Skip to content

What Can Go Wrong If My Contract Omits Data Processing Terms?

Summary

  • Article 28 of the UK GDPR requires a written contract with mandatory data processing clauses whenever a controller engages a processor.
  • Omitting these terms breaches the UK GDPR and exposes your business to ICO enforcement action and fines.
  • Missing terms also leave security, breach handling and data subject rights undefined, which stalls negotiations and damages supplier trust.
  • This guide explains the risks of omitting data processing terms from contracts for supplier businesses in the United Kingdom.
  • LegalVision’s business lawyers specialise in advising clients on data processing terms and UK GDPR compliant contracts.

Tips for Businesses

Audit every contract where you handle personal data for a customer. Check each Article 28 requirement is present: documented instructions, confidentiality, security, sub-processor authorisation, assistance with data subject rights, deletion or return at termination, and audit rights. Add compliant terms to your standard template so new contracts start correct.

Summarise with:
ChatGPT logo ChatGPT Perplexity logo Perplexity

On this page

If your contract omits data processing terms, you breach Article 28 of the UK GDPR, and the Information Commissioner’s Office can take enforcement action against your business. Article 28 requires a written contract whenever a controller engages a processor to handle personal data. That contract must cover documented instructions, confidentiality, security measures, sub-processor rules, assistance with data subject rights, deletion or return of data, and audit rights. Without those terms, nobody has agreed who handles a data breach, who answers a subject access request, or who pays when something goes wrong. Controller customers increasingly check for these clauses during procurement, so a gap can stall or lose the deal. This article will explore the potential risks and consequences if your contracts omit data processing terms.

What are Data Processing Terms?

Data processing terms are an essential requirement under the UK GDPR, the primary legislation in the UK that dictates how organisations must handle personal data

Compliance with these laws is mandatory, and breaching these legal rules can lead to severe consequences, including heavy fines, enforcement action, and reputational damage. 

Ensuring that your contracts include appropriate data processing terms is critical to compliance. According to Article 28 of the UK GDPR, a data controller and a data processor must agree on specific mandatory terms. These terms should cover several obligations, including:

  • The processor must only handle personal data based on the controller’s instructions.
  • The processor must maintain confidentiality and implement appropriate security measures for personal data.
  • There must be rules governing the sharing of personal data with third-party sub-processors.
  • There must be provisions for addressing data subject rights, supporting the data controller, and managing personal data at the end of the contract.

These terms aim to ensure the protection and security of personal data shared between controllers and processors. 

Services agreements or separate data processing agreements can include such terms. Data processing terms are not only a legal requirement but also vital for setting out essential obligations and managing data protection risks. 

“In my experience, the businesses that get caught out are rarely the ones refusing to sign a data processing agreement. They are the ones whose standard services contract was written before they started handling customer data, and never revisited. That gap tends to surface at the worst possible moment, in the middle of a deal or a breach.”

Kieran Ram
Kieran Ram Associate, LegalVision

What Can Go Wrong Without Data Processing Terms in a Contract?

A supplier acting as a data processor must include data processing terms in its contracts. Omitting these terms can lead to significant problems, including the following:

Non-Compliance with Data Protection Laws

The UK GDPR requires that contracts between controllers and processors include specific terms. These terms should address processing activities, the nature and purpose of processing, the types of personal data, and the obligations and rights of both parties.

Failure to include these terms in a contract constitutes non-compliance with the UK GDPR.  It exposes your business to significant fines and penalties, potentially damaging your reputation and financial stability. 

What Enforcement Action Can Follow a Missing Data Processing Clause

The Information Commissioner’s Office has a range of tools when a contract lacks the mandatory terms. It can issue a reprimand, serve an enforcement notice requiring you to fix the contract, or impose a monetary penalty. Breaches of the Article 28 contract requirements sit at the standard maximum fine level, which is £8.7 million, or 2% of total worldwide annual turnover for an undertaking, whichever is higher.

Enforcement is not the only exposure. Processors carry direct obligations under the UK GDPR, so a processor can be fined or face a claim for damages in its own right, not only through the controller. A processor that decides the purposes and means of processing is treated as a controller for that processing, which brings a much wider set of duties. Your controller customer is exposed too, because it must only appoint processors that offer sufficient guarantees.

The commercial risk usually arrives first. A controller customer who spots the gap may pause the contract, demand an audit, or walk away. Building compliant terms into your standard data processing agreement removes that risk before it reaches a negotiation.

Key Statistics

  1. Only 15% of businesses check their suppliers: 15% of UK businesses formally reviewed the cyber security risks posed by their immediate suppliers in 2025/26, rising to 48% among large businesses.
  2. 17,431 personal data breaches reported: organisations reported 17,431 personal data breaches to the ICO in 2025/26, up from 12,412 the previous year.
  3. Fines up to £8.7 million or 2% of turnover: breaches of the Article 28 contract requirements fall under the standard maximum fine, which is £8.7 million, or 2% of total worldwide annual turnover for an undertaking, whichever is higher.

Sources

  • Department for Science, Innovation and Technology (GOV.UK), Cyber Security Breaches Survey 2025/2026, 2026
  • Information Commissioner’s Office, Annual Report and Financial Statements 2025/26, 2026
  • Information Commissioner’s Office, Data Protection Fining Guidance, 2025

Lack of Contract Clarity and Increased Risk of Data Breaches

With precise data processing terms, there will be clarity regarding who is responsible for data protection matters, such as data security, breach handling, and responding to data subject rights requests. This can be critical to ensuring that data protection issues, such as data breaches, are dealt with appropriately. 

This ambiguity can lead to inadequate data protection measures and an increased risk of data breaches. This can have severe legal, financial, and reputational consequences.

Front page of publication
GDPR Essentials Factsheet

This factsheet sets out how your business can become GDPR compliant.

Download Now

Lack of clarity over obligations also increases the likelihood of disputes over the responsibilities and liabilities between controllers and processors. Such disputes can be costly, time-consuming, and damaging customer to business relationships.

Negotiation and Reputation Issues

Savvy business controller customers will likely notice the absence of data processing clauses and question your commitment to data protection law compliance as a supplier. In my experience, the businesses that get caught out are rarely the ones refusing to sign a data processing agreement. They are the ones whose standard services contract was written before they started handling customer data, and never revisited. That gap tends to surface at the worst possible moment, in the middle of a deal or a breach.

This can lead to prolonged negotiations and back-and-forth with customers, delaying contract closures and potentially damaging your reputation as a reliable supplier. Customers may lose trust in your business, affecting future business relationships that rely on personal data security. 

Having robust and compliant data processing clauses in your contract from the outset will help avoid this risk. 

Including robust data processing terms in your contracts is not just a legal requirement and essential to ensuring compliance with the UK GDPR, but it is also vital for clarifying responsibilities, protecting data effectively, and maintaining a solid reputation as a trusted supplier, where data protection is often a key customer concern. 

Continue reading this article below the form
Need legal advice?
Call 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you on the same business day.

Navigating the complexities of data processing terms can be challenging. However, working with a data protection lawyer can provide invaluable clarity and protection for your business. A data protection lawyer can ensure your terms comply with the UK GDPR and avoid hefty fines.

This proactive approach can help a company navigate its data protection obligations effectively and safeguard itself against potential risks. You should seek legal advice if you require support with data processing terms as a supplier business. 

Key Statistics

  1. Only 15% of businesses check their suppliers: 15% of UK businesses formally reviewed the cyber security risks posed by their immediate suppliers in 2025/26, rising to 48% among large businesses.
  2. 17,431 personal data breaches reported: organisations reported 17,431 personal data breaches to the ICO in 2025/26, up from 12,412 the previous year.
  3. Fines up to £8.7 million or 2% of turnover: breaches of the Article 28 contract requirements fall under the standard maximum fine, which is £8.7 million, or 2% of total worldwide annual turnover for an undertaking, whichever is higher.

Sources

  • Department for Science, Innovation and Technology (GOV.UK), Cyber Security Breaches Survey 2025/2026, 2026
  • Information Commissioner’s Office, Annual Report and Financial Statements 2026
  • Information Commissioner’s Office, Data Protection Fining Guidance, 2025

Key Takeaways

Neglecting data processing terms in your contracts can lead to significant legal and reputational risks. Ensuring that your contracts include UK GDPR-compliant data processing terms is vital for compliance and adequate data protection. You should seek advice from a data protection lawyer on your contracts. A lawyer can help you meet compliance requirements and protect your business from risk as a processor. 

LegalVision’s experienced data, privacy, and IT lawyers can assist as part of our LegalVision membership if you need advice on data processing contracts. For a low monthly fee, you will have unlimited access to lawyers to answer your questions and draft and review your documents. Call us today on 0808 196 8584 or visit our membership page.

Frequently Asked Questions

What is a data processing agreement?

A data processing agreement is a contract between a data controller and a data processor. It sets out the mandatory terms the UK GDPR requires whenever personal data is shared, including how the processor may use the data and the security it must apply.

Am I a data controller or a data processor?

A controller decides the purposes and means of processing personal data. A processor handles personal data on the controller’s instructions, usually while supplying a service. Your role determines your obligations. A business can act as both, though not for the same processing activity.

Do I need the controller’s permission before using a sub-processor?

Yes. A processor needs the controller’s prior written authorisation before engaging a sub-processor. That authorisation can be specific or general, and the controller keeps the right to object to new appointments. The processor remains liable to the controller for the sub-processor’s compliance.

Can data processing terms sit inside a services agreement?

Yes. You can include data processing terms in a services agreement or in a separate data processing agreement. Either works, provided the terms meet every requirement in Article 28 of the UK GDPR. What matters is the content, not which document holds the clauses.

Register for our free webinars

When AI Is Misused: How One Business Responded Without Runaway Legal Fees

Online
How one business recovered its IP without incurring high legal costs after relying on an AI-drafted contract. Register for our free webinar.
Register Now

Ask A Lawyer: Terminations and Restructures After Fire and Rehire

Online
Fire and rehire rules change from January 2027. Join our free live Q&A webinar with an employment practice leader on managing terminations and restructures.
Register Now

Sponsoring Overseas Talent: What Your Business Needs to Know

Online
Learn what UK businesses need to know before sponsoring overseas workers. Register for our free webinar.
Register Now

Before You Sell Your Business: The Legal Steps That Make You Attractive To Buyers

Online
Get your business sale ready before buyers start due diligence. Register for our free webinar.
Register Now
See more webinars >

Kieran Ram

Associate | View profile

Kieran is an associate in LegalVision’s Corporate and Commercial team. He has completed a Law Degree, the Legal Practice Course and a Masters in Sports Law, specialising in Football Law.

Qualifications: Bachelor of Laws (Hons), Master of Laws, Legal Practice Course.

Read all articles by Kieran

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

LegalVision is an award-winning business law firm

  • Award

    2025 Future of Legal Services Innovation Finalist - Legal Innovation Awards

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2023 Economic Innovator of the Year Finalist - The Spectator

  • Award

    2023 Law Company of the Year Finalist - The Lawyer Awards