Skip to content

Understanding DPIAs and Data Processing Agreements for Business Owners

Summarise with:
ChatGPT logo ChatGPT Perplexity logo Perplexity

On this page

A protection impact assessment examines how planned processing could affect people’s rights and freedoms. Businesses often shorten these names to DPA and DPIA.UK business owners may need both documents when introducing a service that uses customer or staff information. You act as a controller when you decide why and how to use personal data. A processor handles that data on your behalf. You must put compliant contractual terms in place before a processor starts work. You must also complete a DPIA before processing that is likely to create a high risk to individuals. The documents address different duties, so completing one does not replace the other. This article explains when controllers need DPAs and DPIAs, their differences, and how to use both when appointing suppliers.

Why Do DPAs and DPIAs Matter for Your Business

You must comply with data protection rules when your organisation processes personal data. Personal data means information about an identified or identifiable living person. Processing includes collecting, storing, using and deleting that information.

Your duties depend on the information you handle, your purposes and the risks to individuals. A payroll arrangement raises different practical questions from a service that tracks customer behaviour. Start with what your business actually plans to do.

If you fail to meet your duties, the regulator may take enforcement action, including fines. You may also face disruption and lose customers’ trust. Clear records and working safeguards help you explain and support your decisions.

Your data protection compliance documents should match your daily operations. A signed agreement cannot show whether staff follow access restrictions in practice.

When Do You Need a Data Processing Agreement

You must agree compliant processing terms whenever another organisation processes personal data on your behalf as a processor. Put the terms in place before the processing starts. Common examples include payroll providers, cloud storage suppliers and outsourced IT support.

Check the supplier’s role for the relevant activity. Access to your data does not, by itself, establish that the supplier acts as your processor. The actual arrangement determines each organisation’s responsibilities.

Before discussing contract wording, ask the supplier to describe how it will use the information. Compare that answer with your own instructions. Resolve any difference before treating the supplier as a processor for the activity.

What Your Agreement Must Cover

Your DPA must describe the subject matter, duration, nature and purpose of the processing. It must identify the types of personal data and the categories of people involved. It must also set out your rights and obligations as controller.

The agreement must require the processor to follow your documented instructions, unless the law requires otherwise. It must require confidentiality commitments from authorised staff and appropriate technical and organisational security measures.

The processor must help you respond to individuals exercising their data rights. The contract must also cover support with security, handling personal data breaches and DPIAs.

Include provisions for returning or deleting data at your choice when the service ends, unless the law requires storage. The processor must provide information demonstrating compliance and allow and contribute to audits. Check that the agreement describes how your business can obtain that information.

How to Control Further Outsourcing

A sub-processor is another processor your supplier appoints to handle the data. Your processor needs your prior written authorisation before appointing a sub-processor. You can give specific or general written authorisation.

With general authorisation, the processor must tell you about proposed additions or replacements. You must have an opportunity to object. The processor must impose equivalent data protection obligations on the sub-processor.

Ask how the supplier sends change notices and who in your business will assess them. An unread notice can leave your team unaware of changes to the processing arrangements.

Can You Negotiate a Supplier’s Standard DPA

You should review a supplier’s standard terms against your planned processing. A familiar supplier name does not establish that the agreement meets your needs. Some suppliers will negotiate, while others offer little scope for changes.

You can discuss additional commercial protections alongside the mandatory terms. For example, an indemnity is a promise to cover specified losses. Check which losses the promise covers and how any contractual liability limit affects it.

When negotiating software subscription contracts, consider how the data terms work with the wider agreement. Check the arrangements for recovering your data when you leave the service.

Continue reading this article below the form
Need legal advice?
Call 0808 196 8584 for urgent assistance.
Otherwise, complete this form, and we will contact you on the same business day.

When Must You Complete a DPIA

You must complete a DPIA before processing that is likely to result in a high risk to individuals’ rights and freedoms. Consider both the likelihood and seriousness of possible harm. The assessment focuses on people, rather than only your business’s financial exposure.

The Information Commissioner’s Office guidance on DPIA triggers identifies activities that require an assessment. Examples include large-scale processing of sensitive health information and systematic monitoring of public areas on a large scale.

Other activities can also trigger the requirement. Profiling means using personal data to evaluate or predict someone’s characteristics or behaviour. Extensive profiling and significant automated decisions need careful assessment.

Check the specific activity when handling children’s personal data or monitoring behaviour. These examples do not mean every use of children’s information automatically requires a DPIA.

What Should Your DPIA Examine

Describe what you plan to do with personal data and why. Explain whether the processing is necessary and proportionate to your purpose. Consider whether a less intrusive approach could achieve the same result.

Identify possible harm to people and assess its likelihood and severity. Then identify practical measures to reduce or remove those risks. Your assessment should explain how each measure addresses the relevant concern.

If you have a data protection officer, seek their advice and record it. Consider the views of affected people where appropriate. Ask your processor for the information you need to assess the planned service.

Describe the people whose information your project involves, including any groups who may face greater risks. Explain what could happen to those people if access controls fail or staff use information for an unexpected purpose. This gives your team a concrete problem to address.

For each proposed measure, explain who will carry it out and what evidence will show that it works. A statement that staff will protect data gives colleagues little direction. A description of access checks and the person responsible gives them a task they can complete.

When You Need to Involve the Regulator

You must consult the Information Commissioner’s Office before proceeding if high risk remains that you cannot sufficiently reduce. Do not treat sending the assessment as permission to start processing.

If your measures reduce the risk so it is no longer high, that consultation requirement does not apply. Record your reasoning and the safeguards supporting your conclusion.

How to Connect Your DPA and DPIA Before Launch

Use your DPIA findings to check whether the supplier’s service can deliver the protections your project needs. A useful way to do this is to trace each proposed safeguard to a contract term or operational task. Keep any unanswered questions open until the responsible person resolves them.

Test the Supplier’s Answers Against Your Plan

For example, imagine a retailer introducing a cloud platform to analyse customer behaviour. The retailer decides the purpose, and the provider processes information on its instructions. The retailer checks whether the planned analysis requires a DPIA before uploading customer information.

Suppose the assessment identifies unnecessary staff access as a risk. Ask the provider which access restrictions the platform supports. Then identify who will configure permissions and check that the settings work.

If the assessment depends on deleting information after a particular period, check the supplier’s actual deletion process. A general promise to protect data does not explain whether the service supports that safeguard. Keep the provider’s written explanation with the project records.

Ask who will supply information about the service if your team needs to investigate an incident. Establish a working contact route before launch. This practical preparation can help your business use the processor’s contractual assistance when needed.

Record the Launch Decision and Follow Up

Assign an owner to each action from the assessment. Record what remains unfinished and whether that affects your decision to proceed. Build the actions into the project plan so the people implementing the service can find them.

The Information Commissioner’s Office guidance on completing a DPIA recommends recording outcomes and integrating them into project plans. Keep the final assessment with the contract version that your business accepted.

After launch, check whether the service still operates as the assessment describes. Changes to the information you collect or the supplier’s service may affect your conclusions. Record the reason for any further review so colleagues can follow the decision later.

Use your supplier due diligence findings when assessing proposed changes. Due diligence means checking a supplier before relying on its services. Give advisers the project description and supplier documents together.

How Often Should You Review Your Documents

Review your documents when changes affect your processing arrangements or the risks to individuals.

Review pointWhen to actWhat to do
DPIAKeep it under review, particularly when a substantial change affects the level of risk.Check whether safeguards still work. Update the assessment and your conclusions where necessary.
Information you collectBefore introducing a change to the information your business collects.Tell the person responsible for privacy reviews. Provide enough detail for them to assess the proposal.
DPAWhen your supplier’s processing arrangements change.Check that the description, instructions and security measures still match the service. Ensure your team can find the applicable agreement.
Staff concernsWhen staff identify changes or concerns about suppliers handling personal data.Build a privacy culture within your organisation. Give staff a clear route for reporting concerns.
Review recordsWhenever you revise an assessment or reconsider a decision.Keep earlier versions and record changes. Retain supplier explanations and the information that informed your decisions.

Keep your documents aligned with how your business and suppliers actually handle personal data.

Key Takeaways

You need compliant contractual terms when a processor handles personal data on your behalf. You need a DPIA before processing that is likely to create a high risk to individuals. A project may require both documents. Use the assessment to identify working safeguards and check that your supplier can support them. Keep your records aligned with the service as it changes. Consult the regulator before proceeding if high risk remains that you cannot sufficiently reduce.

LegalVision provides ongoing legal support for businesses through our fixed-fee legal membership. Our experienced data, privacy and IT lawyers help businesses manage contracts, employment law, disputes, intellectual property, and more, with unlimited access to specialist lawyers for a fixed monthly fee. To learn more about LegalVision’s legal membership, call 0808 196 8584 or visit our membership page.

Frequently Asked Questions

Do small businesses need both a DPA and a DPIA?

Small businesses may need both, depending on their processing activities. You need a DPA when a processor handles personal data on your behalf. You need a DPIA before processing likely to create a high risk to individuals’ rights and freedoms.

Can you rely on a supplier’s standard DPA?

You can use a supplier’s standard DPA if it meets the applicable requirements and reflects your processing. Review the terms before accepting them. Check the security provisions, support obligations and arrangements for returning or deleting data.

Does a DPA replace a DPIA?

No. A DPA sets contractual duties for a processor handling personal data on your behalf. A DPIA assesses risks to individuals from planned processing. You must check whether each requirement applies to your project.

When should you update a DPIA?

Review and update your DPIA when a substantial change to processing affects the level of risk. Check whether your safeguards remain effective. Update the assessment and your conclusions to reflect the changes.

Register for our free webinars

How One Business Introduced AI Safely Across Its Workforce

Online
Your staff already uses AI. See how one business introduced an AI policy and governance framework that worked. Register for our free webinar.
Register Now

Ask a Corporate Lawyer: Structuring Your Business for Growth

Online
Learn how to set up your company structure and cap table before you raise. Register for our free webinar.
Register Now

Supplier Insolvency: What In-House Counsel Should Fix in Contracts Now

Online
Review termination, step-in and retention of title clauses to protect your business if a supplier fails. Register for our free webinar.
Register Now

Signing a Contract? Get These Terms Right First

Online
Learn what uncapped indemnities and data processing clauses really cost you before you sign. Register for our free webinar.
Register Now
See more webinars >

Aamna Mughal

Trainee Solicitor | View profile

Aamna is a trainee solicitor at LegalVision within the Corporate and Commercial team.

Qualifications:  Bachelor of Laws (Hons), Manchester Metropolitan University.

Read all articles by Aamna

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

LegalVision is an award-winning business law firm

  • Award

    2025 Future of Legal Services Innovation Finalist - Legal Innovation Awards

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2023 Economic Innovator of the Year Finalist - The Spectator

  • Award

    2023 Law Company of the Year Finalist - The Lawyer Awards