What Is a Data Processing Agreement (DPA)? A Guide for UK Employers Using Time Tracking Software
30 July 2026·7 min read
A Data Processing Agreement is the contract GDPR requires between you (the employer deciding why and how personal data is processed) and your SaaS vendor (the company handling that data on your behalf). If you use face recognition time tracking, you need one before a single employee clocks in — and without it, you are already in breach.
A Data Processing Agreement (DPA) is a contract required by GDPR (Article 28) between a data controller — you, the business deciding why and how personal data gets processed — and a data processor — the SaaS vendor actually handling that data on your behalf. In the time and attendance world, that means vendors like Jibble, Beebole, Factorial, or PunchIn storing your employees' facial recognition templates and timesheets.
It is not optional paperwork. Under UK GDPR (and EU GDPR), the moment you hand employee personal data to a vendor without a DPA in place, you are technically in breach — regardless of how compliant the vendor's product claims to be.
What a DPA Actually Does
A proper Data Processing Agreement legally documents the processor's obligations. At minimum, it should cover:
Purpose limitation The processor will only handle the data for the purposes you specify — not repurpose it (for example, sell it, use it to train their own models, or share it with third parties) without your authorisation.
Security measures The processor must implement appropriate technical and organisational measures: encryption, access controls, segregated environments, and the other safeguards expected for the sensitivity of the data they hold.
Retention and deletion It sets out what happens to employee data when you stop using the tool or an employee leaves — including how long templates and timesheets are kept, and how deletion is carried out.
Breach notification The processor must notify you promptly if there is a data breach, so you can meet your own 72-hour breach-notification duty to the regulator (the ICO in the UK).
Sub-processors If the vendor uses another company — for example a cloud host — to process the data, the DPA governs how that is disclosed and controlled, and what standards those sub-processors must meet.
International data transfers Critical if the vendor's servers are not in the UK or EU. The DPA must specify the transfer mechanism (for example Standard Contractual Clauses) that makes the transfer lawful.
Assistance with rights and DPIAs The processor confirms it will assist you with data subject rights requests (access, deletion, rectification) and with Data Protection Impact Assessments where needed.
Why It Matters More When Biometric Data Is Involved
Biometric data used for unique identification is special category data under Article 9 of the UK GDPR — the same category as health records and ethnic origin. Face recognition time tracking falls squarely in that category: the point of the system is to uniquely identify who clocked in.
As the employer, you are the data controller. That means you carry legal liability if something goes wrong — a fine, a breach, or an employee complaint. The vendor is the processor; they act on your instructions. The DPA is the paperwork that:
- Shifts contractual accountability onto the vendor for their end of the processing
- Gives you evidence of due diligence if a regulator ever asks
- Makes clear what the vendor may and may not do with facial templates and attendance records
Without a DPA, you remain exposed for failures on the vendor's side as well as your own. With biometric data in play, that exposure is not theoretical.
For the broader compliance picture — lawful basis, DPIAs, privacy notices, and retention — see our guide on GDPR and biometric data compliance for UK employers.
What “Good” Looks Like in Practice
Any legitimate vendor will offer a DPA as a standard document you sign during onboarding — usually available on request, or included in their terms and admin settings. You should be able to read it without a specialist lawyer decoding every clause, and it should clearly state:
- That you are the controller and they are the processor
- The categories of data processed (including biometric templates if applicable)
- Security, retention, breach, sub-processor, and transfer terms
- How you instruct them (and how they refuse unlawful instructions)
If a vendor cannot produce a DPA, that is a red flag, not a minor gap. Walk away, or at least do not switch on biometric enrolment until one is in place and signed.
When comparing tools, treat the DPA the same way you treat pricing and features: ask for it early, read it, and keep a signed copy with your DPIA and Appropriate Policy Document.
How PunchIn Handles the DPA
PunchIn includes a clear, understandable Data Processing Agreement as part of signup. It forms part of our Terms & Conditions, is aligned with UK GDPR Article 28, and sets out our role as processor for the attendance and biometric data you control.
Each customer runs on segregated infrastructure. Biometric templates are used only to provide the service, never sold or reused for other purposes, and handled under the retention and deletion terms in our biometric data retention policy.
If you are evaluating face recognition time tracking and need the DPA before you enrol staff, you can review it when you create an account — or contact us at punch-in.co.uk with any questions before you start.
This article is for general informational purposes and does not constitute legal advice. If you are uncertain about your compliance obligations, consult a qualified data protection solicitor or a registered Data Protection Officer.
Sign up to get PunchIn's clear DPA with your account.