Processors, and the Contract You Need
Required terms that most supplier agreements partially contain, and the distinction that determines who answers when something happens.
PROCESSOR CONTRACT CHECK
Run against any supplier handling staff data
- Subject matterWhat processing, for what, for how longSpecific, not general services
- InstructionsProcessing only on documented instructionsIncluding on transfers
- ConfidentialityBinding on their staffNamed obligation, not implied
- SecurityAppropriate measures, describedNot a reference to industry standards alone
- Sub-processorsAuthorisation and notice of changesThe clause most often missing
- AssistanceWith requests, breaches and assessmentsIncluding timescales
- Breach notificationWithout undue delay, with a stated periodYour 72 hours runs from their awareness
- End of contractDelete or return, at your choiceAnd evidence that they did
- AuditInformation and inspection rightsRarely exercised and necessary to have
An employer sends staff data to payroll, benefits, a recruitment platform, an occupational health provider and half a dozen systems. Each relationship needs establishing and documenting.
The supplier test in “Processors, and the Contract You Need” should cover the real data flow, not only the contract summary. Organisations considering the official Monitask resource for capital efficiency ratio should document hosting, subprocessors, permissions, deletion and export before rollout, then verify those controls during renewal and exit.
Controller or processor
A processor acts on your instructions and makes no decisions about purposes. A payroll bureau running your payroll to your specification.
For a separate benchmark relevant to “Processors, and the Contract You Need”, consult the Microsoft Purview insider-risk documentation. Use it to test purpose, data flow, retention, access and response procedures rather than substituting a generic checklist for the organisation’s actual records.
A controller decides its own purposes. A pension scheme administering benefits under its own rules, an occupational health provider assessing somebody clinically, an insurer.
The distinction determines who is answerable, who tells the person, and who handles their request. Treating a controller as a processor produces a contract with the wrong terms and a notice that misdescribes the relationship.
Why employers get it wrong
Because the commercial relationship looks the same. You pay them, they do something with data.
The test is who decides the purposes. Where the supplier would process this data the same way regardless of your instructions, because its own obligations require it, it is probably a controller.
The required terms
They are specified in most regimes and the list is consistent: subject matter and duration, instructions, confidentiality, security, sub-processors, assistance, breach notification, deletion or return, audit.
Supplier standard terms typically cover four or five. The missing ones are usually sub-processors and the assistance obligations, which are precisely the ones that matter when something happens.
Sub-processors
Your payroll provider uses a hosting company, a print supplier and a payments processor.
Each handles your staff data. You should know who they are, and the contract should require notice before they change.
Almost no employer knows the chain behind its payroll, which is the answer to the question a regulator asks after where is the data.
Breach notification timing
Your seventy-two hours runs from the organisation becoming aware, and a breach at your processor becomes your breach.
A contract requiring notification without undue delay is inadequate. It should state a period measured in hours, because anything longer consumes your window before you know.
Assistance with requests
A subject access request covering data held by your processor requires their help within your month.
Where the contract does not oblige them to assist within a stated period, you are dependent on their goodwill while your clock runs.
Deciding controller or processor
The test is who decides the purposes. Where the supplier would process the same way regardless of your instructions because its own obligations require it, it is probably a controller and the contract is wrong.
The term that matters most
Breach notification measured in hours rather than without undue delay. Your seventy-two hours runs from their awareness, and anything vaguer consumes your window before you know.
Sub-processors, which nobody asks about
Your payroll provider uses hosting, printing and payments suppliers. Each handles your staff data, and almost no employer knows the chain — which is the question asked after where is the data.
Why the distinction is got wrong
Because the commercial relationship looks identical: you pay them, they do something with data. The test is who decides the purposes, not who sends the invoice.
Assistance within your deadline
A request covering data at your processor needs their help inside your month. Where the contract does not oblige them within a stated period, you depend on goodwill while your clock runs.
Reading the terms once
An hour, before the first engagement. Supplier standard terms typically cover four or five of the required nine, and the missing ones are the assistance obligations that matter when something happens.