A business buying software or outsourced services should identify who controls personal-data use and who processes it on another party’s behalf. A legal-review enquiry should address the actual arrangement rather than just the contract title.

Define the legal instruction

The actual roles and data flows should determine contractual review. A label on a document does not establish the responsibilities of every party.

Professional fees, scope and other expenses

Ask for written scope and a clear fee basis: fixed, hourly, staged or another agreed arrangement. Identify applicable taxes, third-party expenses and excluded specialist work. Clarify what happens if facts change or the instruction expands, and who must authorise additional work before it begins.

Comparison item Question to resolve
Data roles and processing activities Are the roles correctly identified?
Subprocessor and transfer arrangements What supplier changes need approval or notice?
Security, assistance and exit obligations How can data be exported and deleted at exit?

Compare the deliverable and excluded stages line by line. Keep a record of the agreed estimate, revision process and approval for any additional expenses.

The decision that deserves the closest review

Provide the service agreement, processing schedule and supplier details. Ask about instructions, subprocessors, security assistance, incident support and data return or deletion. Review international transfer arrangements separately where relevant.

Prepare a brief the solicitor can price

Supply the complete documents, a short chronology where useful, the commercial objective and any urgent dates. Explain what outcome you need from the instruction. Clear organisation allows the adviser to distinguish initial scoping from a substantive review and later negotiation or dispute work.

Map the data service before commissioning the review

Explain the data handled, purposes, locations and the parties operating each part of the service. Supply the main commercial contract as well as the proposed data terms. This lets the adviser review the arrangement as a whole instead of interpret a processor label without the underlying facts.

Compare scope for reviewing roles, subcontracting, assistance and exit arrangements. Ask how supplier amendments and related schedules are included. Coordinate legal review with the operational team so obligations agreed on paper are understood by the people responsible for access, incident handling and service changes.

This legal guide concerns England and Wales. Confirm the jurisdiction and scope for the actual instruction.

A hypothetical example

A business buys a cloud platform with an outsourced support provider. It maps the parties and data flows before asking a solicitor to review the processing terms, avoiding an incomplete two-party description.

A mistake to avoid

Accepting a document labelled GDPR agreement without checking the actual services and data flows.

Agree how the instruction will be managed

Agree the contact person, expected updates and who can approve further work. Ask how the budget changes if the other side sends new documents, negotiations expand or proceedings become necessary. Keep advice, agreed terms and the executed documents organised so operational decisions use the final position rather than an earlier draft.

Questions before choosing

Does a signed agreement guarantee compliance?

It documents important obligations, but operational controls and the real processing activities must also be assessed.

Does a signed data agreement complete every privacy task?

Review the wider responsibilities and actual service operation. The agreement is one part of the arrangement, alongside appropriate processes and other applicable obligations.

Sources and further reading

Research date: 6 October 2026. Refer to the current linked guidance and written provider or adviser terms when making a decision.