The commercial terms are agreed. The pricing is signed off. Then the customer's procurement team sends over their own Data Processing Agreement (DPA).

It is 20 pages long. It is apparently non-negotiable. And sales want it signed by Friday.

For a scaling software as a service (SaaS) business, this is where a lot of uncapped risk gets in through the back door. The main contract may have a sensible liability cap. The DPA quietly sits outside it.

Why customers send their own

Under the UK General Data Protection Regulation (UK GDPR), when you process personal data on a customer's behalf, you are acting as their processor. The law requires a written contract covering certain minimum terms.

Larger customers have their own templates, written to protect them. That is reasonable. But those templates are usually drafted for every type of supplier they use, not for a SaaS platform serving hundreds of customers on shared infrastructure.

Terms that work for a single outsourced service provider can be unworkable, or expensive, for you.

1. Liability outside the cap

This is the most common problem. The DPA includes an indemnity for any breach of data protection obligations, and states that it applies regardless of any limitation of liability elsewhere.

That can turn a sensibly capped contract into unlimited exposure. Data incidents are one of the most likely sources of a large claim, so this is exactly where a cap matters most.

A common middle ground is a separate, higher cap for data protection claims, often called a super cap, rather than unlimited liability.

2. Breach notification deadlines

Controllers must report certain personal data breaches to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of them. Customers often push that pressure down to you with a 24-hour notification window, or shorter.

You need time to understand what has happened before you can report anything useful. Notification without undue delay, sometimes with a long-stop such as 48 hours, is a more workable position. Whatever you agree, make sure your incident response process can actually meet it.

3. Sub-processor approval

Your platform runs on third parties: cloud hosting, email delivery, analytics, support tools. These are your sub-processors.

Some customer DPAs require specific prior consent before you add or change one. On a shared platform, you cannot run a separate supplier stack for each customer. A general authorisation, with advance notice and a right to object, is the usual model for SaaS.

4. Audit rights

Unrestricted on-site audits, at any time and at your cost, do not scale across a customer base. Push for audits that rely first on your existing certifications and reports, with on-site audits limited in frequency, on reasonable notice and at the customer's cost unless a material breach is found.

5. International transfers

If personal data leaves the UK, for example to an overseas hosting region, support team or sub-processor, the transfer needs a lawful mechanism. Some customer DPAs prohibit any transfer outside the UK outright, which may not match how your product actually runs.

Check where the data actually goes before you sign a promise about where it stays.

6. Security schedules you cannot meet

Many DPAs attach a detailed security schedule. Some requirements will be standard. Others may demand specific certifications, encryption standards or testing frequencies you do not currently have.

Signing up to controls you do not operate puts you in breach on day one.

Have your own DPA ready

The strongest position is to offer your own DPA first, drafted around how your platform really works. Many enterprise customers will accept a well-drafted supplier DPA for standardised SaaS, because it saves their legal team time.

Where they insist on their template, you at least have a clear fallback for each key clause, and your sales team knows what can and cannot be conceded.

Keep your supplier terms aligned

Whatever you promise customers, you need to be able to pass down to your own suppliers. If you agree 24-hour breach notification but your hosting provider only commits to 72 hours, the gap is yours.

The commercial takeaway<.br>
The DPA is not a compliance formality. For a SaaS business, it is often where the largest uncapped exposure in the whole deal sits.

A standard DPA and a clear negotiation playbook let your sales team close faster, with fewer escalations and less risk.

If enterprise DPAs are slowing your deals or getting signed without review, book a free 20-minute call with our team.

Book a free 20min Chat

Feel free to ask for details, don't save any questions!

Our Office

Business Hours

  • Monday - Friday - 9am to 5pm

Get in Touch

Ethiqs is committed to providing our clients with accessible, transparent and affordable legal services and this starts all the way from the initial consultation.