Data processing agreement for a web developer with access to customer data

A data processing agreement for a web developer or digital agency to use with clients whose sites hold customer data, drafted for the developer with the privacy notice, for a fixed fee of £795 in five working days.

Share

Data processing agreement for a web developer with access to customer data

A data processing agreement for a web developer or agency that builds or maintains a client's site, drafted for the developer, covering when a developer is a processor and when it is not, the mandatory terms for build, hosting and maintenance, staging copies, test data and the database on a developer's machine, hosting, plugins and the sub-processors a site depends on, credentials, access and the developer who keeps the keys, and hand-over, hosting migration and the end of the relationship. £795 with the privacy notice, delivered in five working days.

Buy now, £795

A web developer who builds a site holding customer accounts, orders, enquiries or bookings, hosts it, maintains it and keeps a copy of the database on a laptop to test the next release is a processor of the client's customers' data, and every such client is legally required to have a data processing agreement with the developer. The agreement has to say when the developer is a processor (and when a brochure site with no data means it is not), carry the mandatory terms for build, hosting and maintenance, deal with staging copies and test data, cover the hosting and the plugins the site depends on, and settle credentials, access and hand-over when the relationship ends. Drafting for the business, I deliver the data processing agreement, the privacy notice and a note on the operational steps they assume in five working days for a fixed £795.

Who this is for

Web developers, digital agencies and freelance developers in England and Wales who build, host or maintain sites and applications that hold their clients' customer data.

What matters in a web developer's data processing agreement

When a developer is a processor and when it is not

A developer who builds a static brochure site and hands it over without hosting or maintaining it processes no personal data on the client's behalf and needs no DPA (though a confidentiality clause covers what it sees), but a developer who hosts the site, maintains it with administrator access, runs the database or keeps a copy for development is a processor under Article 4 of the UK GDPR of whatever the site holds; Article 28 of the UK GDPR makes a written contract with specified terms compulsory between a controller and any processor for that work, and the developer's DPA should say which of its services involve processing and which do not.

The mandatory terms for build, hosting and maintenance

The DPA must set out the subject matter and length of the processing, its nature and purpose, the data types and categories of individuals, and the controller's rights and duties, and for a developer the schedule should describe the site's users, customers and enquirers, the account, order, enquiry, booking and analytics data the site holds, the hosting, maintenance, support, backup and development the developer performs, and the instructions (the development agreement, the maintenance plan and the tickets); the developer must process only on documented instructions, keep confidentiality, secure the data as Article 32 requires, use authorised sub-processors on matching terms, assist with rights requests and with the client's security, breach and impact assessment duties, return or delete the data at the end, and make compliance demonstrable through information and audit.

Staging copies, test data and the database on a developer's machine

Developers copy the production database to staging and local environments to test releases, which puts the client's customers' data on servers and laptops the client has not assessed, and the DPA should require the developer to use anonymised or synthetic test data where possible, to protect any production copies to the same standard as production (encryption, access control, deletion when the test is done), to keep staging environments off the public internet or behind authentication, and to tell the client where copies exist; a staging site indexed by a search engine with real customer data in it is a breach the client discovers from a customer, and the DPA should make it the developer's obligation to prevent.

Hosting, plugins and the sub-processors a site depends on

The hosting provider, the content delivery network, the email delivery service, the backup service, the form and payment plugins that send data to their providers, the analytics and the developer's own tools are sub-processors under Article 28(2) and (4) where they process the client's data on the developer's instructions, and the DPA should list the categories, grant a general authorisation with notice of changes and a right to object, flow down the obligations, and set out the international transfers and their safeguards under Article 46 of the UK GDPR; where the client contracts with the host directly and the developer merely manages it, the DPA should say so, and the developer should tell the client which plugins send data where, because the client's privacy notice has to state it.

Credentials, access and the developer who keeps the keys

Article 32 of the UK GDPR requires security appropriate to the risk, and the security schedule should cover named accounts with multi-factor authentication, least privilege, the secure storage of credentials (never in email or the repository), the removal of access for leavers, the developer's own devices, the update and patching of the platform and plugins (which is where most site compromises start), the backups and their testing, and the developer's response to a compromise; the DPA should also say who owns the hosting, domain and platform accounts (the client, with the developer as a user), because a developer who holds the domain and the hosting in its own name holds the client's business.

Hand-over, hosting migration and the end of the relationship

At the end the DPA should provide for the hand-over of the site, the database, the backups, the credentials and the documentation in a usable form, the transfer of hosting and domain accounts to the client or its new developer, the deletion of the developer's copies (production, staging, local) within an agreed period with written confirmation, the removal of the developer's access, and cooperation with the migration for a stated period at a stated rate; data protection liability sits within the development agreement's cap or a stated cap, with each party liable under Article 82 of the UK GDPR for its own failures, and the developer's own privacy notice covers the data it controls (its clients' contacts and its own business records).

What it costs

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

We only built the site. Do we need a DPA with the client?

Not for a build handed over with no hosting, maintenance or access afterwards; a confidentiality clause covers what you saw. Hosting, maintaining or keeping a copy of a site with customer data makes you a processor, and then the client needs a DPA.

Can we test releases on a copy of the live database?

Preferably with anonymised data; where real data is used, protected to the production standard, off the public internet and deleted when the test is done. The DPA makes that the developer's obligation.

Who should own the hosting and domain accounts?

The client, with the developer as an authorised user. The DPA says so, and provides for the transfer of accounts and the hand-over of credentials when the relationship ends.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.