Templates · Core pack

Data processing agreement template, GDPR ready.

The data processing agreement is the document that appears the first time a serious customer's legal team reviews you: if your product touches their users' personal data, UK GDPR Article 28 requires written terms between you, and they will not sign without them.

This template drafts a DPA that answers a security review's checklist the first time, instead of being negotiated line by line from a blank page.

When you need it

The moments this document comes up.

  • A customer's procurement asks for your DPA, and the deal waits on the answer.
  • Your product processes personal data on behalf of business customers.
  • You appoint a new sub-processor and existing customers must be told.
  • A customer's own DPA lands in your inbox and you need to know what a fair one looks like.

What's inside

What the template covers.

The sections below mirror the document the generator drafts. Every template is a starting point, not legal advice, and says so on its face.

01

Roles and scope

Who is controller and who is processor, and exactly which processing the agreement covers.

02

Processing details

Subject matter, duration, nature and purpose, data categories, and data subjects, the annex Article 28 expects.

03

Processor obligations

Documented instructions, confidentiality, security measures, and help with data subject requests.

04

Sub-processors

The authorisation model, the current list, and how changes are notified and objected to.

05

International transfers

How transfers outside the UK are covered: adequacy or standard contractual clauses.

06

Breach, audit, and exit

Breach notification without undue delay, audit rights, and deletion or return when the contract ends.

Settings, not blanks

Drafted from choices you make.

A downloaded template hands you someone else's prose with holes in it. Here the document is generated from a settings sheet, so the wording follows your answers, and changing an answer later regenerates the parts it touches.

DATA PROCESSING AGREEMENT

SETTINGS
  • JurisdictionEngland & Wales
  • RoleProcessor
  • Sub-processorsListed in annex
  • TransfersUK adequacy + SCCs
Generate document

After generating, the document opens in the editor like any other: edits arrive as tracked changes you accept or reject, compliance checks run against real rulepacks, and exports come out as print-ready PDF or DOCX your lawyer can redline. What a compliance check actually does →

FAQ

Fair questions.

When does a startup need a DPA?

The moment you process personal data on another business's behalf, which for a SaaS product is usually the first paying customer. UK GDPR Article 28 requires a written contract covering that processing; larger customers will send their own if you cannot produce yours, and theirs will be drafted in their favour.

What does Article 28 actually require the DPA to say?

A specific list: process only on documented instructions, keep confidentiality, secure the data, use sub-processors only with permission, help the controller with data subject rights and breaches, allow audits, and delete or return data at the end. The GDPR rulepack checks each of those is actually present, which is how a homemade DPA usually fails a review.

A customer sent me their DPA. Should I just sign it?

Read the liability and audit clauses first: customer-drafted DPAs often carry uncapped data liability and unrestricted on-site audit rights. Having your own template puts a reasonable starting point on the table, and having a solicitor review anything unusual before signing is money well spent.

Draft your data processing agreement this week.

It is one of the first-week five: drafted, checked, and exported inside the 7-day free trial. Pay and not have your documents? One email within 30 days refunds every penny, and every export stays yours.