Reviewing a data processing schedule in a customer's contract
Review of a data processing schedule, data processing addendum or Article 28 terms in a customer's contract,, marked up with a written explanation, for a fixed fee of £495 in three working days.
Reviewing a data processing schedule in a customer's contract
A supplier-side review of the data processing schedule or addendum a customer requires, covering the mandatory Article 28 terms, the instructions and their scope, sub-processors and transfers, security and breach notification, assistance and its cost, audit, deletion and return, and the liability the schedule adds. £495, in three working days.
Buy now, £495A data processing schedule sets out the terms on which a supplier processes personal data for a customer, and the law requires certain of them: a contract between a controller and its processor must contain the provisions listed in Article 28 of the UK GDPR. Customers' schedules add to those provisions, on breach notification periods, on assistance, on audit and on liability, and the additions are contractual choices rather than legal requirements. I review the schedule from the supplier's side and return it marked up with a written explanation of what the law requires, what the customer has added, and the changes a customer will accept, for a fixed fee of £495 in three working days.
Who this is for
Software, SaaS, IT services, marketing, payroll, HR, logistics and other suppliers in England and Wales that process personal data for their customers and have been sent a data processing schedule, addendum or agreement to sign. The supplier and the customer are businesses; the supplier is the processor and the customer the controller for the data the schedule covers.
What to look for in a data processing schedule
The terms the law requires
Article 28 of the UK GDPR, applied with the Data Protection Act 2018, requires the contract to set out the subject matter, duration, nature and purpose of the processing and the types of data and data subjects, and to oblige the processor to act only on documented instructions, to ensure confidentiality, to take appropriate security measures, to engage sub-processors only with authorisation and on the same terms, to assist the controller with data subject rights and with its security, breach and impact assessment obligations, to delete or return the data at the end, and to make available the information needed to demonstrate compliance and allow audits. The review checks that each is present and drafted no wider than the Article requires.
Instructions, purpose and the processing the supplier needs to do
The schedule should describe the processing accurately, and the review checks the description against what the supplier's service does, since a processor that processes outside the documented instructions is treated as a controller for that processing. It asks for the supplier's own operational processing, service improvement, security monitoring, aggregated analytics, to be described and authorised, for a procedure for the customer to give further instructions, and for the supplier's right to notify the customer if an instruction infringes data protection law.
Sub-processors, hosting and international transfers
The schedule will require prior specific consent to each sub-processor or, more workably, general authorisation with a list, notice of changes and a right to object. The review checks the mechanism, lists the supplier's sub-processors and their locations, and checks the transfer provisions: any transfer outside the UK needs a lawful mechanism under Article 46 of the UK GDPR, the International Data Transfer Agreement, the Addendum to the EU standard contractual clauses or adequacy regulations, and the schedule should say which applies and who carries out the transfer risk assessment. The Data (Use and Access) Act 2025 is amending these rules and the review notes the current position.
Security, breach notification and the periods the customer sets
The schedule will specify security measures and require notification of a personal data breach within a period, in hours, with information the supplier may not have. Article 32 of the UK GDPR requires measures appropriate to the risk, and Article 33 requires the processor to notify the controller without undue delay, so that the controller can meet its 72-hour deadline to the ICO. The review asks for the security measures to be those the supplier operates, described in a schedule the supplier controls, for the notification period to run from the supplier's confirmation of a breach affecting the customer's data, and for the initial notice to contain what the supplier knows at the time, with updates to follow.
Assistance, audit and who pays
The supplier must assist the customer with data subject requests, impact assessments, consultations with the ICO and breach handling, and the schedule will provide for that assistance at the supplier's cost. The review asks for assistance beyond a stated level to be charged at the supplier's rates, for audits to be on reasonable notice, once a year unless a breach has occurred, by an independent auditor under confidentiality, limited to the processing for that customer, and for the supplier's existing certifications and audit reports to be accepted first.
Deletion, return, liability and the interaction with the main agreement
The schedule should provide for deletion or return of the data at the customer's choice at the end of the services, with a period for export and a carve-out for data the supplier must retain by law or holds in backups until they cycle. The review checks the liability provisions, since customers put data protection breaches outside the cap or subject them to a higher cap and add indemnities for regulatory fines and claims, and asks for a separate cap the supplier's insurance supports, for fines to be recoverable only to the extent the supplier caused them and the law permits, and for the schedule's precedence over the main agreement to be limited to data protection matters. The Late Payment of Commercial Debts (Interest) Act 1998 continues to apply to the fees.
What it costs
Standard review, £495. Marked-up document and a written explanation of the changes. Three working days.
Complex review, £895. Heavily negotiated or unusually complex documents. Five working days.
Buying online forms the engagement on payment. The scope is what the contract review page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- Your own contract returned with my amendments as tracked changes, plus a clean version with every change accepted, ready to send to the other side
- Comments in the document where a point needs explaining
- A written explanation of what I have changed and why, by email or as an attachment if it is lengthy, marking the points I would hold firm on and the ones that are negotiable
- A view on what is normal market practice and what is the other side pushing their luck
- One round of follow-up questions by email, included
What is not included
- Negotiating directly with the other side, which I quote separately once I know who is on the other side. Where the other side is willing to share a live document, I can work in that document directly
- Drafting a replacement contract from scratch
- Advice on the law of any jurisdiction other than England and Wales
- Tax, accounting or regulatory advice
- Disputes about a contract that is already signed
Questions I am often asked
The customer's schedule requires breach notification within twenty-four hours. Do we have to accept that?
The law requires notification without undue delay, and the customer sets a period to protect its own seventy-two-hour deadline. The review asks for the period to run from your confirmation of a breach affecting the customer's data, in working hours, with the first notice containing what you know and updates to follow.
We use several sub-processors. Do we need the customer's consent for each?
The law allows either specific consent for each or a general authorisation with notice of changes and a right to object, and the review asks for the general authorisation with your current list attached, so that adding a sub-processor is a notification rather than a negotiation.
The schedule puts data protection liability outside the cap. Can we change that?
Customers negotiate this. The review asks for a separate cap set by reference to your cyber insurance, for fines and claims to be recoverable only to the extent your breach caused them and the law allows, and for the exclusions in the main agreement to apply.
Related guidance and services
- Contract review, £495, the service this page describes
- Data protection agreements and privacy terms, £795
- Reviewing a security schedule in a customer's contract
- Reviewing an audit rights clause
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.