DPA UK
Definition
DPA UK
DPA UK refers to the Data Protection Act 2018, the statute that implements and supplements the United Kingdom’s data protection regime alongside the UK GDPR. It was substantially amended in 2025, and outsourced processing sits squarely inside what it governs.
The Act and the UK GDPR work as a pair. Neither one stands alone, and a question about outsourcing usually needs both.
The statute runs to six parts, and most of them deal with law enforcement, the intelligence services and the regulator rather than commercial contracts.
The pairing matters commercially because the processor relationship is contractual by law — a controller cannot simply instruct a supplier and hope the arrangement holds.
The regime then changed. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and the Information Commissioner’s Office now confirms its data protection provisions are in force.
Key takeaways
- The Data Protection Act 2018 and the UK GDPR operate together rather than separately.
- Engaging a processor requires a written contract with prescribed content.
- The controller stays accountable for processing carried out on its behalf.
- The Data (Use and Access) Act 2025 amended the framework rather than replacing it.
How it works
The regime splits responsibility between controllers, who decide why and how personal data is processed, and processors, who act on instructions. Outsourcing almost always creates a processor, and that classification determines the paperwork.
A controller must use only processors that offer sufficient guarantees about their technical and organisational measures. That judgement has to be made before the data moves and revisited afterwards.
The contract carries prescribed terms rather than negotiable preferences. Subject matter, duration, purpose, data types, confidentiality, security, sub-processing, assistance, deletion and audit all have to appear.
| Contract term | Why buyers get it wrong |
|---|---|
| Sub-processor consent | Treated as a notification rather than a permission |
| Audit rights | Written in, never exercised, then unusable in an incident |
| Deletion at end of term | Silent on backups, so data outlives the contract |
| Assistance with data subject rights | No timescale, so the controller misses its own deadline |
| International transfers | Assumed covered by the main contract when they are not |
Sub-processing is where offshore delivery usually surfaces — a UK provider that fulfils work through an overseas affiliate has engaged a sub-processor, and the chain needs the same protections at every link.
Enforcement reaches both parties — the Commissioner can act against a processor directly, which is a change from the pre-2018 position.
Examples
Outsourced processing under this Act is routine rather than exotic, and the arrangements that cause trouble are rarely unusual ones. What follows are situations where the obligation moved but the paperwork did not.
A London insurer runs claims administration from Cebu through a UK-incorporated provider. The insurer is the controller, the UK entity is the processor, and the Philippine delivery arm is a sub-processor that must be named.
A retail bank uses a payroll bureau for its own staff data. The bank is the controller even though the data is about employees rather than customers, and the bureau’s contract carries the full processor terms.
A charity outsources donor mailings to an agency. The agency selects the mailing house itself, which creates a sub-processor the charity never approved and would struggle to describe.
A software vendor hosts client data and insists it is a controller. The classification is wrong where the client sets the purpose, and getting it wrong shifts obligations onto the party that never accepted them.
Related terms
UK data protection vocabulary overlaps with the European originals it was built from. The definitions below mark the boundaries that keep this regime distinct from its neighbours.
- General Data Protection Regulation (GDPR): the EU regulation the UK version was derived from.
- GDPR outsourcing: the processor contract question under the EU regime.
- ISO 27701: a privacy management certification providers use as evidence.
- PIPEDA outsourcing: the Canadian equivalent, built on accountability rather than prescribed contract terms.
- Compliance outsourcing: contracting the compliance function itself.
- Data centre outsourcing: where hosting decisions create transfer questions.
- Back office outsourcing: the delivery model that generates most processor relationships.
FAQ
Is the Act the same as the UK GDPR?
No. The UK GDPR sets the main rules and the Act supplements them, adds exemptions and covers law enforcement and intelligence processing.
Does a processor need its own contract with sub-processors?
Yes. The protections in the controller contract must be passed down, and the processor remains liable to the controller for the sub-processor’s failures.
Can we appoint an offshore processor?
Yes, subject to a lawful transfer mechanism and the usual contract terms. Location changes the transfer analysis, not the processor obligations.
What did the 2025 Act change?
It amended the existing framework across research, legitimate interests, automated decision making and the regulator’s structure. It did not replace the Data Protection Act 2018.
Who is liable if the processor causes a breach?
Both can be. The controller answers for its choice and instructions, and the processor answers for its own obligations under the regime.
Does a certificate satisfy the guarantees test?
It contributes evidence. The controller still has to form and record its own view about that specific provider.
Review Outsource Accelerator and start with the partners whose documentation you can actually read.







Independent




