Guides

What happens to your data when a supplier builds your software.

8 August 2026 · 5 min read

When a supplier builds or runs software for you, you remain the data controller and they act as your processor. UK GDPR requires a written data processing agreement covering purpose, security, sub-processors, breach notification and what happens to the data when the relationship ends.

You areThe controller
They areYour processor
RequiredA written agreement

01

The distinction that decides everything

You decide why and how personal data is used, which makes you the controller and puts the legal obligation on you. A supplier acting on your instructions is a processor. That remains true even when the supplier knows far more about the technology than you do.

It matters because the regulator will come to you, not to them. Which is precisely why the agreement between you needs to be written rather than assumed.

02

What the agreement must actually cover

01The subject matter, duration, nature and purpose of the processing, and the categories of data and people involved.
02A commitment to act only on your documented instructions.
03Security measures, described specifically enough to be meaningful.
04Whether sub-processors are used, who they are, and your right to object to changes.
05Assistance with data subject requests, so you can meet your one month deadline.
06Breach notification without undue delay, so you can meet yours.
07Deletion or return of the data at the end of the engagement, and evidence that it happened.

03

The practical arrangements that matter more than the paperwork

Systems should sit on your own provider accounts wherever possible, with the supplier given access rather than ownership. That single arrangement removes most of the ambiguity about what happens if the relationship ends badly.

Ask where the data physically sits, and whether any of it leaves the UK. If it does, there needs to be an appropriate transfer mechanism in place, and a supplier who cannot name theirs has not thought about it.

04

Questions worth asking before you sign

01Will you sign a data processing agreement, and can we see your standard one?
02Whose accounts will the systems run on?
03Which sub-processors will touch our data?
04Does any of it leave the UK, and under what mechanism?
05What is your breach notification commitment in hours?
06What happens to the data if we stop working together?

Common questions

Do we need a data processing agreement for a small project?

If any personal data is involved, yes. There is no size threshold in the legislation. It is also a short document for a small engagement, so the cost of doing it properly is low.

Who is liable if the supplier causes a breach?

As controller you carry the primary obligation to the regulator and to the individuals affected, which is why the agreement, the security measures and the breach notification commitment matter so much to you specifically.

Should the supplier host the system on their own accounts?

Prefer your own accounts with access granted to them. It removes ambiguity about ownership, makes an exit straightforward and means the data never depends on a relationship continuing.

Ask for our data processing agreement

We will send our standard one before you commit to anything, so you can see the terms rather than take them on trust.

Start a conversation