Data processing agreement, Pellham & Co and Merrowfield

UK data processing agreement template with sub-processors

A data processing agreement is what a UK controller has to have in writing before a processor touches personal data. This one covers a hosted order management platform for a UK retailer, with the processing annex, a table of five named sub-processors and their transfer safeguards, eight security measures, and a breach notice of 48 hours rather than 72.

Create a document with OneCraft8 A4 pages, editable, then download as a PDF

The document, page by page

Every page as it renders and as it prints, with nothing summarised. Read the wording before you reuse it.

Data processing agreement

Order Management Platform, UK GDPR

Between Pellham & Co Limited, controller, and Merrowfield Systems Limited, processor

Merrowfield Systems Limited
Effective 04/05/2027
Data processing agreement · Pellham & Co and Merrowfield Systems · DPA-2027-33Page 2 of 8
Data processing agreement · Pellham & Co and Merrowfield Systems · DPA-2027-33Page 3 of 8
Data processing agreement · Pellham & Co and Merrowfield Systems · DPA-2027-33Page 4 of 8
Data processing agreement · Pellham & Co and Merrowfield Systems · DPA-2027-33Page 5 of 8
Data processing agreement · Pellham & Co and Merrowfield Systems · DPA-2027-33Page 6 of 8
Data processing agreement · Pellham & Co and Merrowfield Systems · DPA-2027-33Page 7 of 8
Data processing agreement · Pellham & Co and Merrowfield Systems · DPA-2027-33Page 8 of 8
Contents
Parties and background
1
1. Roles and instructions
2
2. Confidentiality and personnel
2
3. Security of processing
3
4. Sub-processors
3
5. International transfers
4
6. Assisting the Controller
4
7. Audit
5
8. Deletion and return
5
9. Liability, term and general
6
Annex 1. Details of the processing
6
Parties and background

This agreement is made on 04/05/2027 between Pellham & Co Limited, company number 04217735, of 18 Shelton Row, Leeds LS1 4PB, called the Controller, and Merrowfield Systems Limited, company number 09482117, of Unit 12, Foundry Wharf, Bristol BS1 6TR, called the Processor.

The Processor supplies a hosted order management platform under a services agreement dated 12/04/2027. Running that platform involves processing personal data for which the Controller is responsible, so this agreement sets out the terms the UK GDPR requires to be in place before that processing begins.

48 hours
Breach notice to the Controller
30 days
Sub-processor notice
30 days
Deletion after the term
1 a year
Audit
1. Roles and instructions
1.1
Who is who
The Controller decides why and how the personal data described in Annex 1 is processed. The Processor processes it on the Controller’s behalf and for no purpose of its own. Nothing in the services agreement changes those roles, and the Processor does not become a controller by choosing how to operate its own infrastructure.
1.2
Documented instructions
The Processor processes personal data only on the Controller’s documented instructions, which are this agreement, the services agreement, and any later written instruction the parties record in the change log. Configuration choices the Controller makes in the platform are instructions for this purpose.
1.3
An instruction that looks unlawful
If the Processor considers an instruction would breach the UK GDPR or the Data Protection Act 2018, it tells the Controller promptly and may pause that instruction until the point is resolved. It is not required to give legal advice, only to raise the concern.
1.4
Records of processing
The Processor keeps a written record of the categories of processing it carries out for the Controller, as Article 30 requires, and makes that record available to the Controller or to the Information Commissioner’s Office on request.
2. Confidentiality and personnel
2.1
Who may see the data
Access is limited to the Processor’s personnel who need it to deliver the services. Each of them is bound by a written confidentiality undertaking that continues after they leave, and access is removed on the day a person’s role changes or ends.
2.2
Training and the point of contact
Personnel with access complete data protection training before access is granted and annually afterwards. The Processor’s data protection contact is its Head of Security, reachable at the address in clause 9.3, and the Controller’s contact is named in the services agreement.
3. Security of processing
3.1
The measures in place
The Processor has implemented the technical and organisational measures below, which take account of the state of the art, the cost of implementation and the risk to the individuals whose data is processed. It reviews them at least annually and does not weaken them during the term.
Area
Measure
Encryption
TLS 1.3 in transit, AES 256 at rest, keys rotated every 12 months
Access control
Role based, least privilege, multi factor authentication on every account
Authentication
Single sign on to the Controller’s identity provider, 30 minute session timeout
Logging
Administrative actions logged and retained for 13 months, alerting on anomalies
Resilience
Backups every 4 hours, restores tested quarterly, recovery target 8 hours
Segregation
Controller data logically separated, non production environments pseudonymised
Personnel
Right to work and reference checks, confidentiality undertakings, annual training
Assurance
Independent penetration test each year, findings remediated by severity
3.2
Pseudonymisation and minimisation
Development and testing use pseudonymised or synthetic data. Where live data is needed to investigate a fault, it is accessed in place, under an approved ticket, and never copied to a laptop or a local database.
4. Sub-processors
4.1
General authorisation, with notice
The Controller authorises the sub-processors listed below. The Processor may add or replace a sub-processor by giving the Controller 30 days written notice, and imposes on each of them data protection obligations no weaker than those in this agreement.
Sub-processor
Service
Location
Transfer safeguard
Northgate Cloud Ltd
Application hosting and backups
London, UK
Not applicable
Halcyon Archive Ltd
Offsite backup vaulting
Manchester, UK
Not applicable
Verity Mail Ltd
Transactional email
Dublin, Ireland
UK adequacy regulations
Clearpath Support Inc
Out of hours support desk
Toronto, Canada
UK adequacy regulations
Sigma Analytics LLC
Product analytics, pseudonymised
Oregon, USA
IDTA and UK Addendum
Sub-processor
Service
Location
Transfer safeguard
Northgate Cloud Ltd
Application hosting and backups
London, UK
Not applicable
Halcyon Archive Ltd
Offsite backup vaulting
Manchester, UK
Not applicable
Verity Mail Ltd
Transactional email
Dublin, Ireland
UK adequacy regulations
Clearpath Support Inc
Out of hours support desk
Toronto, Canada
UK adequacy regulations
Sigma Analytics LLC
Product analytics, pseudonymised
Oregon, USA
IDTA and UK Addendum
Sub-processor
Service
Location
Transfer safeguard
Northgate Cloud Ltd
Application hosting and backups
London, UK
Not applicable
Halcyon Archive Ltd
Offsite backup vaulting
Manchester, UK
Not applicable
Verity Mail Ltd
Transactional email
Dublin, Ireland
UK adequacy regulations
Clearpath Support Inc
Out of hours support desk
Toronto, Canada
UK adequacy regulations
Sigma Analytics LLC
Product analytics, pseudonymised
Oregon, USA
IDTA and UK Addendum
4.2
Objecting to a new sub-processor
The Controller may object within the 30 day notice period on reasonable data protection grounds. The parties then discuss the objection, and if it cannot be resolved the Controller may terminate the affected part of the services without penalty and with a refund of fees paid in advance.
4.3
The Processor stays responsible
The Processor remains fully liable to the Controller for the performance of each sub-processor’s data protection obligations, and cannot answer a claim by pointing at one of them.
5. International transfers
5.1
Transfers outside the United Kingdom
Personal data is stored in the United Kingdom. It is transferred outside the UK only to the sub-processors in clause 4.1 and only where the transfer is covered by UK adequacy regulations or by the Information Commissioner’s international data transfer agreement, or by the UK Addendum to the European Commission standard contractual clauses.
5.2
If a safeguard stops working
If adequacy is withdrawn or a transfer mechanism is invalidated, the Processor tells the Controller within five working days, and either puts an alternative safeguard in place or stops the transfer and moves that processing into the United Kingdom.
6. Assisting the Controller
6.1
Requests from individuals
A request from an individual that reaches the Processor is forwarded to the Controller within two working days and is not answered by the Processor. The Processor then helps the Controller answer it within five working days, using the export, search and deletion tools in the platform.
6.2
Assessments and consultations
The Processor gives the Controller the information it reasonably needs for a data protection impact assessment and for any prior consultation with the Information Commissioner’s Office, including a description of the processing, the security measures and the transfer safeguards.
6.3
Personal data breaches
The Processor notifies the Controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting Controller data, with what is known, what is affected, what has been contained and who to contact. The 48 hours is deliberately shorter than the 72 the Controller has to report to the Information Commissioner’s Office, so that the Controller has time to decide.
The processor clock is not the regulator clock
A controller has 72 hours from becoming aware of a reportable breach to tell the Information Commissioner’s Office. A processor that takes 72 hours to tell the controller leaves it with none. That is the whole reason this agreement sets 48.
7. Audit
7.1
Information first, inspection second
The Processor makes available the information needed to show compliance with this agreement, including its latest penetration test summary and its security policies. The Controller may audit or appoint an auditor once in any 12 months on 20 working days written notice.
7.2
How an audit runs, and who pays
An audit takes place in business hours, does not disrupt the service, and does not give access to another customer’s data. The first audit in a 12 month period is at the Processor’s cost. A further audit in the same period, other than one following a breach, is charged at £1,200 a day.
8. Deletion and return
8.1
At the end of the services
Within 30 days of the end of the services the Processor provides a complete export of the personal data in a structured, commonly used format, and then deletes the data from live systems. It confirms the deletion in writing within 45 days.
8.2
Backups and legal holds
Backup copies are purged on their normal cycle and in any case within 90 days, and remain protected by this agreement until they are. The Processor may keep a copy where the law requires it, tells the Controller what it is keeping and why, and deletes it when the requirement ends.
9. Liability, term and general
9.1
Term
This agreement starts on 04/05/2027 and runs for as long as the Processor processes personal data for the Controller, whatever the services agreement says about its own term.
9.2
Liability
The liability caps in the services agreement apply to this agreement, except that neither party limits liability for a fine or compensation that arises from its own breach of the UK GDPR. Each party pays its own share of any liability under Article 82 in proportion to its responsibility.
9.3
Notices, precedence and law
Notices under this agreement go to dataprotection@merrowfield.example and to the Controller’s named contact. If this agreement and the services agreement conflict on a data protection matter, this agreement prevails. It is governed by the law of England and Wales.
Annex 1. Details of the processing
Subject matter
Hosted order management for the Controller’s retail business
Duration
The term of the services agreement, plus the 30 day deletion window
Nature and purpose
Storing, retrieving, transmitting, exporting and deleting order records
Types of personal data
Name, delivery and billing address, email, telephone, order history, payment card token
Special category data
None. The Controller does not upload special category or criminal offence data
Categories of data subject
The Controller’s retail customers, and its own staff who use the platform
Frequency of processing
Continuous, for as long as the platform is in use
Retention
Deleted 30 days after the end of the services, backups purged within 90 days
Subject matter
Hosted order management for the Controller’s retail business
Duration
The term of the services agreement, plus the 30 day deletion window
Nature and purpose
Storing, retrieving, transmitting, exporting and deleting order records
Types of personal data
Name, delivery and billing address, email, telephone, order history, payment card token
Special category data
None. The Controller does not upload special category or criminal offence data
Categories of data subject
The Controller’s retail customers, and its own staff who use the platform
Frequency of processing
Continuous, for as long as the platform is in use
Retention
Deleted 30 days after the end of the services, backups purged within 90 days
Subject matter
Hosted order management for the Controller’s retail business
Duration
The term of the services agreement, plus the 30 day deletion window
Nature and purpose
Storing, retrieving, transmitting, exporting and deleting order records
Types of personal data
Name, delivery and billing address, email, telephone, order history, payment card token
Special category data
None. The Controller does not upload special category or criminal offence data
Categories of data subject
The Controller’s retail customers, and its own staff who use the platform
Frequency of processing
Continuous, for as long as the platform is in use
Retention
Deleted 30 days after the end of the services, backups purged within 90 days
For Pellham & Co Limited, the Controller
Name
:
Position
:
Date
:
For Merrowfield Systems Limited, the Processor
Name
:
Position
:
Date
:

Section by section

What each section is for, so you can keep the ones you need and drop the rest.

Cover and contents
A contract cover naming the platform, then a contents list to the eleven parts.
Parties and background
Both company numbers, the services agreement behind it, and a stats strip of deadlines.
1. Roles and instructions
Controller and processor, documented instructions, unlawful instructions and Article 30 records.
2. Confidentiality and personnel
Who may see the data, written undertakings, training and the data protection contact.
3. Security of processing
A table of eight measures, plus pseudonymisation and access to live data for faults.
4. Sub-processors
General authorisation with 30 days notice, the list of five, objections and liability.
5. International transfers
Where data goes, the safeguards relied on, and what happens if one is invalidated.
6. Assisting the Controller
Data subject requests, impact assessments and the 48 hour breach notice.
7. Audit
Information first, inspection second, and who pays for a second audit in a year.
8. Deletion and return
The export and deletion timetable, backups, and any copy kept because the law requires it.
9. Liability, term and general
Term tied to the processing, liability for fines, notices and precedence.
Annex 1
The processing details: subject matter, duration, data types, data subjects and retention.

Clauses in this document

How to adapt this agreement

For a processor outside the UK, start with the transfer clauses rather than the security ones, and attach the international data transfer agreement or the UK Addendum as a schedule rather than referring to it. For special category data, change Annex 1 and add the extra safeguards that follow, because the current annex records none and an auditor will read that as a statement. For a controller to controller arrangement, this is the wrong document: sharing between two controllers needs a data sharing agreement, not a processing one.

Which law the terms follow

The agreement is governed by the law of England and Wales and is written to the UK GDPR and the Data Protection Act 2018. Transfers rely on UK adequacy regulations for Ireland and Canada, and on the Information Commissioner's international data transfer agreement with the UK Addendum for the United States. Dates are written day first, the audit charge is in pounds, and the regulator named throughout is the Information Commissioner's Office.

What makes this document work

The breach clock is set against the controller's own deadline

The processor notifies within 48 hours of becoming aware, and a callout explains why: the controller has 72 hours to report to the Information Commissioner's Office, and a processor that takes 72 leaves it with none. The number is derived from the obligation rather than guessed.

Five sub-processors, each with its transfer safeguard named

Two in the UK with no safeguard needed, Ireland and Canada under adequacy regulations, and a United States analytics provider under the international data transfer agreement and the UK Addendum. A controller can answer a customer's question from one table.

Annex 1 answers the questions Article 28 actually asks

Subject matter, duration, nature and purpose, the types of personal data down to the payment card token, special category data stated as none, the categories of data subject, the frequency and the retention period. That annex is what an auditor reads first.

Questions people ask

What is a data processing agreement?

A written contract between a controller and a processor setting out how personal data may be handled. Under the UK GDPR a controller may only use a processor under such a contract, and it has to cover the subject matter, duration, nature and purpose of the processing, the data and the data subjects, and the obligations of both parties.

What must a UK GDPR data processing agreement contain?

Documented instructions, confidentiality obligations on personnel, security measures, rules on engaging sub-processors, assistance with data subject rights and impact assessments, breach notification, deletion or return of the data at the end, and a right to audit. Annex 1 records the processing details themselves.

How quickly must a processor report a personal data breach?

The UK GDPR says without undue delay, and a controller then has 72 hours to report to the Information Commissioner's Office where the breach is reportable. This agreement fixes the processor's deadline at 48 hours so the controller keeps a day to assess and decide before its own clock runs out.

How are sub-processors handled?

By general authorisation with notice. The five current sub-processors are listed in the agreement, and the processor may add or replace one on 30 days written notice. The controller may object on reasonable data protection grounds, and if the objection cannot be resolved it may terminate the affected services without penalty.

What happens to the data when the agreement ends?

The processor provides a complete export in a structured, commonly used format within 30 days, deletes the live data and confirms the deletion in writing within 45 days. Backups are purged on their normal cycle and in any case within 90 days, and stay protected by the agreement until they are.

Build your own in about a minute

The button below opens the generator with this use case already described. Change the wording to match your own, generate, then edit anything you like.

Make my uk data processing agreement template with sub-processors

Other document examples

Want the steps in the builder? Read Create a document with AI, then Add a cover page to your document. For everything this generator can do, see the document maker.

Sources

Written and checked by the OneCraft team. Last checked .