Data Processing Agreement (DPA)
Last updated: June 2026
This Data Processing Agreement ("DPA") forms part of the agreement between The IT Workshop ("Processor") and the client ("Controller") and applies where The IT Workshop processes personal data on behalf of the client in the course of providing IT services.
This DPA is intended to comply with the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and where applicable, the EU General Data Protection Regulation (EU GDPR 2016/679).
1. Definitions
Personal Data means any information relating to an identified or identifiable natural person, as defined under UK GDPR / EU GDPR.
Processing means any operation performed on personal data, including access, storage, retrieval, or deletion.
Controller means the client who determines the purposes and means of processing personal data.
Processor means The IT Workshop, acting on the instructions of the Controller.
2. Scope of Processing
The IT Workshop will only process personal data to the extent necessary to deliver the agreed IT services. The types of personal data processed may include:
- Employee names and contact details
- Business email addresses
- System login credentials (handled securely and never stored in plain text)
- Device and network configuration data
Processing will occur for the duration of the service engagement and will cease upon termination, unless retention is required by law.
3. Processor Obligations
The IT Workshop agrees to:
- Process personal data only on documented instructions from the Controller
- Ensure that all personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures to protect personal data
- Not engage sub-processors without prior written consent from the Controller
- Assist the Controller in responding to data subject rights requests (access, erasure, rectification, etc.)
- Notify the Controller without undue delay upon becoming aware of a personal data breach
- Delete or return all personal data upon termination of services, at the Controller's choice
- Make available all information necessary to demonstrate compliance with this DPA
4. Security Measures
The IT Workshop implements the following security measures as a minimum standard:
- Encrypted remote access tools (e.g. end-to-end encrypted remote desktop sessions)
- Multi-factor authentication on all internal systems
- No storage of client credentials beyond the duration of the service session
- Regular review of access controls and data handling procedures
5. International Transfers
The IT Workshop will not transfer personal data outside the UK or EEA without ensuring appropriate safeguards are in place, in accordance with UK GDPR Chapter V and EU GDPR Chapter V.
For EU-based clients (including those based in Germany): as the UK is now a third country under EU GDPR, transfers of personal data from the EU to The IT Workshop in the UK are subject to appropriate safeguards. The IT Workshop is prepared to enter into EU Standard Contractual Clauses (SCCs) where required. Please contact us to discuss your specific requirements.
For UK-based clients transferring data internationally: The IT Workshop complies with the UK International Data Transfer Agreement (IDTA) framework where applicable.
6. Supervisory Authority
For UK-based clients, the relevant supervisory authority is the Information Commissioner’s Office (ICO).
For EU-based clients, including those based in Germany, the relevant supervisory authority is the competent data protection authority in your member state. For businesses based in Berlin, this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI). This DPA can be adapted to reference the applicable EU supervisory authority upon request.
7. Sub-Processors
Where The IT Workshop engages third-party sub-processors (e.g. remote access software providers, cloud storage), it will ensure those sub-processors are bound by equivalent data protection obligations. A list of current sub-processors is available upon request.
8. Data Breach Notification
In the event of a personal data breach affecting client data, The IT Workshop will notify the Controller within 72 hours of becoming aware, providing sufficient detail to allow the Controller to meet their own regulatory obligations.
9. Governing Law
This DPA is governed by the laws of England and Wales. For EU-based clients, it is also subject to applicable EU GDPR requirements.
10. EU Clients — Additional Note
For clients based in the EU, including Germany, this DPA can be adapted to reference the applicable EU supervisory authority and include Standard Contractual Clauses (SCCs) for international data transfers. A German-language version is available upon request. Please contact us at support@theitworkshop.uk to discuss your specific requirements.
11. Contact
For any questions regarding this DPA or to request a signed copy, please contact us at support@theitworkshop.uk or via our Get a Quote page.