Reviewing a customer's data processing agreement

A review and mark-up of a customer's data processing agreement for the supplier being asked to sign it, with the changes to ask for and why, for a fixed fee of £495 in three working days.

Share

Reviewing a customer's data processing agreement

A review of the data processing agreement a customer has sent a supplier, for the supplier, covering what customers add to the law and why, the clauses that cost money: breach deadlines, audits and assistance, liability, indemnities and the cap the main contract forgot, sub-processors, transfers and the operational promises, the review, the mark-up and the explanation that comes back, and the conversation with the customer's procurement team. £495, delivered in three working days.

Buy now, £495

A customer's data processing agreement contains what the law requires and, usually, a good deal more: breach notification within twenty-four hours, audit rights on demand, uncapped liability and an indemnity for the customer's own fines, a veto over sub-processors and a prohibition on any transfer outside the United Kingdom. Some of it the supplier can accept, some of it it cannot deliver, and some of it reopens a liability position the main contract has already settled. The review returns the document marked up with the changes to ask for and an explanation of which provisions are the law, which are the customer's preference and which the supplier should not sign. I review the customer's DPA for the supplier for a fixed fee of £495, delivered in three working days, as a tracked mark-up with notes.

Who this is for

Suppliers, SaaS vendors, agencies, consultancies and service providers in England and Wales who have been sent a data processing agreement by a customer and need to know what they are accepting before they sign.

What matters in reviewing a customer's DPA

What customers add to the law and why

The written contract Article 28 of the UK GDPR requires between controller and processor must contain the terms the Article sets out, which are a modest set of obligations most suppliers can meet, and a customer's template adds to them because the customer's lawyers drafted it for the customer's largest and riskiest suppliers and the procurement team sends it to everyone; the review separates the provisions the law requires (which the supplier accepts), the provisions that are the customer's reasonable preference (which the supplier accepts or negotiates), and the provisions that go beyond what the supplier can deliver or that shift risk the main contract has allocated (which the supplier marks up), with the explanation written so that the supplier can send it to the customer.

The clauses that cost money: breach deadlines, audits and assistance

A promise to notify breaches within twenty-four hours of occurrence (rather than without undue delay after becoming aware, in time for the customer's seventy-two hours under Article 33), an audit right exercisable at any time without notice or limit, an obligation to assist with the customer's subject access requests, impact assessments and regulatory enquiries at no charge, and a duty to implement whatever security the customer specifies from time to time are the clauses that cost a supplier money and that the mark-up addresses: notification measured from awareness within a realistic period, audits by certification and reports with on-site audit on notice and at cost, assistance at reasonable cost beyond what Article 28 requires, and security measured against the supplier's own schedule.

Liability, indemnities and the cap the main contract forgot

Customer DPAs commonly exclude data protection liability from the main contract's cap, add an indemnity for the customer's fines, losses and claims (including the customer's own regulatory fines, which the regulator imposes on the controller for its own failures), and make the supplier liable for the customer's breaches of the UK GDPR; the review checks the DPA against the main contract's cap and exclusions, marks up an indemnity so that it covers only the supplier's own breaches and sits within the cap (or a stated higher cap for data protection where the supplier accepts one), and explains that Article 82 of the UK GDPR already makes each party liable for its own failures, so that an indemnity for the customer's fines is a transfer of the customer's risk rather than a legal requirement.

Sub-processors, transfers and the operational promises

A prohibition on sub-processors without the customer's prior written consent to each, a requirement to keep all data in the United Kingdom, a ban on transfers without the customer's approval of the safeguards, a duty to delete all data within days of termination with certification, and obligations to hold specific certifications are the operational promises a supplier with a hosting provider, a support tool and an email platform abroad cannot keep; the mark-up substitutes general authorisation with a list and a right to object under Article 28(2), states the transfers and the safeguards under Article 46 the supplier uses, aligns deletion with the supplier's backup cycle, and limits certifications to those the supplier holds, with the explanation telling the customer why.

The review, the mark-up and the explanation that comes back

The review returns the customer's DPA as a tracked mark-up with the supplier's proposed changes and a note explaining each: which clause, what it says, what the law requires, what the supplier can accept and what it proposes instead, in terms the supplier can forward to the customer's procurement or legal team; where the DPA is attached to a main agreement the review reads the two together, because the DPA's liability and termination provisions only make sense against the main terms, and where the customer is in the European Union the review checks that the DPA's transfer provisions work for EU data as well.

The conversation with the customer's procurement team

Most customers accept most of the mark-up, because the changes are the ones every competent supplier asks for and the procurement team has seen them before, and the note is written to make that conversation short: the law requires this, we accept that, we propose this instead for the following reason; where the customer refuses to move on a point the supplier cannot accept (uncapped liability, twenty-four-hour notification, a sub-processor veto), the supplier has to decide whether the contract is worth the risk, and the note says which points are in that category; the supplier's own DPA, offered instead, is the stronger position for the next customer.

What it costs

Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

A big customer has sent us a thirty-page DPA. Can we just sign it?

Read it first. It will contain the law's requirements plus audit rights, breach deadlines and liability positions the customer's lawyers wrote for its riskiest suppliers. The review marks up the two or three that matter and explains the rest.

Is uncapped data protection liability normal?

It is common in customer templates and rarely necessary. Article 82 already makes each party liable for its own failures; the mark-up brings data protection liability within the main contract's cap or a stated higher cap, and limits any indemnity to the supplier's own breaches.

What do we get back?

The customer's DPA as a tracked mark-up with the proposed changes, and a note explaining each change in terms you can forward to the customer, in three working days.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.