Data processing agreement for an IT support provider
A data processing agreement for an IT support or managed service provider to use with its clients, drafted for the provider with the privacy notice, for a fixed fee of £795 in five working days.
Data processing agreement for an IT support provider
A data processing agreement for a managed service or IT support provider, drafted for the provider, covering why access to systems makes the provider a processor, the mandatory terms for a service that touches everything, security, access controls and the engineer with the password, backups, cloud platforms and the sub-processors behind the service, breach notification when the provider is the one who finds it, and termination, hand-back and the backups that outlive the contract. £795 with the privacy notice, delivered in five working days.
Buy now, £795An IT support provider can see everything its clients hold: the email, the files, the databases, the backups, the CRM, with administrator credentials to all of it. That access makes the provider a processor of the clients' personal data even where it never reads a record, which means every client is legally required to have a data processing agreement with it. The DPA has to describe processing that is incidental to the service, carry security and access controls the provider can honour, deal with the cloud platforms and backups behind the service, provide for the breach the provider is usually the first to find, and settle what happens to the data and the backups when the contract ends. For £795, fixed, with delivery in five working days, I draft the data processing agreement and the privacy notice for the business and add a note on the operational steps they assume.
Who this is for
Managed service providers, IT support companies, outsourced IT departments and technology consultancies in England and Wales with access to clients' systems and data.
What matters in an IT support provider's data processing agreement
Why access to systems makes the provider a processor
A provider with administrator access to a client's systems processes the personal data in them (access, storage, backup, migration and incidental viewing are all processing under Article 4 of the UK GDPR), on the client's behalf and instructions, and is therefore a processor whether or not it ever opens a record; Whenever a processor acts for a controller, Article 28 of the UK GDPR requires a written contract containing the terms it lists, so that a client whose IT provider works under a quote and an invoice is in breach, and a provider who offers its own DPA with the service agreement gives every client the same terms and spares itself the client's generic version with its unlimited audit rights.
The mandatory terms for a service that touches everything
The DPA must set out what is processed and for how long, why and how, which types of data and which categories of individuals, and what the controller must do and may require, and for an IT provider the schedule should say that the data is whatever the client holds in the systems the provider supports (all categories, including special category data where the client holds it), that the processing is the support, maintenance, hosting, backup and migration the service agreement describes, and that the instructions are the service agreement and the tickets the client raises; the provider must confine processing to the client's documented instructions, keep it confidential, apply Article 32 security, bring in sub-processors only with authorisation and on the same obligations, support the client on data subject requests and on security, breaches and impact assessments, delete or return the data at the end, and provide information and audits to demonstrate compliance.
Security, access controls and the engineer with the password
Article 32 of the UK GDPR requires security appropriate to the risk, and for a provider whose engineers hold the keys the security schedule should cover named and individual accounts (no shared administrator credentials), multi-factor authentication, least privilege and access reviews, logging of privileged access, the vetting and confidentiality of staff, the handling of credentials on leaving, the provider's own systems and devices, remote access tools and their configuration, and the provider's own security certification where it has one; the client's audit right should be met by the provider's certification and reports in the first instance, with on-site audit on notice and at cost.
Backups, cloud platforms and the sub-processors behind the service
The provider's backup service, its remote monitoring and management platform, its ticketing system, the cloud platforms it administers or resells and any subcontracted engineers are sub-processors under Article 28(2) and (4), and the DPA should list the categories, give general authorisation subject to notification and a right to object, flow down the obligations, and identify each transfer outside the United Kingdom and its safeguard under Article 46 of the UK GDPR for platforms hosted abroad; where the client's own cloud subscriptions are in the client's name and the provider merely administers them, the DPA should say so, because the provider is not a sub-processor's sub-processor for a platform the client contracts with directly.
Breach notification when the provider is the one who finds it
The provider is usually the first to detect ransomware, a compromised mailbox or a lost device, and the DPA should require it to notify the client without undue delay and within a stated short period after becoming aware, with the information the client needs for its own seventy-two-hour notification under Article 33, to contain the incident on the client's authority, to preserve evidence, and to assist with the client's notification to individuals under Article 34 at the client's reasonable cost; the DPA should also say who decides whether an incident is a breach (the client, as controller, on the provider's information) and that the provider does not notify the regulator itself.
Termination, hand-back and the backups that outlive the contract
At the end of the service the DPA should provide for the hand-back of credentials, documentation and configurations, the transfer of the client's data and backups to the client or its new provider in a usable form, the deletion of the provider's copies by a stated date with a certificate of deletion, the retention of backups only for the period the backup cycle requires and then overwritten, and the provider's cooperation with the transition, which is where a dismissed provider holds the upper hand and the DPA should remove it; liability for data protection breaches sits within the service agreement's cap or a stated cap, with each party liable under Article 82 of the UK GDPR for its own failures.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
We never look at our clients' data. Are we still a processor?
You are. Administrator access, storage, backup and migration are processing whether or not an engineer reads a record. Every client is required to have a DPA with you, and offering your own is better than signing theirs.
What should the DPA say about breaches we discover?
Notify the client without undue delay within a stated short period, with the information the client needs for its own seventy-two-hour deadline, contain on the client's authority, preserve evidence and assist. The client decides whether it is a breach and notifies the regulator; the provider does not.
What happens to the backups when a client leaves?
Handed back in a usable form, the provider's copies deleted within a stated period with certification, and backups overwritten on the cycle. The DPA removes the upper hand a dismissed provider would otherwise hold.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Managed service provider agreement
- Data protection clauses in a customer contract
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.