For UK managed service providers

You are a processor for most of what you do. Almost no GDPR guide is written for that.

Managed service providers get asked to prove their data protection position more often than almost anyone, because they hold the keys to everything. But the standard advice assumes you decide why data is processed, and for your managed services you do not: the client does. That changes who is responsible for what, who tells whom about a breach, what your contracts have to say, and what you can honestly put on a questionnaire.

Why the role question comes first

A controller decides why and how personal data is processed. A processor does it on someone else's instructions. For your managed services the client decides, so you are the processor, and that is a materially lighter set of duties in some places and a heavier one in others.

Lighter: you do not need your own lawful basis for their data, you are not the one who answers their staff's subject access requests, and you are not the one who notifies the ICO about a breach in their systems.

Heavier: you cannot engage a sub-processor without their permission, you must be under a written contract that says specific things, you must notify them of a breach without undue delay, and you have to delete or return everything when the contract ends, which for a backup provider is a genuinely hard promise to keep.

And you are simultaneously a controller for your own business: your ticketing system, your staff, your marketing. Both are true at once. A record that describes only the managed services, or only your own business, will not survive the first serious question.

The questions that come up, in order

01
Do we need a DPA with every client?
Yes, wherever you process personal data on their behalf, and it is their obligation as much as yours: Article 28 says a controller may only use a processor under a written contract. In practice the MSP supplies it, because you have fifty clients and each of them has one of you. Having your own that you are happy with, rather than signing fifty different ones, is worth the afternoon it takes.
02
What has to be in it
The subject matter and duration, the nature and purpose, the types of data and categories of people, and the controller's obligations and rights. Then the operative clauses: you act only on documented instructions, your staff are under confidentiality, you keep appropriate security, sub-processors need permission and notification, you assist with data subject rights and with breach notification, you delete or return at the end, and you allow audits. Anything shorter is missing something the client's insurer will ask about.
03
Sub-processors, which for an MSP is a long list
Your RMM, your PSA and ticketing, your backup target, your SOC or SIEM provider, your documentation platform, your remote access tool, and the hyperscaler underneath several of them. Every one is a sub-processor when it touches client data, needs the client's permission in general terms, and needs a route by which you tell them before it changes. Publishing the list at a fixed address means doing that once rather than emailing fifty clients.
04
Your admin access is what they are really asking about
Standing domain admin, a shared break-glass account, credentials in a vault half the engineers can open. Questionnaires circle this in three or four different rows. What answers it well: named accounts rather than shared, multi-factor on every one, just-in-time or approval-gated elevation where you have it, logging that shows who used what, and an offboarding process that removes access the same day. Where you are not there yet, say what you do instead, because a plausible partial answer beats a yes that is disproved on the call.
05
Breach: who tells whom, and how fast
As a processor your duty is to the client, not to the ICO: notify the controller without undue delay once you are aware. Their 72 hours to the ICO starts when you tell them, which is why clients push for a number in the contract. Committing to 24 or 48 hours to the client is common and workable. Committing to 72 misunderstands whose clock it is.
06
When one client's incident touches others
The scenario nobody writes down until it happens: a compromise of your RMM or your credentials is not one client's breach, it is potentially all of them. Decide in advance who calls whom, in what order, and what you say before you know the scope. Having that written is also the answer to the question sophisticated clients ask about tenant isolation.
07
What the client's insurer and auditor ask for
A signed DPA, your sub-processor list, your security measures, your breach procedure, evidence of MFA and backups, and increasingly whether you hold Cyber Essentials. Cyber Essentials is the one genuinely worth having as an MSP: it is inexpensive, UK buyers recognise it, and the self-assessment covers most of what the questionnaires ask anyway.
08
Your own compliance, separately
Your ticketing system holds your clients' staff contact details, and that is you as a controller. So is your marketing list, your own staff data, and your website analytics. It needs its own record, its own privacy notice, and an ICO registration. It is the half MSPs most often skip, and the half a regulator would look at first, because it is where you are the one making the decisions.

Which role are you in? A service-by-service answer

What you doWhich role you are inWhat it obliges
Managing the client's servers, endpoints and networkProcessor. You act on their instructions and touch their data incidentally, not for your own purposes.Article 28: needs a written contract
Running their Microsoft 365 or Google Workspace tenantProcessor for their mailbox content. You are also introducing a sub-processor they need to know about.Article 28, plus sub-processor consent
Backup and disaster recoveryProcessor, and the highest-consequence one: you hold a complete copy of everything. Retention and deletion terms matter more here than anywhere else.Article 28, and your deletion obligation
Your RMM agent on their machinesProcessor, and your RMM vendor is a sub-processor. This is the entry clients most often find missing from a sub-processor list.Article 28(2): tell them before you change it
Security monitoring, SOC or SIEMProcessor, usually with a third party behind you. Logs contain personal data, and the retention period is rarely written down.Article 28, plus your own retention
Your ticketing system, holding their staff's contact detailsController. Those are your business contacts for your own purposes, and it is your privacy notice that covers them.Your own lawful basis
Marketing to prospects and clientsController, and PECR applies on top for email and calls.Your own lawful basis, and PECR
Your own staff recordsController. Obvious once stated, and routinely missing from the record because it does not feel like the business.Your own lawful basis
Reselling a SaaS product to the clientDepends entirely on the agreement you signed. Some make you a reseller of record and a controller; most make you neither and the client contracts directly. Read it before you answer a questionnaire about it.Only you can answer this: read the reseller agreement

Most MSPs are a processor for the managed services and a controller for their own business, at the same time, for the same client. That is normal. What causes trouble is a record and a contract that only describe one of the two.

What to do this month, in order

  1. Decide your role per service, using the table below. An hour, and it makes every later answer consistent.
  2. Get one DPA you are happy with and use it with every client, rather than signing whatever each one sends. If a client insists on theirs, read the sub-processor and audit clauses before signing.
  3. List your sub-processors, every tool that touches client data. It is longer than you think. Publish it at a fixed address so a change is one update rather than fifty emails.
  4. Write down your access model: named accounts, MFA, how elevation works, how offboarding removes it. This answers a quarter of every questionnaire you will ever receive.
  5. Put a number in your breach commitment to clients, and make sure your own detection can meet it.
  6. Do your own record, as controller, for the ticketing system, the marketing list and your staff.
  7. Consider Cyber Essentials. For a UK MSP it pays for itself in shortened questionnaires.

Your clients get asked too

This is the part of the MSP position that is commercially interesting rather than merely obligatory. You have dozens of small clients, and they are receiving the same supplier questionnaires and document requests you are, usually with less idea what to do about it. You are already the person they call.

Some MSPs answer those requests as a favour and absorb the cost. Some price it as a service line: an onboarding pack and an annual review per client, which is a straightforward margin on work you are partly doing anyway. If you want to do it properly, with your own branding on what the client sends out and your own domain on their published pages, that is what Business Plus is for, and there is a partner route as well: see partners.

Three things MSPs get wrong

  • Claiming to be a controller for the managed services. Usually said in good faith, in a questionnaire, and it commits you to duties that are not yours while implying you decide what happens to the client's data.
  • A sub-processor list that stops at the obvious ones. Azure and Microsoft 365 are on everyone's list. The RMM, the documentation tool and the remote access utility are the ones that go missing, and they are the ones with the deepest access.
  • No plan for the multi-client incident. Every MSP has thought about a client being compromised. Fewer have written down what happens when the compromise is yours and it reaches all of them.

Pricing

Everything above is work you can do yourself, and this page is the guide to it. If you would rather not: Rowpa builds the record across both halves, your managed services as processor and your own business as controller, holds the MSP stack in a vendor library with source links and review signals, publishes the sub-processor list with change notifications, and turns it into the pack or the questionnaire answers a client's auditor asks for. Free to build and read the whole record. £79 once for a Questionnaire Pass, £39 once for a pack, or Business £79/mo for unlimited packs and twelve questionnaires a year, which is where an MSP with a dozen enterprise-facing clients lands. Business Plus £159/mo adds your own domain and branding if you are doing this for clients too. All prices ex VAT.

Start free See all plans

Common questions

Are we a controller or a processor?
Both, at once. Processor for the managed services, because the client decides why their data is processed. Controller for your own business: ticketing, marketing, staff, your website. The table above splits it service by service, and getting it right is what makes every questionnaire answer consistent.
Do we need a DPA with every client?
Wherever you process personal data on their behalf, yes, and it is their legal obligation as much as your commercial one. Supply your own rather than signing fifty variants. Where a client insists on theirs, read the sub-processor and audit clauses first: those two create the work later.
A client wants unlimited audit rights. Is that normal?
It is a common opening position and it is negotiable. Article 28 requires you to allow audits and contribute to them, not to accept an unbounded right at any time at your cost. Reasonable notice, working hours, once a year absent an incident, and a right to satisfy the request with an existing report or certification: all standard, and all worth asking for.
Do we have to tell clients before we change our RMM?
Yes, if they are on general written authorisation for sub-processors, which is the usual arrangement: you tell them of intended changes and they have the opportunity to object. Publishing the list with change notification is the low-effort way to meet that across a whole client base.
Our client had a breach. Do we notify the ICO?
Not as their processor. You notify them, without undue delay, and their clock to the ICO starts from that. You assist with the assessment and the notification. If the breach is in your own systems and concerns data you control, that is a different situation and yours to report.
Do we need Cyber Essentials?
It is not legally required. For a UK MSP it is usually worth it anyway: it is cheap, UK buyers and public sector frameworks recognise it, and the self-assessment covers most of what supplier questionnaires ask about MFA, patching, access control and malware protection. It is the best value credibility item for this segment.
Can we resell this to our clients?
You can do the work for them, and many MSPs price it as a service line. Business Plus gives you your own domain on published pages, your logo and colours on what goes out, and your own footer line in place of ours. The Trust Center keeps its Rowpa review badge, which shows the page was generated from a record. If you want a referral or reseller arrangement rather than buying for yourself, that is what the partners page is for.
Where does our documentation platform sit?
It is a sub-processor, it holds some of the most sensitive material you have, network diagrams, credentials, client contacts, and it is the one most often missing from a sub-processor list. It also deserves a hard look at its own access model, because it is the single document that would most help an attacker.

Further reading

The next client audit should take an hour.

Build your whole record free, no card. Pay only when you send something.

Start free