UK GDPR: controller, processor and the Article 28 contract
Under UK GDPR, the organisation that decides why and how personal data is used is the controller, and a business that handles the data on its behalf is a processor (ICO (opens in a new tab)). On most website projects you are the controller and we are your processor for any personal data we can see, such as form entries, orders or CRM contacts.
Article 28 requires a written contract with set terms (ICO (opens in a new tab)). On request, Xsofty signs a data processing agreement (DPA) that includes those terms. In short, the processor:
- acts only on your documented instructions;
- keeps the data confidential and secure;
- uses sub-processors only with your authorisation;
- helps with rights requests, breaches and impact assessments;
- deletes or returns the data at the end, as you choose;
- gives you the information needed to show compliance, and allows audits.
The ICO says this contracts guidance is under review after the Data (Use and Access) Act, so check the linked page for changes (ICO (opens in a new tab)).





