Contract clause

Data processing clause under UK GDPR Article 28

A data processing clause is the set of controller to processor terms that Article 28 of the UK GDPR requires whenever one organisation processes personal data on another's behalf. It records what is processed and why, and binds the processor to act only on instructions, keep the data secure, control sub processors and support the controller.

Under the UK GDPR a controller may only use a processor that gives sufficient guarantees, and the guarantees have to be in a binding written contract. The clause is short to state and easy to get subtly wrong, because the regulation lists what it must contain.

· Co-founder

4 min read · Published

Sample clause

a campaign services agreement under which Pellbrook Marketing Ltd, a fictional email agency in Leeds, sends newsletters to the customer list of Harrowgate Garden Centres Ltd

8. Data Processing 8.1 Harrowgate is the controller and Pellbrook is the processor of the Customer List. Schedule 3 sets out the subject matter, duration, nature, purpose, data types and data subjects. 8.2 Pellbrook must process the Customer List only on Harrowgate's documented instructions, including with regard to transfers outside the United Kingdom, and must tell Harrowgate immediately if it considers an instruction infringes data protection law. 8.3 Pellbrook must ensure its personnel who process the Customer List are bound by confidentiality, and must implement the measures required by Article 32 of the UK GDPR. 8.4 Pellbrook must not engage a sub processor without Harrowgate's prior written authorisation, and must impose the same data protection obligations on any sub processor it engages. 8.5 Pellbrook must assist Harrowgate with data subject requests and with its obligations under Articles 32 to 36, and must notify Harrowgate of a personal data breach without undue delay. 8.6 At the end of the Services, Pellbrook must delete or return the Customer List at Harrowgate's choice, and must make available the information needed to demonstrate compliance with this clause, including allowing audits. Audit days beyond the first in a year cost £850 each.

Sample wording, not legal advice.

Variants

Reference to a standalone data processing agreement

The parties already use a full data processing agreement with annexes and want the main contract to point to it.

The parties' Data Processing Agreement dated 2 March 2026, as varied from time to time, applies to all processing of personal data by the Agency on the Client's behalf under this agreement and forms part of it. If this agreement and the Data Processing Agreement conflict on any matter concerning personal data, the Data Processing Agreement prevails. The Agency must not process personal data for the Client until both documents are signed.

EU GDPR version

The controller is established in the European Union, or the processing is subject to the EU regulation rather than the UK one.

The Processor must process Personal Data only on documented instructions from the Controller, in accordance with Article 28 of Regulation (EU) 2016/679. The Processor must not transfer Personal Data to a third country or an international organisation except on those instructions or where Union or Member State law requires it, in which case it must inform the Controller before processing unless that law prohibits it. Any sub processor must be bound by the same obligations by contract.

Australian version under APP 8

An Australian business sends personal information to a provider overseas and relies on the contract as its reasonable steps.

Before receiving any Personal Information from the Customer, the Provider agrees that it will handle that information in accordance with the Australian Privacy Principles, other than APP 1, as if it were an APP entity. The Provider must not use or disclose the information except to perform the Services, must protect it from misuse, interference and loss, and must allow the Customer to verify compliance on reasonable notice.

With a named sub processor list

The processor relies on several platforms and wants general authorisation rather than asking each time.

Harrowgate gives general written authorisation for Pellbrook to use the sub processors listed in Schedule 4, each with its service and processing location. Pellbrook must give Harrowgate at least 30 days written notice of any intended addition or replacement. Harrowgate may object on reasonable data protection grounds within that period, and if the objection is not resolved Harrowgate may end the affected Services without charge.

What to negotiate

The risk of leaving it out

A controller that lets a processor handle personal data without an Article 28 contract is in breach of the UK GDPR itself, whatever the processor then does. It also has no contractual right to direct the processing, audit it or require the data back.

The points Article 28 makes mandatory

Article 28(3) requires the contract to set out the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. It then requires eight commitments from the processor: to act only on documented instructions, including on transfers; to ensure people processing the data are bound by confidentiality; to take the security measures in Article 32; to follow the rules on engaging sub processors; to help the controller answer data subject requests; to help with security, breach notification and impact assessments under Articles 32 to 36; to delete or return the data at the end; and to provide the information needed to demonstrate compliance, including audits. A processor must also tell the controller if an instruction appears to infringe the law.

Controller or processor

The clause only fits when one party genuinely decides the purposes and means of the processing and the other follows. A marketing agency sending a client's newsletter to the client's list is a processor. The same agency building its own audience list and selling access to it is a controller, and a processing clause would describe the relationship falsely. The ICO's guidance on controllers and processors turns on who makes the decisions about why and how data is used, not on what the contract calls each party, so labelling a party does not settle the question.

Where it sits in a generated document

The generator can write the clause inside a services agreement, with Schedule 3 produced as a table of processing details rather than a vague reference. Documents contain no input fields, so the sub processor names, locations and the audit charge in pounds appear as written content. A contents page is only used on long documents of six pages or more, so it suits a standalone agreement rather than a single clause.

Documents that carry this clause

Questions people ask

Is a data processing clause the same as a data processing agreement?

They do the same legal job. A clause places the Article 28 terms inside the main contract, while an agreement puts them in a separate document with its own annexes. Larger suppliers usually have a standard agreement that attaches to every customer contract. Smaller engagements often manage with a well drafted clause and one schedule.

What happens if the contract misses one of the Article 28 points?

The contract does not meet the requirement, and both the controller and, in its own right, the processor can be exposed. Missing points are common where an old contract was updated in a hurry, often the duty to flag unlawful instructions or the processing details. Checking the clause against Article 28(3) line by line is the reliable test.

Does a processor have to report a breach within 72 hours?

The 72 hour period applies to the controller reporting to the Information Commissioner's Office. A processor must tell the controller without undue delay after becoming aware. Because the controller needs time to assess before its own deadline, contracts often set a fixed period for the processor, such as 24 or 48 hours.

Can a processor use data for its own purposes?

Not under a processing clause. If a processor decides to use the data for its own purposes, such as training its products or building its own lists, it becomes a controller for that processing and needs its own lawful basis. A clause should state plainly that the processor acts only on the controller's documented instructions.

Do UK and EU versions of the clause differ?

The Article 28 requirements are essentially the same in both regulations. The differences show up in references to the governing regulation, the supervisory authority, and the transfer rules, since each regime has its own adequacy decisions and transfer tools. A contract covering both usually names both regulations and both sets of transfer safeguards.

Who pays for the processor's help with data subject requests?

The regulation requires assistance but is silent on cost. Many clauses provide that routine help is included in the fees and that substantial work, such as a large access request needing manual review, is charged at agreed day rates. Stating the rate in the contract avoids arguing about it during a statutory deadline.

Put the clause in a finished document

The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.

Create a document with OneCraft

Related clauses

For everything the document generator can do, see the document maker.

Step by step in the builder: Create a document with AI, then Document builder components.

Sources

Written and checked by the OneCraft team. Last checked .