When a supplier handles your customers' data: the contract UK GDPR requires
By the Offrano editorial team · · 4 min read
Commission a new website, move email to a cloud provider, hand payroll to a bureau or let an agency run your marketing lists, and a supplier ends up handling personal data on your behalf. Under UK GDPR that relationship needs a written contract with specific terms. Many small businesses sign a supplier's standard terms without checking whether they cover this, or do not realise it applies to them. This guide explains when the contract is needed, what must be in it and what to ask before signing.
✓ Confirm
Almost done: please confirm your email address.
We have sent an email to {email}. We only release your request to businesses once you have clicked the link in it.
Controller and processor
UK GDPR distinguishes between a controller, which decides why and how personal data is processed, and a processor, which processes it on the controller's behalf. If your business collects customer data and a software developer builds and hosts the system, or an IT provider manages your servers, you are usually the controller and the supplier the processor.
The Information Commissioner's Office states the rule plainly: whenever a controller uses a processor, there must be a written contract, or another legal act, in place. If the processor uses another organisation to help, a sub-processor, it needs a written contract with that sub-processor too.
Some suppliers are controllers in their own right, for example an accountant or a payroll bureau that decides some things about the data because of its own legal duties. In those cases a processor contract may not fit, and the relationship needs to be described differently. If you are unsure, ask the supplier how it sees its role and check the ICO's guidance on controllers and processors.
Source: ico.org.uk
What the contract must describe
The ICO's checklist starts with the details of the processing: its subject matter and duration, its nature and purpose, the types of personal data, the categories of people the data is about, and the controller's obligations and rights. A vague reference to 'data we may process' does not meet this.
- what the processing is about and how long it lasts
- what the processing involves and why
- which types of personal data are handled
- whose data it is: customers, employees, patients, pupils
- your obligations and rights as controller
Source: ico.org.uk
The terms the processor must accept
The contract must also contain specific obligations. The processor may act only on your documented instructions unless the law requires otherwise; must ensure its staff are bound by confidentiality; must take appropriate security measures; may engage a sub-processor only with your prior authorisation and under a written contract; must help you respond to people exercising their rights; and must assist you with security, breach notification and data protection impact assessments.
At the end of the contract, the processor must delete or return all personal data at your choice, and it must submit to audits and inspections and give you the information needed to show that both sides meet their obligations.
Source: ico.org.uk
Questions to ask before you sign
Most established suppliers have a data processing agreement ready. Read it against the checklist rather than assuming it is complete. The practical points that cause trouble later are where the data is stored and whether it leaves the UK, which sub-processors are used and how you are told about changes, how quickly the supplier will tell you about a breach, and how data is returned in a usable format when you leave.
Security deserves specific questions. A supplier that holds Cyber Essentials certification has at least shown five basic technical controls; for larger or more sensitive systems, ask what else it does, including backups, access control and testing.
- storage location and any transfers outside the UK
- list of sub-processors and the notice you get before changes
- breach notification time and contact
- export format and deletion at the end of the contract
- certifications held, such as Cyber Essentials or ISO 27001
Source: ncsc.gov.uk
Changes in the law
The Data (Use and Access) Act 2025 amended parts of UK data protection law, and the ICO has said some of its guidance is under review as a result. The core requirement for a written controller-processor contract remains in the ICO's guidance. Check the current version when you draft or renew contracts, and take legal advice for complex arrangements.
Offrano's own position is simple: a customer's enquiry is passed to exactly one business that buys it, which then becomes responsible for that data. If you are commissioning a supplier yourself, our request forms go to one supplier in the chosen field that buys the request; we email you its name, address and phone number before it sees your details, and the service is free for you.
Source: ico.org.uk