Data processing agreement template, GDPR ready.
The data processing agreement is the document that appears the first time a serious customer's legal team reviews you: if your product touches their users' personal data, UK GDPR Article 28 requires written terms between you, and they will not sign without them.
This template drafts a DPA that answers a security review's checklist the first time, instead of being negotiated line by line from a blank page.
The moments this document comes up.
- A customer's procurement asks for your DPA, and the deal waits on the answer.
- Your product processes personal data on behalf of business customers.
- You appoint a new sub-processor and existing customers must be told.
- A customer's own DPA lands in your inbox and you need to know what a fair one looks like.
What the template covers.
The sections below mirror the document the generator drafts. Every template is a starting point, not legal advice, and says so on its face.
01
Roles and scope
02
Processing details
03
Processor obligations
04
Sub-processors
05
International transfers
06
Breach, audit, and exit
Drafted from choices you make.
A downloaded template hands you someone else's prose with holes in it. Here the document is generated from a settings sheet, so the wording follows your answers, and changing an answer later regenerates the parts it touches.
DATA PROCESSING AGREEMENT
SETTINGS- JurisdictionEngland & Wales
- RoleProcessor
- Sub-processorsListed in annex
- TransfersUK adequacy + SCCs
After generating, the document opens in the editor like any other: edits arrive as tracked changes you accept or reject, compliance checks run against real rulepacks, and exports come out as print-ready PDF or DOCX your lawyer can redline. What a compliance check actually does →
Fair questions.
When does a startup need a DPA?
The moment you process personal data on another business's behalf, which for a SaaS product is usually the first paying customer. UK GDPR Article 28 requires a written contract covering that processing; larger customers will send their own if you cannot produce yours, and theirs will be drafted in their favour.
What does Article 28 actually require the DPA to say?
A specific list: process only on documented instructions, keep confidentiality, secure the data, use sub-processors only with permission, help the controller with data subject rights and breaches, allow audits, and delete or return data at the end. The GDPR rulepack checks each of those is actually present, which is how a homemade DPA usually fails a review.
A customer sent me their DPA. Should I just sign it?
Read the liability and audit clauses first: customer-drafted DPAs often carry uncapped data liability and unrestricted on-site audit rights. Having your own template puts a reasonable starting point on the table, and having a solicitor review anything unusual before signing is money well spent.
Related templates.
Privacy policy
UK GDPR privacy notice for your website and product: what you collect, why, and users' rights.
Terms of service
The terms your site and product run on: acceptable use, IP, liability, and governing law.
Mutual non-disclosure agreement
A mutual NDA both sides can sign without a fight: obligations, carve-outs, and term.
Draft your data processing agreement this week.
It is one of the first-week five: drafted, checked, and exported inside the 7-day free trial. Pay and not have your documents? One email within 30 days refunds every penny, and every export stays yours.