Data Processing Agreement

Draft template — last updated 2026-08-18

When this actually applies to you

This template is relevant if you (as a bookkeeper or accountant) upload clients' bank statements into your own Ledger instance. In that relationship, your client is typically the data controller for their own financial data, and you — running the software that processes it on their behalf — act as the data processor. This document is a starting point for formalizing that relationship in writing, which UK GDPR generally expects when a controller uses a processor.

1. Parties

Between [Controller name — your client] ("the Controller") and [Processor name — you/your business] ("the Processor"), in respect of personal data processed using the Ledger application.

2. Subject matter and duration

The Processor processes bank statement data (transaction records, account holder details) on behalf of the Controller for the purpose of bookkeeping and financial record-keeping, for the duration of the engagement between the parties, as set out in [reference your underlying service agreement/engagement letter here].

3. Nature and purpose of processing

Extraction of transaction data from bank statement PDFs/photos, categorization, analysis (cash flow, reconciliation), and export of that data for accounting purposes.

4. Categories of data subjects and data

Data subjects: the Controller's business and any individuals named in transaction descriptions (e.g. payees, payers). Data: transaction records, account holder name, address, sort code, account number, IBAN, and the original statement document.

5. Sub-processors

Anthropic (Claude AI) is used as a sub-processor to perform the actual data extraction from statement content. The Controller consents to this sub-processing by entering into this agreement. [Placeholder: add process for notifying the Controller of any future change of sub-processor.]

6. Processor obligations

  • Process data only on the Controller's documented instructions
  • Ensure appropriate technical and organisational security measures (see the Privacy Policy for what's actually implemented — encryption at rest, HTTPS, hashed credentials)
  • Assist the Controller in responding to data subject rights requests
  • Notify the Controller without undue delay of any personal data breach
  • Delete or return all personal data at the end of the engagement, at the Controller's choice [placeholder — confirm your actual offboarding process]

7. Audit rights

[Placeholder: this section typically gives the Controller a right to request evidence of compliance or to audit the Processor's practices — worth defining what's realistic to offer for a self-hosted, small-operator setup before committing to specific wording.]

8. Liability

[Placeholder: needs solicitor input — liability allocation between controller and processor for data protection failures has real legal weight and shouldn't be drafted without review.]