Where a supplier processes personal data on an organisation's behalf, the relationship needs appropriate contractual terms. Establish the roles for the particular activity before using a processor template. A supplier may act differently for service delivery, billing and its own analytics.
Check the processing description, documented instructions, confidentiality, security, subprocessors, assistance and end-of-service handling. Connect the contract to the service's real settings and transfer arrangements. A signed schedule with empty fields does not explain what the supplier is authorised to do.
Identify the relationship behind the purchase
Start with the service being bought, not the supplier's description of itself. A payroll bureau may follow employer instructions for payroll calculations but make separate decisions about its own billing records. Record the roles for each activity. If both organisations determine purposes jointly, a standard processor schedule may address the wrong relationship. Establishing the roles first prevents later disputes about who can answer a worker's request or authorise a new use.
Describe the processing in terms that an operational manager can verify: the categories of people, types of information, activities, purpose and expected duration. Avoid leaving an annex marked to be agreed after the contract starts. A supplier should know whether it will receive bank details, sickness information or only employee numbers. The description also gives the security reviewer a realistic basis for judging the proposed controls.
Connect required terms to delivery arrangements
The ICO sets out contractual requirements covering instructions, confidentiality, security, subprocessors, assistance, deletion or return and information supporting audits. [1] Turn each requirement into a delivery question. Who receives an incident alert? How does the employer request a search? What happens if the supplier believes an instruction conflicts with data protection law? The agreement should be usable during a difficult event, not just complete at signature.
Check response arrangements against the controller's own deadlines. A supplier promise to answer all queries within thirty working days may be commercially convenient but unsuitable for an urgent breach or access request. Agree prioritisation, escalation contacts and any charges for assistance. Do not leave the business dependent on an unnamed sales representative who may have moved roles when help is needed.
Review the processing chain and locations
Request the current subprocessor list and the mechanism for proposed changes. Assess the relevant services, locations and safeguards rather than counting the number of suppliers. Remote support can matter even when the main hosting region is the UK. The guide to International transfers of personal data explains the separate transfer assessment; contractual processing terms and international transfer arrangements solve different parts of the problem.
Ask which settings remain the customer's responsibility. Public sharing links, administrator permissions and optional training or analytics uses can alter the practical risk. Record the agreed configuration alongside the contract version. Where a supplier cannot offer a requested control, decide whether another technical measure, a narrower dataset or a different service is needed before confidential records are uploaded.
Plan assistance and exit before signing
Run a short practical scenario: an employee requests their payroll history while the business is changing provider. Identify who searches the old platform, exports readable files and explains deletion from live storage and backups. Check whether contract expiry cuts off the access needed to complete this work. A right to obtain data is less useful if export takes weeks and the account closes the next morning.
Use Data processing agreement review to review the proposed agreement with the processing description, subprocessor information and security answers available. Highlight any supplier terms allowing independent reuse of customer data. Ask for a list of unresolved issues and operational actions as well as drafting changes. Keep the signed schedule with the main agreement so procurement, privacy and technical staff work from the same version throughout the relationship.
Translate audit rights into an evidence request
Before demanding an extensive inspection, identify the assurance the business actually needs. For example, a payroll customer may need evidence that leavers lose access, incident reports reach the named contact and backups follow the agreed arrangements. Ask which reports the supplier can provide, what they cover and which exceptions remain unresolved. A certificate's title alone does not answer those operational questions.
Agree how a concern moves from routine assurance to a deeper investigation. Record the contact, expected response and any practical access restrictions, especially where other customers' information shares the same environment. Review proposed charges and limitations against the contract's requirements. This preparation gives both parties a workable route when evidence reveals a problem, rather than leaving the customer with an impressive audit clause that nobody knows how to exercise.
Illustrative scenario
A payroll provider uses another service for document storage. The employer reviews the processing chain, incident reporting and access locations rather than assuming the payroll contract covers every downstream arrangement. The agreed schedule describes the employee information and the assistance needed for requests or incidents.
Preparation checklist
- Confirm controller and processor roles for each activity.
- Complete the data, purpose and duration description.
- Review subprocessors, security and overseas access.
- Agree assistance, audit information and exit handling.
Frequently asked questions
Is a confidentiality clause enough for a processor?
No. Confidentiality addresses only part of the relationship. The processing contract needs the applicable data protection terms and an accurate description of the authorised activities.
Must we accept every new subprocessor?
Check the agreed authorisation and change process against the applicable requirements. A notice should reach someone able to assess the proposed change and act within the relevant period.
Can a supplier be both processor and controller?
It may have different roles for different activities. Describe those activities separately and assess the actual decisions about purpose and means rather than relying on one blanket label.
What should we test before ending the service?
Test export completeness, readability, permissions and retrieval timing. Confirm assistance for outstanding requests and the agreed return or deletion arrangements before closing the administrator account.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction