Data protection clauses in a supplier contract
The data protection clauses for a business's supplier contracts, drafted for the customer side with the privacy notice, for a fixed fee of £795 in five working days.
Data protection clauses in a supplier contract
The data protection clauses a business should have in its contracts with suppliers, drafted for the customer side, covering the three kinds of supplier and the clauses each needs, the processor supplier and the Article 28 terms in the main contract or a schedule, the controller supplier and the sharing terms, the supplier with incidental access and the confidentiality clause that is enough, liability, insurance and termination for a data breach, and audit, assistance and the clauses suppliers push back on. £795 with the privacy notice, delivered in five working days.
Buy now, £795A business that buys services has suppliers who process its data on its behalf, suppliers who use the data for their own purposes, and suppliers who merely see it in passing, and the data protection clauses in its contracts should fit each: the mandatory processor terms for the first, data sharing terms for the second, and a confidentiality clause for the third, with liability, insurance, termination and audit provisions that give the business a remedy if a supplier lets it down. I draft the clauses as a schedule for the business's supplier contracts, with the privacy notice, for a fixed fee of £795, delivered in five working days, with a note on the operational steps the documents assume.
Who this is for
Businesses in England and Wales buying services that involve their customers', staff or contacts' data, from a company with a supplier contract template to one that signs whatever suppliers send.
What matters in supplier-side data protection clauses
The three kinds of supplier and the clauses each needs
A supplier is a processor where it handles the business's data on the business's instructions (software, hosting, payroll, marketing execution, IT support), a controller where it decides its own purposes (a professional adviser, an insurer, a referral partner, a platform using the data for itself), and neither where its access is incidental (a cleaner, a maintenance contractor), and the clauses should fit the role: Under Article 28 of the UK GDPR the relationship between a controller and its processor must be governed by a written contract with the listed terms, the data sharing code of practice under section 121 of the Data Protection Act 2018 sets the standard for controller-to-controller terms, and a confidentiality clause with security practices covers incidental access; the schedule drafted for the business contains all three, with the main contract selecting the one that applies.
The processor supplier and the Article 28 terms in the main contract or a schedule
For a processor the contract must set out the duration, nature and purpose of the processing, the categories of data and of data subjects, and the controller's obligations and rights, and must oblige the supplier to process only on documented instructions, keep confidentiality, secure the data as Article 32 requires, use authorised sub-processors on matching terms, assist with rights requests and with the controller's security, breach and impact assessment duties, return or delete the data at the end, and make compliance demonstrable through information and audit; the business's schedule drafts each from the customer's side (breach notification within a stated short period from the supplier's awareness, sub-processors with notification and a genuine objection right, deletion with certification), while staying within what a competent supplier will sign.
The controller supplier and the sharing terms
For a supplier that is a controller the contract should state the purposes for which the business shares data and the supplier may use it, the lawful basis each relies on, the supplier's obligation to give its own notice under Article 14 of the UK GDPR, the security each applies, the cooperation on breaches and requests, the limits on onward sharing and retention, and the position on termination, with a joint controller arrangement under Article 26 where the business and the supplier jointly decide the purposes; a business that signs a processor DPA with a supplier that is really a controller has a document that says the wrong thing about who decides.
The supplier with incidental access and the confidentiality clause that is enough
For a supplier whose staff may see data without processing it (cleaners, builders, security guards, engineers), the contract needs a confidentiality clause covering everything seen on the premises or systems, the supplier's staff vetting and training, the practices the supplier follows (no reading, copying or photographing), the reporting of anything found unsecured, and the supplier's liability for its staff's deliberate misuse, with the business's own security under Article 32 of the UK GDPR (clear desks, locked screens, secured waste) as the primary protection; imposing processor terms on such a supplier misdescribes the relationship and produces obligations the supplier cannot meet.
Liability, insurance and termination for a data breach
The clauses should make the supplier liable for losses caused by its breach of the data protection terms (the business's regulatory fines caused by the supplier's failure, the costs of notification, the claims by individuals under Article 82 of the UK GDPR), within a cap that is higher than the general cap for data protection where the supplier will agree one, with an indemnity for the supplier's own breaches, should require the supplier to hold cyber and professional indemnity insurance at stated levels, and should give the business the right to terminate for a material data protection breach and to require deletion and return; a supplier contract that caps data protection liability at a month's fees leaves the business carrying the supplier's risk.
Audit, assistance and the clauses suppliers push back on
Suppliers push back on unlimited audit rights, on assistance at no cost, on breach notification measured in hours and on uncapped liability, and the schedule is drafted so that the business asks for what it needs and a competent supplier can give: audit by the supplier's certifications and reports with on-site audit on notice where they are insufficient, assistance within Article 28's scope at no charge and beyond it at reasonable cost, notification within a stated short period from awareness with the information the business needs for its seventy-two hours under Article 33, and liability within a stated data protection cap; the note that comes with the documents explains which clauses to hold and which to trade, and the privacy notice drafted alongside tells the business's customers and staff about the suppliers the clauses govern.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Do all our suppliers need data protection clauses?
Every supplier that touches personal data needs the clauses that fit its role: processor terms, controller sharing terms or a confidentiality clause. The schedule contains all three and the contract selects the one that applies.
Should we ask suppliers for uncapped data protection liability?
Ask for a data protection cap higher than the general cap, an indemnity for the supplier's own breaches and insurance at stated levels. Uncapped liability is what suppliers refuse, and a higher cap with insurance is what protects the business.
Our cleaner's contract has processor clauses. Is that right?
It is not. Incidental access is not processing, and processor clauses misdescribe the relationship. A confidentiality clause with vetting, practices and liability for deliberate misuse is the right term, with the business's own clear-desk and screen-locking as the primary protection.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Data protection clauses in a customer contract
- Reviewing a supplier's data processing agreement
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.