the supplier can honour them.

What obligations should we put on the customer?

That it has a lawful basis for the data it gives us, has given its notices, instructs lawfully, has obtained consents, and does not put special category or children's data into the service without agreement, with an indemnity for its breach. A supplier processing data the customer had no right to collect needs that.

Can we limit our data protection liability?

To the main cap or a stated higher data protection cap, with each party liable for its own failures and the customer's own fines excluded. Uncapped data protection liability is what customer templates ask for and the supplier's own terms should not give.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.