Data processing agreement for a payroll provider
A data processing agreement for a payroll bureau or outsourced payroll service to use with its clients, drafted for the provider with the privacy notice, for a fixed fee of £795 in five working days.
Data processing agreement for a payroll provider
A data processing agreement for a payroll bureau or outsourced payroll provider, drafted for the provider, covering the provider as processor and the client as employer, the mandatory terms applied to payroll, special category data in a payroll file, HMRC, pension providers and the parties the provider deals with, errors, corrections and the liability for a wrong payslip, and retention, hand-over and the year-end records. £795 with the privacy notice, delivered in five working days.
Buy now, £795A payroll provider holds every employee's name, address, bank details, pay, tax code, pension contributions and the deductions that reveal union membership, court orders and sickness, and files with HMRC and the pension provider on the employer's behalf. It is the employer's processor, every client is legally required to have a data processing agreement with it, and the agreement has to deal with the special category data a payroll file contains, the third parties the provider deals with, the errors that payroll produces and the records that must be kept for years. Drafting for the business, I deliver the data processing agreement, the privacy notice and a note on the operational steps they assume in five working days for a fixed £795.
Who this is for
Payroll bureaux, accountancy practices running payroll for clients, outsourced HR and payroll providers and software-plus-service payroll businesses in England and Wales.
What matters in a payroll provider's data processing agreement
The provider as processor and the client as employer
The employer is the controller of its employees' data, decides what they are paid and instructs the provider to calculate, pay and report it, and the provider is the processor, acting on those instructions and the law's requirements; Article 28 of the UK GDPR requires a written contract between a controller and its processor containing the terms the Article lists, which the provider should supply with its service terms, and the DPA should say that the provider's filings with HMRC and the pension provider are made on the employer's behalf as its agent, which keeps the employer's statutory liability where the law puts it while the provider carries the contractual duty to file correctly and on time.
The mandatory terms applied to payroll
The DPA must set out the duration, nature and purpose of the processing, the categories of data and of data subjects, and the controller's obligations and rights, and for payroll the schedule should describe the employees and workers, the pay, tax, national insurance, pension, benefit, deduction and absence data, the calculation, payment, reporting and record-keeping the provider performs, and the instructions (the service terms, the monthly inputs, the employer's authorisations); the provider must act only on documented instructions, bind its staff to confidentiality, implement Article 32 security, use sub-processors only with authorisation and under matching terms, help the client answer data subject requests and meet its security, breach and impact assessment duties, return or delete the data when the service ends, and provide the information and audit access needed to show compliance.
Special category data in a payroll file
A payroll file reveals trade union membership through subscription deductions, health through sickness and statutory sick pay, family circumstances through maternity and paternity pay, and sometimes religion or disability through benefit elections, all special category data under Article 9 of the UK GDPR that the employer processes under the employment law condition in Schedule 1 to the Data Protection Act 2018 and the provider processes on its instructions; the DPA should recognise that the data includes special category data, restrict the provider's use to the payroll, limit access to named staff, and require the security that the sensitivity warrants, because a payroll provider's spreadsheet of a client's sickness deductions emailed to the wrong client is the breach that follows.
HMRC, pension providers and the parties the provider deals with
The provider submits real-time information to HMRC, files with the pension provider under the employer's auto-enrolment duties, pays employees through a payment service, issues payslips through a portal and may deal with the court for attachment of earnings orders, and the DPA should describe each recipient and its role (HMRC and the pension provider as controllers in their own right, the payment and payslip services as the provider's sub-processors with general authorisation and flow-down, any software provider as a sub-processor), with the international transfers under Article 46 of the UK GDPR stated where the software or the portal is hosted abroad; the employee's payslip portal is where employees exercise their rights, and the DPA should say who answers a request.
Errors, corrections and the liability for a wrong payslip
Payroll errors (an underpayment, an overpayment, a wrong tax code applied, a missed pension contribution, a late filing with a penalty) are the main source of disputes between a provider and its clients, and the DPA and the service terms together should say that the provider processes the inputs the client supplies and is responsible for the calculation and the filing on those inputs, that the client is responsible for the inputs and their timing, that errors are corrected in the next run at no charge, that the provider's liability for penalties and losses caused by its errors sits within a stated cap, and that data protection liability follows Article 82 of the UK GDPR with each party liable for its own failures; the DPA should also require the provider to tell the client of an error that is a breach (a payslip sent to the wrong person) in time for the client's seventy-two-hour deadline under Article 33.
Retention, hand-over and the year-end records
Payroll records must be kept for the period HMRC requires after the end of the tax year to which they relate, and the DPA should state who keeps them (the client as controller, with the provider holding copies for the service and for the period the client instructs), the provider's deletion of the data at the end of the service within a stated period after handing over the records and the year-to-date figures to the client or the new provider in a usable form, the retention of the provider's own records of its work (its audit trail, which it may keep for its own legitimate interests and professional obligations), and the certification of deletion; a payroll provider that keeps every client's data indefinitely has a retention failure of the kind the regulator finds on inspection.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our payroll bureau has never given us a DPA. Is that a problem?
It is, for the employer: the law requires a written contract with the processor containing the listed terms. The provider should supply one with its service terms, and the DPA drafted for a provider does that.
Is payroll data special category data?
Parts of it: union deductions, sickness, maternity and some benefit elections reveal special category data. The DPA recognises that, restricts use and access, and requires security to match.
Who is liable if the provider makes a payroll error?
The provider for the calculation and filing on the inputs supplied, within a stated cap; the client for the inputs and their timing. The DPA and the service terms allocate it, and a wrong payslip sent to the wrong person is also a breach to notify.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Reviewing a payroll or HR outsourcing agreement
- Data processing agreement for a bookkeeper
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.