Reviewing a supplier's data processing agreement
A review of a supplier's standard data processing agreement for the customer being asked to accept it, with the changes to ask for and why, for a fixed fee of £495 in three working days.
Reviewing a supplier's data processing agreement
A review of the data processing agreement a supplier has offered, for the customer, covering what supplier DPAs leave out and why, breach notification that arrives too late, the sub-processor list, the changes and the objection that cannot be used, the supplier's own use of the data and the aggregation clause, transfers, hosting and the safeguards the supplier claims, and liability, deletion and the clauses to ask for before signing. £495, delivered in three working days.
Buy now, £495A supplier's standard DPA is drafted to protect the supplier: breach notification without undue delay that may mean days, general authorisation for sub-processors with an objection right that leads only to termination, a licence to use the customer's data for the supplier's own analytics, transfers under safeguards the customer cannot check, and liability within a cap that may be a month's fees. Most of it is market practice for a hosted service and the customer accepts it; some of it the customer should ask to change, and some of it tells the customer what it is signing up to and should inform the decision to use the supplier at all. The review returns the DPA marked up with the changes worth asking for and a note on the rest. I review the supplier's DPA for the customer for a fixed fee of £495, delivered in three working days, as a tracked mark-up with notes.
Who this is for
Businesses in England and Wales accepting a software, hosting, marketing, HR, payroll or other supplier's data processing terms, and anyone whose supplier has said its DPA is non-negotiable.
What matters in reviewing a supplier's DPA
What supplier DPAs leave out and why
Whenever a processor acts for a controller, Article 28 of the UK GDPR requires a written contract containing the terms it lists, and a supplier's DPA usually contains them in form while qualifying them in substance: instructions limited to the supplier's documented functionality, assistance limited to what the product provides, audit limited to the supplier's reports, and deletion limited to what the supplier's backup cycle allows; the review checks that each mandatory term is present and workable, identifies the qualifications that matter for the customer's data and explains which qualifications are market practice for a hosted service and which are the supplier protecting itself at the customer's expense.
Breach notification that arrives too late
The customer must notify the Information Commissioner's Office within seventy-two hours of becoming aware of a reportable breach under Article 33 of the UK GDPR, and a supplier DPA that promises notification 'without undue delay' with no period, or within seventy-two hours of the supplier's own confirmation, can leave the customer learning of a breach after its own deadline has passed; the review marks up a notification period measured from the supplier's awareness (hours or a stated short period, not days), the information the supplier must provide (what happened, whose data, what the supplier has done), and the supplier's cooperation with the customer's notification to individuals under Article 34, because the customer is the party the regulator fines for a late notification.
The sub-processor list, the changes and the objection that cannot be used
Supplier DPAs provide general authorisation for sub-processors under Article 28(2) of the UK GDPR with a published list, notification of changes (sometimes only by updating a web page the customer must check) and a right to object whose only consequence is that the customer may terminate the service, which for a customer that has migrated its operations to the supplier is no remedy; the review asks for notification by email or in-product, a reasonable period to object, a genuine attempt to resolve the objection, and a refund of prepaid fees on termination, and checks the current list for sub-processors the customer would not accept, because the list is where the customer discovers where its data is.
The supplier's own use of the data and the aggregation clause
Many supplier DPAs and terms grant the supplier a right to use the customer's data to improve the service, to train models, to produce aggregated statistics or benchmarks, or to derive anonymised data it may keep and use, which takes the supplier outside the processor role for that use (Article 28(10) makes a processor that determines its own purposes a controller) and may be a disclosure of the customer's customers' data the customer has no basis for; the review identifies the clause, explains what it permits, and marks up a limitation (anonymised and aggregated only, no training on identifiable data, no use the customer's own privacy notice does not cover), with the customer told where the supplier is unlikely to move and what that means.
Transfers, hosting and the safeguards the supplier claims
The review checks where the supplier hosts, which sub-processors are outside the United Kingdom, and which safeguard under Article 46 of the UK GDPR the DPA relies on for each (the international data transfer agreement, the addendum to the EU standard contractual clauses, an adequacy regulation, the UK extension to the US data privacy framework for a certified supplier), whether the safeguard is attached or merely referred to, whether the supplier has carried out a transfer risk assessment, and whether the customer's own obligations (to tell its data subjects about the transfers, to have its own assessment) are met; a DPA that says data 'may be transferred in accordance with applicable law' has told the customer nothing, and the mark-up asks for the specifics.
Liability, deletion and the clauses to ask for before signing
Supplier DPAs cap data protection liability within the main terms' cap (often a year's fees or less) and exclude indemnities, which a customer of a large hosted service will not change but should know, and the review explains the exposure the customer carries as a result and the insurance that covers it; deletion at the end should be within a stated period, with export available before it and certification on request, and the review asks for both; and the note lists the handful of changes worth asking for (notification period, objection remedy, data use limitation, transfer specifics, deletion certification), the market-practice provisions to accept, and the points that should inform whether the customer uses the supplier at all, because a supplier's refusal to say where it hosts is information.
What it costs
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our supplier says its DPA is non-negotiable. Is the review still worth it?
It is, because the review tells you what you are accepting (the breach timing, the data use rights, the transfers, the liability cap) and which points the supplier's own terms may already allow you to configure. Large suppliers do not negotiate; they do answer questions, and the note tells you which to ask.
What should the breach notification clause say?
Notification measured from the supplier's awareness within hours or a stated short period, with the information you need for your own seventy-two hours, and cooperation with your notification to individuals. 'Without undue delay' with no period can mean days.
The DPA lets the supplier use our data to improve its service. Is that normal?
Common, and it takes the supplier outside the processor role for that use. The review marks up a limitation to anonymised and aggregated data and tells you whether the supplier is likely to agree, and what your own privacy notice needs to say if it does not.
Related guidance and services
- Data protection agreements and privacy terms, £495, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Reviewing a customer's data processing agreement
- International data transfer agreement for a UK business
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.