Pactora Clause Guide

Data Protection

The data protection clause sets out how personal data is handled under the contract, who is the data controller, who is the data processor, and what obligations each party owes under UK GDPR and the Data Protection Act 2018.

This guide was written by Sneha Ganapavarapu, a qualified lawyer with experience in commercial contracts across technology, IP, and energy sectors. All legal sources are linked. This is general legal information, not legal advice. Always consult a qualified solicitor before signing any contract that matters to your business.

Plain English

What it is

The data protection clause sets out how personal data is handled under the contract, who is the data controller, who is the data processor, and what obligations each party owes under UK GDPR and the Data Protection Act 2018.

For UK freelancers & small businesses

What reasonable looks like

  • Clear identification of who is controller and who is processor.

  • Processor obligations set out — process only on documented instructions, implement appropriate security measures, assist with subject access requests, notify of breaches within 72 hours, delete or return data on termination.

Watch out for

Red flags

No data protection clause at all in a contract involving personal data.

Clause that makes you responsible as controller when you are clearly acting as processor.

No breach notification obligation.

No deletion or return of data on termination.

England & Wales

Market standard UK position

UK GDPR compliant processor terms.

Clear controller/processor distinction.

72-hour breach notification.

Data deletion or return on termination.

Other jurisdictions

How this differs outside England & Wales

The guide above reflects England & Wales law and market practice. If your contract is governed by another jurisdiction, the following differences may apply.

Germany (BDSG 2018 + GDPR)

The Federal Data Protection Act 2018 (BDSG) supplements the GDPR. The BfDI and 16 Landesdatenschutzbehörden are the supervisory authorities. Germany has stricter employee-data provisions under § 26 BDSG. Processing employee data for fraud detection requires a separate assessment. Technical and organisational measures must be documented in the contract (§ 64 BDSG).

France (Loi Informatique et Libertés + GDPR)

The CNIL is the French supervisory authority. Data breach notification must reach the CNIL within 72 hours. French DPA enforcement has focused heavily on international data transfers, particularly to the US. France has an optional formal notification regime for certain automated decision-making.

India (DPDP Act 2023)

The Digital Personal Data Protection Act 2023 is in force but most provisions await commencement orders. Until fully commenced, the IT (Reasonable Security Practices) Rules 2011 under the IT Act 2000 continue to govern sensitive personal data. The DPDP framework is consent-based with a "data principal" (data subject) and "data fiduciary" (controller).

Scotland

The UK GDPR and Data Protection Act 2018 apply in Scotland as in England & Wales. The ICO is the supervisory authority. No material differences in the data processing terms applicable to commercial B2B contracts.

Legal advice triggers

Ask your lawyer if…

The contract involves personal data and has no data protection clause.

You are being made controller when you are acting as processor.

References

Legal sources

Read more

Further reading

Ready to check your contract?

Upload your contract to Pactora and we will flag data protection issues instantly — alongside all other key clauses.

Upload a contract to Pactora

Templates

Download free contract templates

Need a starting-point contract? Browse our free downloadable templates — NDA, Services Agreement, SaaS Subscription, and Freelance Engagement Letter.

Browse templates

Further reading

Related clause guides

Limitation of Liability

A limitation of liability clause caps how much one party can owe the other if something goes wrong.

Indemnities

An indemnity is a promise by one party to compensate the other for specific losses, costs, or claims — even if those losses weren't caused by a breach of contract.

IP Ownership

The intellectual property ownership clause determines who owns the work product created under the contract.

Termination

The termination clause sets out the conditions under which either party can end the contract, how much notice is required, and what happens when the contract ends.

Dispute Resolution

The dispute resolution clause sets out the process parties must follow before and during a formal legal claim — including escalation steps, arbitration or court proceedings, and any time limits on bringing a claim.

Auto-Renewal

An auto-renewal clause rolls the contract over automatically at the end of its term unless one party actively opts out within a specific cancellation window.

Fee Increases

A fee increase clause lets the supplier raise their prices during the contract term, typically linked to an index such as CPI or at the supplier's discretion.

Payment Terms

Payment terms set out when invoices fall due, what happens if payment is late or disputed, and whether the supplier can suspend services over an unpaid bill.

Assignment and Change of Control

These clauses govern who you can end up contracting with if either business is sold or restructured, and whether a funding round or acquisition could trigger the other side's exit rights.

Governing Law

The governing law clause determines which country's laws interpret the contract and which courts have jurisdiction over disputes — which directly affects your cost of enforcement.

Confidentiality

The confidentiality clause (or NDA) sets out what information must be kept secret, how long that obligation lasts, and the limited circumstances in which disclosure is permitted.

We use essential cookies to keep you signed in. We would also like to use analytics cookies to understand how the product is used. You can decline without losing any functionality. Privacy policy