Most small businesses using HubSpot assume the compliance question is simple: HubSpot handles the data, HubSpot handles the compliance. That assumption is wrong, and it's the kind of wrong that puts you on the hook.
HubSpot plays two distinct legal roles under UK GDPR. Understanding which role applies to which data is not optional. It changes what documents you need, what you're liable for, and what you have to record.
---
Under UK GDPR, every organisation involved in handling personal data is classified as either a controller or a processor. The ICO defines these clearly: a controller determines the purposes and means of processing; a processor handles data on behalf of a controller, following the controller's instructions.
With HubSpot, the split works like this.
HubSpot as your processor. When you store contact records, run email campaigns, track deals, or log call notes in HubSpot, you are the controller. You decide what data to collect, why you collect it, and how long you keep it. HubSpot processes that data on your instructions. As HubSpot's own Data Processing Agreement puts it, the DPA covers "the Processing of Customer Personal Data by us as a Processor on your behalf."
HubSpot as its own controller. The picture changes when HubSpot uses data for its own purposes. HubSpot's DPA explicitly states that it also covers "the Processing of Controller Personal Data by each party as a Controller in connection with our enrichment products and your use of the HubSpot tracking code." When a visitor lands on your website and HubSpot's tracking script fires, HubSpot collects behavioural data it uses for its own product analytics and improvement. For that data, HubSpot is a controller in its own right, not your processor.
So the answer to the question in the title is: both. The role depends on which data and which purpose.
UK GDPR is the retained version of the EU GDPR, incorporated into UK law via Section 3 of the European Union (Withdrawal) Act 2018. It applies to any organisation processing the personal data of people in the UK. The ICO is the supervisory authority. The rules are substantively the same as EU GDPR, but you answer to the ICO, not an EU data protection authority.
For the processor relationship with HubSpot, Article 28 of UK GDPR requires a written contract to be in place. No contract, no lawful processing. That contract is HubSpot's DPA.
---
The ICO has been explicit: UK GDPR applies to all organisations regardless of size, and being small is not an exemption from enforcement. That said, the ICO does apply proportionality. Fines for smaller organisations are calibrated to their financial position, and the ICO typically works through a resolution process before taking formal action against businesses that cooperate.
The more realistic risk for a small business is not a headline fine. It is a published reprimand. Since 2022, the ICO has published details of all reprimands it issues, naming the organisation and explaining what went wrong. For a small business, a named reprimand on the ICO register is commercially damaging in a way that can outweigh any financial penalty. Clients search that register.
The highest-risk areas for SMEs from an ICO enforcement perspective include failure to have appropriate processor contracts in place. That is exactly what a missing or unaccepted HubSpot DPA represents.
For reference, the ICO's maximum fines under UK GDPR are £17.5 million or 4% of annual global turnover (whichever is higher) for the most serious breaches. The lower tier, which covers administrative failures like missing processor contracts, carries a maximum of £8.7 million or 2% of global turnover. Those figures are the ceiling, not the floor. But they illustrate the seriousness the regulator attaches to these obligations.
---
Here is a concrete scenario that plays out more often than it should.
A small marketing agency signs up for HubSpot to manage client contacts and run email campaigns. They go through onboarding, configure their pipelines, and start importing contact lists. Nobody on the team accepts the HubSpot DPA. Nobody logs HubSpot in their Record of Processing Activities (ROPA). Nobody checks what sub-processors HubSpot uses.
Eighteen months later, a contact submits a Subject Access Request. The agency scrambles to respond. During that process, a data protection consultant reviews their setup and finds: no DPA with HubSpot, HubSpot not listed in the ROPA, no documentation of the data transfer to the US.
Three problems, each a separate compliance gap.
The DPA problem is the most immediate. HubSpot does not force the DPA on you at login. You have to navigate to it yourself. Many businesses have been using HubSpot for years without ever accepting it. The DPA is available, HubSpot has done their part, but the obligation to accept it is yours.
The ROPA problem follows directly. Article 30 of UK GDPR requires you to maintain a record of processing activities. HubSpot belongs in it. If you cannot show the ICO what data you hold, where it goes, and under what legal basis, you cannot demonstrate compliance.
The transfer problem is the third layer. HubSpot is a US company. Part of the processing happens in the US, which makes international data transfer a live issue under UK GDPR.
---
The DPA is available at legal.hubspot.com/dpa. To accept it inside your HubSpot account, go to Settings, then Account Defaults, then Legal Stuff, then Data Processing Agreement. Make sure the person accepting has authority to sign on behalf of the business. Save a PDF of the confirmation. This is your evidence that the Article 28 contract is in place.
For your CRM data (contacts, deals, emails, call notes), HubSpot is your processor. You are the controller. The DPA governs this relationship.
For HubSpot's tracking code and enrichment products, HubSpot acts as a controller for its own purposes. You should note this in your privacy policy and, if you use those features, consider what disclosure you make to website visitors. The HubSpot cookie banner helps, but you need to configure it correctly and ensure your privacy notice reflects what data is collected and by whom.
HubSpot uses two mechanisms for transferring personal data from the UK to the US. First, the UK Extension to the EU-US Data Privacy Framework: HubSpot is certified under this framework, and it covers UK-to-US transfers. Second, the UK Addendum to the Standard Contractual Clauses, which is the International Data Transfer Addendum (IDTA) issued by the ICO under section 119A of the Data Protection Act 2018. Both are incorporated into HubSpot's DPA automatically once you accept it.
You do not need to negotiate separate transfer documents. But you do need to record which transfer mechanism applies in your ROPA. For most small businesses using HubSpot for standard CRM and marketing, the DPF and SCCs/UK Addendum are sufficient. If you process sensitive categories of data through HubSpot (health information, for example), a Transfer Impact Assessment is advisable.
Your Record of Processing Activities needs an entry for HubSpot. At minimum, include:
HubSpot uses sub-processors, including Amazon Web Services and Google Cloud Platform for hosting. The full list is on HubSpot's legal pages. You do not need to list every sub-processor in your ROPA, but you should note that HubSpot uses sub-processors and reference where the current list is published. HubSpot will notify you at least 30 days before adding or changing a sub-processor if you subscribe to their notifications at legal.hubspot.com/subscribe-subprocessor-updates. Subscribe to that list. Sub-processors change.
If you use HubSpot's tracking code on your website, your privacy notice needs to disclose this. Visitors should know that a third-party tool is collecting behavioural data, what that data is used for, and who the third party is. HubSpot's dual role as controller for tracking data means this is not just a processor disclosure. It is a controller-to-controller disclosure that your privacy notice should reflect.
---
If you're not sure whether your business is covered, Rowpa generates your full ROPA in 15 minutes. Start free at rowpa.app
---
This post is for information only and does not constitute legal advice.