Data processing agreement for a SaaS vendor
A data processing agreement for a SaaS provider to attach to its customer terms, drafted for the vendor with the privacy notice, for a fixed fee of £795 in five working days.
Data processing agreement for a SaaS vendor
A data processing agreement for a software-as-a-service provider to offer its customers, drafted for the vendor, covering the vendor's own DPA and why it beats signing each customer's, the mandatory terms and the schedule that carries them, sub-processors, the list and the notification customers accept, security, audits and the certifications that stand in for them, transfers, hosting regions and the safeguards, and deletion, breach notification and the liability that matches the main terms. £795 with the privacy notice, delivered in five working days.
Buy now, £795A SaaS vendor processes its customers' personal data on their behalf, which means every customer is legally required to have a data processing agreement with it; a vendor without its own version ends up signing each customer's, with different audit rights, breach deadlines and liability positions in each. The vendor's DPA has to contain the terms the law requires, carry the schedule of what is processed, handle sub-processors in a way customers will accept, describe the security and the audit route, state the hosting and the transfers, and align deletion, breach notification and liability with the main terms. I draft the data processing agreement and the privacy notice for the business for a fixed fee of £795, delivered in five working days, with a note on the operational steps the documents assume.
Who this is for
SaaS and software providers in England and Wales with business customers, from a start-up fielding its first security questionnaire to an established product whose DPA was written for an earlier version of the service.
What matters in a SaaS vendor's data processing agreement
The vendor's own DPA and why it beats signing each customer's
A controller and its processor must have a written contract containing the terms Article 28 of the UK GDPR lists, and a vendor that offers its own compliant DPA as part of its standard terms (accepted online, or signed as a schedule) gives every customer the same terms, keeps the audit, breach and liability positions consistent with the main agreement, and spends its negotiating time on the enterprise customers whose procurement teams will send their own; a vendor without one signs whatever each customer sends, which is where twenty-four-hour breach notification and uncapped data protection liability come from.
The mandatory terms and the schedule that carries them
The DPA must set out the subject matter, duration, nature and purpose of the processing, the data types and data subject categories, and the obligations and rights of the controller, which the agreement carries in a schedule describing the service, and must oblige the vendor to process on documented instructions only, ensure confidentiality, meet the Article 32 security standard, engage sub-processors only when authorised and on flow-down terms, assist the customer with rights requests and its security, breach and impact assessment obligations, return or delete the data at the end, and supply the information and audit access that demonstrate compliance; the agreement should state that the customer's instructions are the terms and the service's documented functionality, so that a customer cannot issue instructions the product cannot follow.
Sub-processors, the list and the notification customers accept
A SaaS vendor uses hosting, email, support and analytics providers that are sub-processors under Article 28(2) and (4) of the UK GDPR, which require the controller's prior authorisation and flow-down of the same obligations; the practical form is general authorisation in the DPA, a published sub-processor list, notification of changes with a period in which the customer may object on reasonable grounds, and a termination right where an objection cannot be resolved, which customers accept because the alternative (specific consent to each) does not work for a multi-tenant service; the vendor must hold written terms with each sub-processor that match what it has promised.
Security, audits and the certifications that stand in for them
Article 32 of the UK GDPR requires security appropriate to the risk, and the DPA should describe the measures in a security schedule (encryption in transit and at rest, access controls, logging, backups, testing, personnel vetting, business continuity) that the vendor can honour; the customer's right to audit under Article 28(3)(h) should be satisfied in the first instance by the vendor's independent certifications and audit reports (an information security standard certificate, a service organisation report), with an on-site audit only where the reports are insufficient, on notice, at the customer's cost, once a year and under confidentiality, because a vendor that grants unrestricted audit rights to every customer has granted something it cannot deliver.
Transfers, hosting regions and the safeguards
The DPA should state where the data is hosted, whether customers can choose a region, which sub-processors are outside the United Kingdom, and the safeguards under Article 46 of the UK GDPR for each transfer (the international data transfer agreement, the addendum to the EU standard contractual clauses, an adequacy regulation, or the UK extension to the US data privacy framework for certified providers), with the transfer risk assessment the regulator expects carried out and the position for EU customers (who need the EU clauses) addressed with an EU addendum where the vendor sells there.
Deletion, breach notification and the liability that matches the main terms
The DPA should provide for the return or deletion of customer data at the end of the subscription within a stated period (with backups overwritten on the vendor's cycle and the customer's export route stated), breach notification to the customer without undue delay and within a stated period that lets the customer meet its own seventy-two-hour deadline under Article 33 (which means a vendor commitment measured in hours or a couple of days, not a promise of twenty-four hours for every incident), assistance at the customer's reasonable cost, and liability for data protection breaches within the main agreement's cap or a stated higher cap, with each party liable under Article 82 for its own failures; a DPA that leaves data protection liability uncapped while the main terms cap everything else has reopened the negotiation the main terms closed.
What it costs
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Our customers keep sending us their own DPAs. Do we have to sign them?
Not necessarily. A vendor with a compliant DPA of its own can offer it instead, and most customers accept it or negotiate from it. Signing each customer's version gives you a different liability and breach position with each.
Can we use sub-processors without asking every customer?
Under general authorisation in the DPA, with a published list, notice of changes and a right to object, yes. That is the standard structure for a multi-tenant service and customers accept it.
Should our DPA promise twenty-four-hour breach notification?
It should promise notification without undue delay within a period that lets the customer meet its own seventy-two hours, which the vendor can honour. Twenty-four hours for every incident is a promise most vendors cannot keep.
Related guidance and services
- Data protection agreements and privacy terms, £795, the service this page describes
- SaaS and technology contracts, £995
- Terms and conditions drafting, £995
- Privacy notice for a SaaS product
- Reviewing a customer's data processing agreement
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.