Data processing agreement for a virtual assistant

A data processing agreement for a virtual assistant or outsourced administrator to use with clients, drafted for the assistant with the privacy notice, for a fixed fee of £795 in five working days.

Share

Data processing agreement for a virtual assistant

A data processing agreement for a virtual assistant or outsourced administrator, drafted for the assistant, covering why an assistant with the inbox is a processor, the mandatory terms for work that has no fixed scope, the assistant's own devices, accounts and home, confidentiality, the client's contacts and the client's own clients, subcontracting, cover and the assistant abroad, and the end of the engagement and the data on a laptop in a spare room. £795 with the privacy notice, delivered in five working days.

Buy now, £795

A virtual assistant works inside the client's inbox, diary, CRM and documents, from their own laptop in their own home, often for several clients at once and sometimes from another country. Every client is legally required to have a data processing agreement with them, and the agreement has to describe work that has no fixed scope, deal with the assistant's own devices and accounts, protect the client's contacts and the client's own clients, say whether the assistant may use cover or subcontractors, and settle what happens to the data on the assistant's laptop when the engagement ends. The business receives the data processing agreement, the privacy notice and a note on the operational steps they assume within five working days for a fixed £795.

Who this is for

Virtual assistants, outsourced administrators, executive assistants working remotely for several clients, and the agencies that place them, in England and Wales.

What matters in a virtual assistant's data processing agreement

Why an assistant with the inbox is a processor

An assistant who manages the client's email, diary, contacts, invoicing or customer correspondence processes the personal data of everyone the client deals with, on the client's instructions, and is the client's processor under Article 4 of the UK GDPR; Article 28 of the UK GDPR makes a written contract with specified terms compulsory between a controller and any processor, which most assistants and their clients do not have, and an assistant who supplies a DPA with their terms of business is giving the client something the client is legally required to obtain and demonstrating the professionalism the client is paying for.

The mandatory terms for work that has no fixed scope

The DPA must set out the processing's subject matter, duration, nature and purpose, the kinds of personal data and the categories of people concerned, and the controller's rights and obligations, and for an assistant the schedule should describe the categories (the client's customers, suppliers, contacts, staff and prospects), the data (contact details, correspondence, financial and account data, whatever the client's business holds), the processing (administration, communication, scheduling, data entry, invoicing) and the instructions (the terms of business and the client's requests as they arise), drafted widely enough to cover work the client has not yet asked for; the assistant must follow the client's documented instructions and nothing else, keep the data confidential, secure it to the Article 32 standard, appoint sub-processors only with authorisation on the same terms, assist with data subject rights and with the client's security, breach and impact assessment duties, delete or return the data at the end, and demonstrate compliance through information and audits.

The assistant's own devices, accounts and home

Article 32 of the UK GDPR requires security appropriate to the risk, and for an assistant working from home on their own equipment the security schedule should cover the devices (a passcode, encryption, updates, security software, a separate user account for the client's work where possible), the accounts (the client's systems accessed through the client's accounts with multi-factor authentication rather than copied into the assistant's own, no forwarding of the client's email to personal accounts), the home (a locked device when unattended, no family use, calls taken privately, paper shredded), the backups, and the assistant's own cloud tools, which are sub-processors needing the client's authorisation; the client should be able to see what the assistant has committed to, because the client is answerable for it.

Confidentiality, the client's contacts and the client's own clients

The DPA should bind the assistant to confidentiality about the client's business and everyone in it, should prohibit the use of the client's contacts for the assistant's own marketing or for other clients, should require the assistant to keep each client's data separate (separate folders, separate logins, no shared spreadsheets across clients), and should say that where the client is itself a processor for its own clients (an agency, a consultancy), the assistant is a sub-processor bound by the same terms the client has given and the client needs its own clients' authorisation to use the assistant; an assistant working for two competing clients needs the separation the DPA describes.

Subcontracting, cover and the assistant abroad

The DPA should say whether the assistant may use another assistant for cover or overflow (a sub-processor under Article 28(2) and (4), needing the client's authorisation and the same terms), should name any agency or platform through which the assistant works, and should address the assistant working from another country (which is an international transfer of the client's data needing the safeguards under Article 46 of the UK GDPR, or an adequacy regulation where the country has one, and which the client may not have realised), with the assistant's location stated and a change notified; a client whose assistant turns out to be in a country with no safeguards has a transfer it did not authorise.

The end of the engagement and the data on a laptop in a spare room

At the end the DPA should require the assistant to return the client's documents and data, to delete the client's data from their devices, accounts and cloud tools within a stated period with written confirmation, to hand back credentials and have their access removed, and to keep nothing except what the law or the assistant's own records require (invoices, the contract), with the client's right to ask for confirmation; the assistant's own privacy notice covers the data they control (their clients' contact details, their own business records), and data protection liability sits within the terms of business' cap each party answering under Article 82 of the UK GDPR for its own failures, with the assistant carrying insurance that covers it.

What it costs

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

I am a one-person virtual assistant. Do my clients really need a DPA with me?

They do. An assistant managing a client's inbox or contacts is the client's processor, and the law requires a written contract with the listed terms. Supplying one with your terms of business gives clients what they need and marks you out.

I work from Spain for UK clients. Does that matter?

It is an international transfer of each client's data, needing a safeguard or an adequacy regulation, which the client may not know about. The DPA states the location and the safeguard so that the client has authorised it.

Can I use my own cloud tools for client work?

As sub-processors, with the client's authorisation in the DPA and the tools' terms checked. Client email should stay in the client's accounts rather than being forwarded to yours.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.