If you are asking what is a DPA UK GDPR terms require, here is the direct answer: a data processing agreement is the written contract you must put in place whenever one organisation (the processor) handles personal data on behalf of another (the controller). Under the UK GDPR, as supplemented by the Data Protection Act 2018, this is not optional. Article 28 of the UK GDPR requires the relationship between a controller and a processor to be governed by a contract that sets out specific mandatory terms: the subject matter and duration of the processing, its nature and purpose, the types of personal data and categories of data subject, and the obligations and rights of the controller. Without a compliant DPA, both parties are exposed to enforcement by the Information Commissioner's Office. This guide explains what a UK DPA is, what it must contain, and how 99 Data Rooms helps you share the personal data behind it safely. It is general information, not legal advice.
DPAs come up constantly for modern businesses. If you use a cloud provider, an email platform, a payroll bureau, an analytics tool or any supplier that touches your customers' or employees' data, you are almost certainly a controller relying on a processor, and a DPA should be in place. Getting it right is both a legal duty and a trust signal to the people whose data you hold.
Controller, processor and why the roles matter
Everything about a DPA flows from two roles defined in data protection law. The controller decides why and how personal data is processed: it sets the purposes and the means. The processor acts only on the controller's documented instructions, processing data on its behalf without deciding the purposes itself. A payroll company running your employees' salary data is a processor; you, the employer deciding to run payroll, are the controller.
The distinction matters because the law places different obligations on each. Controllers carry the primary accountability for lawful processing, for responding to data subject rights, and for the overall compliance picture. Processors have narrower but real duties, and under the UK GDPR they can be directly liable for certain failures. The DPA is the instrument that pins down which role each party plays and what each must do. The ICO publishes detailed guidance on the controller and processor relationship and on what contracts must contain (see Sources).
Sometimes both parties are separate controllers, or joint controllers, rather than controller and processor, and the correct contract differs. Diagnosing the relationship honestly is the first step, because a DPA drafted for the wrong relationship protects no one.
What a UK DPA must contain
Article 28 of the UK GDPR lists the mandatory terms, and a compliant DPA works through them. It must set out the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subject. Beyond those descriptive elements, it must bind the processor to specific commitments.
The processor must process personal data only on the controller's documented instructions. It must ensure that people authorised to process the data are under a duty of confidentiality. It must take appropriate technical and organisational security measures. It must not engage a sub-processor without the controller's authorisation, and must impose equivalent obligations on any sub-processor it does use. It must assist the controller in responding to data subjects exercising their rights, and in meeting the controller's own obligations around security, breach notification and impact assessments. It must, at the controller's choice, delete or return the personal data at the end of the service. And it must make available the information needed to demonstrate compliance and allow audits.
For special category data, such as health, biometric or other sensitive information, the stakes and the safeguards rise further, and our guide on sharing sensitive personal data under UK GDPR goes into that in detail. A DPA is also closely tied to where data physically sits: many controllers want assurance that processing happens in the UK or an adequate jurisdiction, which is why data residency is a common negotiating point in these agreements.
DPAs and document sharing: the practical overlap
A DPA is a document, but it is also a lens on how you actually move personal data around day to day. It is little use to sign a strict DPA and then email spreadsheets of customer records as attachments to anyone who asks. The obligations to keep data confidential, secure and under control apply to the mechanics of sharing, not just the contract on file. Our guide on UK GDPR and document sharing walks through how the two connect, and why the way you distribute a file is itself a processing activity that needs to be lawful and secure.
This is where many organisations have a gap. The contract is airtight; the workflow leaks. Personal data ends up in forwarded emails, shared drives with stale permissions, and downloads no one can retract. A DPA that promises "appropriate technical and organisational measures" is only credible if the tools you use to share the underlying data actually deliver control, access restriction and auditability.
How 99 Data Rooms handles the data behind your DPA
99 Data Rooms does not draft your DPA for you, and we are clear about that: a DPA is a bespoke contract that depends on your specific processing, and it belongs with a qualified adviser. What 99 Data Rooms does is give you a defensible way to share the personal data that a DPA governs, which is often the harder problem in practice.
The platform is UK-hosted in London with data resident in the UK, encrypted with AES-256 at rest and TLS 1.2 or higher in transit, and there are no third-party viewer trackers watching your documents. When you share a file containing personal data, you send a tracked, revocable link rather than an attachment, gate it behind a verified email and a one-time code so only the intended recipient opens it, and see page-by-page analytics that distinguish a raw visit from a verified viewer who passed the gate. If access should end, one click revokes the link, even mid-view. That directly supports the "appropriate technical and organisational measures" and access-control commitments a DPA requires, and you can read the detail on our security and compliance page.
Two honest caveats. First, SOC 2 and ISO certifications are held by our infrastructure providers, Supabase and Cloudflare, not by 99 Data Rooms itself. Second, a data processing agreement covering our own role as a processor is available on request. The wider platform is in beta and improving fast, but the controls that matter for handling personal data are already in place.
Share the data behind your DPA securely, for free
You can share files containing personal data as gated, tracked, revocable links inside 99 Data Rooms. The free tier is a real tier, not a trial: three rooms, twenty-five active links, forever, no card required. Start for free, set up a room, and move up only when you want unlimited links, NDA gating or watermarking. The platform is in beta and improving fast, but UK hosting, encryption, gating and one-click revocation are already there to back up the promises in your DPA.
Sources
- Controller and processor obligations, and the mandatory content of processing contracts: Information Commissioner's Office, UK GDPR guidance and resources, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
- Statutory framework supplementing the UK GDPR: Data Protection Act 2018, https://www.legislation.gov.uk/ukpga/2018/12/contents
What is a DPA under UK GDPR?
A data processing agreement is the written contract required by Article 28 of the UK GDPR whenever a processor handles personal data on behalf of a controller. It sets out mandatory terms covering the processing and binds the processor to specific security, confidentiality and assistance obligations (see Sources). This is general information, not legal advice.
Do I legally need a DPA?
If any supplier processes personal data on your behalf, yes. The UK GDPR requires the controller-processor relationship to be governed by a compliant contract. Operating without one exposes both parties to ICO enforcement (see Sources).
What must a UK DPA contain?
The subject matter, duration, nature and purpose of processing, the types of data and data subjects, plus processor commitments on documented instructions, confidentiality, security, sub-processors, assisting with data subject rights, deletion or return of data, and allowing audits (see Sources).
Is a DPA the same as a privacy policy?
No. A privacy policy tells data subjects how you use their data. A DPA is a contract between a controller and a processor governing processing carried out on the controller's behalf. They serve different purposes and both may be needed.
Does 99 Data Rooms provide a DPA?
A DPA covering 99 Data Rooms' role as a processor is available on request. We do not draft your DPAs with third parties for you; that is a bespoke legal task. What we provide is a secure, UK-hosted, auditable way to share the personal data a DPA governs, detailed on our security page.