GLOBAL BRIDGE LABS
← All posts/BPO & Operations

Data processing agreements for outsourcing (UK)

Data processing agreement outsourcing guide for UK firms: when you need a DPA, the ICO's required terms, sub-processors, breaches and what to check.

By Danushka Pinto, Co-founder / DirectorPublished 8 min read
Data processing agreement outsourcing: key takeaways infographic by Global Bridge Labs
Key takeaways from this article. Share it with the link and credit Global Bridge Labs.
On this page

Key takeaways

A data processing agreement for outsourcing is the written contract UK GDPR requires whenever a provider handles personal data on your behalf. It sets out what the provider may do with the data, how it protects it, which sub-processors it uses, how it helps you with rights and breaches, and what happens at the end.

  • Required whenever a BPO provider processes personal data you control.
  • The ICO lists minimum terms: instructions, confidentiality, security, sub-processors and more.
  • Offshore work also needs a transfer safeguard such as the IDTA.
  • Breach terms should require the provider to tell you without undue delay.
  • Check the DPA matches reality: where data sits, who accesses it, which tools.

Want to check a provider's DPA? Send it to us on WhatsApp and we will point out gaps against the ICO's list.

Chat on WhatsApp →

What is a data processing agreement?

A data processing agreement (DPA) is a contract between a controller, the organisation that decides why and how personal data is used, and a processor, an organisation that handles that data on the controller's behalf. UK GDPR requires one in writing whenever a processor is used.

In business process outsourcing (BPO), you are usually the controller and the provider is the processor. The DPA can be a standalone document or a schedule in the main contract.

When do you need a DPA?

You need a DPA whenever an outsourced team will access, store, use or delete personal data that you control. That covers almost all customer support, call answering, CRM work, data entry and finance admin, because names, emails, phone numbers and order details are personal data.

A provider that argues it does not need a DPA for this work is either misunderstanding its role or hoping you will not ask.

What must a DPA include?

The ICO sets out the minimum terms a controller-processor contract must contain, along with details of the processing itself.

  • Subject matter, duration, nature and purpose of the processing.
  • Types of personal data and categories of individuals.
  • Processing only on your documented instructions.
  • Confidentiality duties for people handling the data.
  • Appropriate technical and organisational security measures.
  • Conditions for engaging sub-processors.
  • Assistance with individuals' rights, breaches and impact assessments.
  • Deletion or return of data at the end, and audit rights.

How should sub-processors be handled?

A sub-processor is another company the provider uses to process your data, such as a cloud host or a workforce management tool. Under UK GDPR the provider needs your authorisation, either specific or general with notice of changes, and must flow down equivalent obligations. Ask for the current list and how you will be told of changes.

If the team works entirely inside your systems, the sub-processor list is usually short, which is another advantage of that model.

What should the DPA say about breaches?

The DPA should require the provider to notify you without undue delay after becoming aware of a personal data breach, with the information you need to assess it. Controllers must report notifiable breaches to the ICO within 72 hours of becoming aware of them, so any delay by the provider eats into that time.

Agree a named contact on each side and a practical timescale, such as within 24 hours of discovery.

What extra is needed for offshore teams?

If the provider's team is outside the UK in a country without adequacy regulations, the DPA is not enough on its own. You also need an appropriate transfer safeguard, such as the ICO's International Data Transfer Agreement or the UK Addendum, and a transfer risk assessment.

Want a managed team that arrives with a DPA and transfer safeguard ready to sign? Tell us about your process on WhatsApp and we will discuss your requirements.

Chat on WhatsApp →

What are the common DPA mistakes?

The common mistakes are signing a generic template that does not describe the actual processing, never reading the sub-processor list, having no practical breach contact, and forgetting the DPA when scope changes. Review it whenever you add a new process or channel.

Another mistake is treating a freelancer or virtual assistant as exempt. If they handle your customers' data, they are a processor too.

What does this look like in practice?

At Global Bridge Labs (GBL), every BPO engagement comes with a data processing agreement under UK GDPR, alongside the transfer safeguard needed for delivery from our Sri Lanka hub. Access is role-based and logged, and teams work inside the client's systems, which keeps the processing description short and accurate.

Checklist: review a DPA

Check each point before signing.

  • The processing description matches what the team will actually do.
  • All ICO-required terms are present.
  • The sub-processor list is attached and change notice is agreed.
  • Breach notification timescale and contacts are practical.
  • Security measures are specific, not generic.
  • A transfer safeguard is included if the team is offshore.
  • Data return and deletion at exit are clear.

Next step

If you are about to sign a DPA with an outsourcing provider, or need one for an existing arrangement, talk to us. 30 minutes, no pitch.

Message us on WhatsApp about your DPA, or book a 30-minute consultation.

Chat on WhatsApp →

Sources and further reading

Frequently asked questions

Is a DPA a legal requirement in the UK?

Yes. UK GDPR requires a written contract between a controller and any processor handling personal data on its behalf, with specific minimum terms set out by the ICO. Using an outsourcing provider without one breaches the law, even if nothing goes wrong.

Who writes the data processing agreement?

Either party can draft it, but it must contain the required terms and accurately describe the processing. Many providers offer their own DPA. Read it carefully, check it against the ICO's list and your actual set-up, and negotiate changes where needed.

What is the difference between a controller and a processor?

A controller decides why and how personal data is processed. A processor handles personal data on the controller's behalf and under its instructions. In most outsourcing, the client business is the controller and the provider is the processor.

Does a DPA cover international transfers?

Not on its own. If the processor's team is outside the UK in a country without adequacy regulations, you also need an appropriate safeguard such as the ICO's International Data Transfer Agreement or the UK Addendum, plus a transfer risk assessment.

Written by

Danushka Pinto
Danushka Pinto
Co-founder / Director

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.

Share this article

Reading is good.
Fixing is better.

30 minutes with our team and you'll leave knowing which of the three problems to fix first.

Book a 30-Minute Consultation →
Keep reading