Data Processing Agreement

A GDPR Article 28 processor agreement with the eight mandatory clauses and a filled-in processing schedule.

100% free. Runs entirely in your browser - your files and data never leave your device and nothing is uploaded to any server.

Template, not legal advice. This is a template, not legal advice. It covers the clauses Article 28(3) requires, but the schedule is what an auditor reads, and only you know what is really in it. Where personal data leaves the UK or EEA you also need a transfer risk assessment alongside the clauses referred to here - that assessment is a separate piece of work this cannot do for you.

Start from an example

Fills every answer with a worked example you can edit. Pick the one closest to your business.

0 of 10 details filled
The parties
What the processing is for
The processing may only be done for this. Anything vague here becomes a wide permission.
The schedule

Article 28(3) requires this. It is also the part an auditor reads first, and the part generic templates leave blank.

Article 28(3) requires this list. A DPA without it fails an audit.
Sub-processors and transfers
Name, purpose and country. The country is what decides whether the transfer clause below applies.
Operational terms
The Controller has 72 hours to tell the regulator, so a processor notice period longer than 48 hours is not workable.

Data Processing Agreement

15 sections · 1335 words · updates as you type

Data Processing Agreement

Last updated: 13 September 2026

Parties

This Data Processing Agreement ("DPA") is made on 13 September 2026 between:

[Controller] of [Controller address] ("the Controller")

and

[Processor] of [Processor address] ("the Processor").

It forms part of, and is subject to, the main agreement between the Parties under which the Processor provides services to the Controller ("the Main Agreement"). Where this DPA conflicts with the Main Agreement on the processing of personal data, this DPA prevails.

Definitions

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU General Data Protection Regulation (EU) 2016/679, and any other law applicable to the processing under this DPA.

"Personal Data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in Data Protection Law.

"Sub-processor" means any third party engaged by the Processor to process Personal Data under this DPA.

Roles of the parties

The Controller determines the purposes and means of the processing. The Processor processes Personal Data only on behalf of the Controller.

The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subject are set out in the Schedule at the end of this DPA.

The Controller is responsible for ensuring it has a lawful basis for the processing it instructs, and that any notice or consent required has been given. The Processor is entitled to rely on the Controller instructions in that respect.

Processing on documented instructions

The Processor shall process Personal Data only on the Controller documented instructions, including as to transfers to a third country, unless required to do otherwise by law - in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits it from doing so.

The Main Agreement, this DPA and the use of the service in its ordinary way constitute the Controller initial documented instructions. Further instructions must be given in writing.

The Processor shall tell the Controller immediately if, in its opinion, an instruction infringes Data Protection Law. The Processor may suspend the affected processing until the instruction is confirmed, corrected or withdrawn.

Confidentiality of personnel

The Processor shall ensure that every person authorised to process Personal Data under this DPA is bound by an appropriate duty of confidentiality, whether by contract or by statute, and that the duty survives the end of their engagement.

Access is limited to those who need it to deliver the services, and is removed when they no longer do.

Security of processing

Taking account of the state of the art, the cost of implementation and the risk to data subjects, the Processor shall implement appropriate technical and organisational measures under Article 32, including as appropriate:

  • encryption of Personal Data in transit and at rest;
  • measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems;
  • the ability to restore availability and access to Personal Data promptly after an incident;
  • a process for regularly testing and evaluating the effectiveness of those measures;
  • role-based access control, with access granted on a need-to-know basis and reviewed periodically;
  • logging of access to and changes affecting Personal Data.

The Processor shall not materially reduce the level of protection these measures provide during the term of this DPA.

Sub-processors

The Controller gives general authorisation for the Processor to engage Sub-processors, and the Processor maintains a current list which it makes available to the Controller on request.

The Processor shall give the Controller at least 30 days notice before adding or replacing a Sub-processor. The Controller may object on reasonable data protection grounds within that period; if the Parties cannot resolve the objection, the Controller may terminate the affected part of the services without penalty.

The Processor shall impose on every Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each Sub-processor obligations.

Assisting with data subject rights

Taking account of the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, so far as possible, in responding to requests to exercise data subject rights - access, rectification, erasure, restriction, portability and objection.

Where the Processor receives such a request directly, it shall not respond to it itself, other than to confirm receipt and direct the person to the Controller, and shall pass the request to the Controller without undue delay.

Assisting with security, breaches and assessments

The Processor shall assist the Controller in complying with its obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to the Processor. That includes assistance with data protection impact assessments and with any prior consultation with a supervisory authority.

The Processor shall notify the Controller without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting Personal Data processed under this DPA. The notification shall describe, as far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not yet available, the Processor shall provide information in phases rather than delay the first notification.

The Processor shall not make any public statement about a breach affecting the Controller Personal Data without the Controller prior written agreement, unless required to by law.

Return or deletion at the end

On the Controller written request, and in any event on the end of the provision of services, the Processor shall at the Controller choice delete or return all Personal Data and delete existing copies, unless the law requires it to keep them.

Unless the Controller instructs otherwise, deletion takes place 30 days after the end of the services, giving the Controller a window to export its data. Where Personal Data remains in routine backups that are not readily accessible, the Processor shall isolate it from further processing and delete it on the ordinary backup cycle, and this DPA continues to apply to it until then.

The Processor shall certify deletion in writing on request.

Information and audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

The Controller may audit the Processor on reasonable written notice of at least 30 days, no more than once in any 12-month period unless a personal data breach or a regulator requires otherwise. Audits take place during business hours, are subject to confidentiality, and must not unreasonably disrupt the Processor business. The Controller bears its own costs.

International transfers

The Processor shall not transfer Personal Data outside the United Kingdom or the European Economic Area without the Controller prior written consent.

Where the Controller consents to such a transfer, the Processor shall first put in place a transfer mechanism valid under Data Protection Law, and shall tell the Controller which mechanism it relies on.

Liability and term

This DPA takes effect on the date above and continues for as long as the Processor processes Personal Data on the Controller behalf. The obligations of confidentiality, deletion and assistance survive its end.

Liability under this DPA is subject to the limitations and exclusions in the Main Agreement, except where Data Protection Law does not permit that - in particular, nothing in this DPA limits either Party liability to a data subject or to a supervisory authority.

Schedule - details of the processing

Subject matter and purpose of the processing

[the services under the main agreement]

Nature of the processing

Collection, storage, organisation, retrieval, use, transmission and deletion of Personal Data, to the extent needed to provide the services.

Duration

For the term of the Main Agreement, plus the retention period of 30 days set out above.

Categories of data subject

  • [list the categories of individual whose data is processed]

Categories of personal data

  • [list the types of personal data processed]

Approved sub-processors

  • None at the date of this DPA.

Signed

For [Controller] (Controller)

Signature: ______________________________

Name: __________________________________

Position: _______________________________

Date: ___________________________________

For [Processor] (Processor)

Signature: ______________________________

Name: __________________________________

Position: _______________________________

Date: ___________________________________

Generated from a template. Not legal advice - read it before you publish or sign it.

Other documents you can generate

Most sites need more than one. A privacy policy without terms, or terms without a refund policy, leaves the obvious gap.

Privacy PolicyA privacy policy written from what your site actually does - GDPR and CCPA sections included only where they apply.Terms and ConditionsTerms of service built around what you actually sell - goods, subscription, downloads or services.Cookie PolicyA cookie policy with a real table - each cookie named, with its purpose and how long it lasts.Cookie Consent BannerGenerates a working consent banner - blocks tagged scripts until consent, Google Consent Mode v2, no dark patterns.Refund and Return PolicyA refund policy customers can follow and payment processors accept - windows, exclusions and statutory rights in plain words.Website DisclaimerA disclaimer that names the actual risk your site carries, plus affiliate and sponsorship disclosures.Accessibility StatementA WCAG accessibility statement that states what you actually meet, names known issues, and gives people a route to report problems.Non-Disclosure AgreementA mutual or one-way NDA with a real purpose clause, standard carve-outs and a defined term.Freelance ContractAn independent contractor agreement that pins down scope, revisions, IP ownership and what happens when payment is late.W-9 FormFills a substitute Form W-9 in your browser - your TIN is never uploaded, stored or sent anywhere.1099-NEC Contractor SummaryPrepares a 1099-NEC recipient statement and a payer summary - with a straight answer about what you can and cannot print yourself.Shipping PolicyA shipping policy Shopify and Amazon sellers can publish - origin, times, tracking, duties and who pays.DSAR Form GeneratorA data-delete and access request page you can host - GDPR and CCPA wording, no upload, no signup.

About this tool

Answer a handful of questions and the document writes itself. It exists for SaaS vendors, agencies and developers whose enterprise customers will not sign until a DPA exists, and during procurement, because it is usually the document holding up the contract is when it is worth twenty minutes. One point that separates a usable version from a copied one: article 28(3) lists eight things a processor contract must contain, and a DPA missing any one of them is not a DPA - it is a document that fails an audit. All eight are unconditional here; what the questionnaire changes is the schedule, which is the part auditors actually read and the part generic templates leave blank. Nothing irrelevant is included. A clause that does not apply to you is omitted, not padded - a document describing something you do not do is a problem in its own right. Nothing is uploaded. The whole thing is assembled locally, so confidential details stay on your machine and there is no account to create or delete later.

How to use this tool

  1. Answer the questionsController. Controller address. Processor. Nothing you type leaves the browser.
  2. Watch it assembleClauses appear and disappear as you answer, so the document matches what you actually do rather than a generic template.
  3. Copy or downloadCopy the text, or download as PDF, Word or plain text. The Word version is the one to edit.

Key features

  • Runs entirely in your browser. Nothing uploaded, nothing stored, no account.
  • Free with no watermark, no email wall and no per-document limit.
  • Built from your answers, so clauses you do not need are left out rather than padded.
  • Downloads as PDF, Word or plain text - the Word file is editable with no protection on it.
  • Says plainly what it is and is not, above the preview rather than in a footer.

Common uses

  • Giving a lawyer a draft to review rather than paying them to start from nothing.
  • Replacing a copied document that describes a different business.
  • Preparing what a client, an app store or a payment processor has asked to see.
  • SaaS vendors, agencies and developers whose enterprise customers will not sign until a DPA exists.
  • Getting something in place during procurement, because it is usually the document holding up the contract.

Tips for better results

  • Keep a copy of each version with its date. When someone asks what your terms said last March, the answer needs to be a file rather than a memory.
  • Fill in the free-text fields rather than skipping them. The named lists - processors, exclusions, deliverables - are what make it read as yours rather than copied.
  • Read it before you publish it. It is a draft built from standard clauses, and you are the only person who knows whether every line is true of you.
  • Download the Word version if you expect to edit it. The PDF is for publishing; the .docx is for changing.

Mistakes to avoid

  • Naming no sub-processors. A DPA whose sub-processor list is empty while the service runs on AWS and sends mail through a third party is the first thing a security reviewer catches, and it stalls the deal rather than closing it.
  • Leaving the placeholder text in. Anything in square brackets is a field you skipped, and readers spot them immediately.
  • Publishing it and never looking again. These go stale - you add a tool, change a processor, start selling somewhere new, and the document still describes last year.
  • Hiding it. A document nobody can find does not do its job - it belongs in the footer of every page.

Frequently asked questions

Answer the questions on the left. The document builds as you type, and you can copy it, or download it as PDF, Word or plain text when it looks right.

No. It assembles a draft from standard clauses, and every page says so above the preview. Missing or weak DPAs are found during vendor security reviews, which is a sales problem long before it is a regulatory one.

Yes - free, no signup, no email required and no watermark. It runs in your browser, which is why it costs nothing to provide.

Broadly, SaaS vendors, agencies and developers whose enterprise customers will not sign until a DPA exists. The best time to do it is during procurement, because it is usually the document holding up the contract.

Naming no sub-processors. A DPA whose sub-processor list is empty while the service runs on AWS and sends mail through a third party is the first thing a security reviewer catches, and it stalls the deal rather than closing it.

No. Everything happens on your device - nothing is sent to a server, nothing is stored, and closing the tab clears it.

Yes. Download the Word version and change anything you like - it is a normal .docx with no protection on it.

People also search for

  • free data processing agreement template
  • data processing agreement template usa
  • data processing agreement template uk
  • data processing agreement template for small business
  • data processing agreement template template
  • data processing agreement template no signup
  • data processing agreement template

Related guides