A data processing agreement is the contract UK GDPR Article 28 requires whenever a controller uses a processor, and for HR teams adopting Microsoft Dynamics 365 HR it's the document that decides whether employee data is lawfully handled. It must define the processing arrangement and include the mandatory safeguards that control how the processor operates.
You're choosing an implementation partner, configuring Dynamics 365 HR, and preparing to move recruitment, payroll-related information, absence records and performance documentation into Dataverse. Then legal asks the question that stops many projects in their tracks: “Where's the DPA?” A generic supplier agreement won't answer it properly. It may cover fees, service levels and liability, but it often says little about documented instructions, sub-processors, data subject rights or deletion at the end of the relationship.
That gap matters. An HR deployment can involve names, addresses, bank details, Right to Work documents, performance notes, Teams conversations, Outlook approvals, SharePoint files and Power BI reports. Your DPA needs to describe the arrangement, not an idealised version of the software architecture.
What a Data Processing Agreement Actually Is
The document behind a lawful HR deployment
A data processing agreement is a contract between a data controller and a data processor. The controller decides why and how personal data is processed. The processor handles that data on the controller's behalf and must follow the controller's documented instructions.
For a UK employer using Microsoft Dynamics 365 HR, the employer will generally determine the purposes of processing employee and candidate information. A technology provider, application provider or implementation partner may process that information while configuring, supporting or operating the solution. The contract needs to set out who does what, which data is involved and the boundaries around every processing activity.
Under UK GDPR Article 28, the arrangement must be governed by a contract or other legal act. The contract must state the subject matter and duration of processing, the nature and purpose of processing, the type of personal data, the categories of data subjects, and the controller's obligations and rights. The UK Government guidance on engaging a data processor confirms that this is a required part of the controller-processor relationship.

A DPA isn't just a privacy version of a master services agreement. The services agreement might say that the supplier will provide implementation support. The DPA should say whether that support includes access to employee records, how access is authorised, what instructions apply, whether support staff can view live data, and what happens to exported files after the work is complete.
What the DPA must make operational
A strong DPA turns legal duties into actions that HR and IT can verify:
- Scope: It identifies the Dynamics 365 HR environment, connected services and processing activities covered.
- Purpose: It limits use to agreed activities such as recruitment, onboarding, employee administration, absence management or reporting.
- Control: It records the customer's instructions and prevents the processor from repurposing employee data.
- Safeguards: It sets expectations for confidentiality, security, access management and oversight.
- Exit: It explains how data will be returned or deleted when the service ends.
Practical rule: If a clause can't be mapped to a person, system, approval or procedure, it probably isn't operational enough.
By the end of a proper review, an HR director should be able to identify every party that can touch employee data, while the IT lead should be able to trace those permissions through Microsoft 365, Dataverse and connected applications. That's the standard to insist on before signing.
The Legal Basis Under UK GDPR and the ICO's Mandatory Elements
The legal architecture comes from the retained Article 28 framework. A controller must use processors that provide sufficient guarantees for appropriate technical and organisational measures. A processor also needs prior written authorisation before appointing another processor. The retained UK GDPR Article 28 text sets out that framework.
The ICO identifies eight mandatory contract elements or safeguards. Each one should appear in the DPA and should make sense in the Dynamics 365 HR design.
The eight safeguards in a working HR environment
-
Documented instructions. The processor must process personal data only on the controller's documented instructions. For Dynamics 365 HR, instructions might cover which Dataverse tables are configured, who can access candidate records, whether production data can be copied into a test environment, and which Power BI reports may use workforce information.
-
Confidentiality. People with access to employee information need confidentiality obligations. That includes implementation consultants, support personnel and any approved sub-processor staff who can access case notes, identity documents or absence information.
-
Security measures. The contract must address appropriate technical and organisational measures. In practice, review access through Microsoft Entra ID, role-based permissions, privileged access, logging, environment separation and the handling of exports to Teams, Outlook or SharePoint. Don't accept a reference to “industry-standard security” without a description of what the provider maintains.
-
Sub-processors. The DPA must control any other processor used by the supplier. A UK Right to Work verification service, AI CV parsing provider or support platform may need to be listed if it processes candidate or employee data.
-
Data subject rights. The processor must assist the controller with rights requests. The clause should work for access, rectification, restriction, erasure and other requests that require records to be located across Dataverse, documents and connected services.
-
Assistance with controller obligations. The processor must help with compliance obligations where relevant. That can include security assessments, incident investigation, data protection impact assessments and information needed to demonstrate compliance.
-
End-of-contract data handling. The DPA must cover deletion or return of personal data. That includes live Dataverse data, documents, exports, support copies and any other location covered by the processing arrangement.
-
Audit and inspection rights. The controller needs a meaningful ability to assess compliance. A clause that allows only a marketing brochure or a vague “reasonable information” response is weak. The ICO guidance on contract content explains these required safeguards.
For broader context, teams reviewing connected platforms can also consult the Purple data security overview, particularly when assessing how a third-party service describes its security controls and data handling.
The ICO's current guidance is explicitly under review following the Data (Use and Access) Act coming into law on 19 June 2025, so UK DPA practice remains a live regulatory topic. That doesn't justify delaying a contract. It does justify keeping your DPA schedule and supplier review process current.
A Clause-by-Clause DPA Checklist for HR and IT Teams
Use the table below in two places. First, use it during supplier diligence before you approve the Dynamics 365 HR design. Then use it as a redline checklist against the vendor's paper. A DPA that looks complete may still fail to describe the actual flow from recruitment through offboarding.
| DPA Clause | What It Should Cover | Check for a Dynamics 365 HR Deployment |
|---|---|---|
| Scope and subject matter | The services, systems and processing activities covered by the agreement. | Does it include implementation, configuration, support, managed services and access to Dataverse? |
| Purposes and duration | Why processing takes place and how long it continues. | Are recruitment, onboarding, employee administration, reporting and support clearly separated? Does the term cover post-termination handling? |
| Personal data and data subjects | The types of data and categories of people involved. | Check names, contact details, bank information, Right to Work documents, performance notes, candidates, employees and former employees. |
| Controller instructions | How instructions are issued, amended and recorded. | Can instructions be tied to a change request, solution design, Dataverse configuration or approved support ticket? |
| Technical and organisational measures | Security, confidentiality, access, resilience and governance controls. | Review Microsoft Entra ID, role-based access, environment permissions, logging, export controls and consultant access. |
| Sub-processors | Authorisation, notification, objections and responsibility for downstream providers. | Identify AI CV parsing, Right to Work verification, communications, hosting and support services that touch personal data. |
| International transfers | Transfer locations and the legal mechanism used for restricted transfers. | Confirm where support, monitoring, backups and connected services operate. Require the relevant UK transfer documentation where needed. |
| Audit and inspection | Evidence, assessments, inspections and regulator access. | Can the customer review security evidence and investigate an issue without the right being reduced to a discretionary supplier response? |
| Liability and indemnities | How privacy and security risk interacts with the main liability structure. | Check whether the standard cap applies to a serious data incident and whether the DPA creates a contradictory limit. |
| Breach notification | Notice timing, contact routes, information supplied and continuing updates. | Ensure the implementation partner’s workflow connects to the customer’s IT security and privacy contacts. |
| Deletion or return | Export, deletion, backups, copies and certification. | Include Dataverse records, SharePoint documents, Power BI datasets, test copies, support extracts and retained logs where relevant. |
Applying the checklist before signature
Start with the data map, not the supplier's template. Ask HR process owners where candidate information enters the organisation, where managers add notes, which documents are uploaded, and which reports leave the core HR application. Then ask IT which services can technically access those records.
Teams and Outlook often create overlooked processing paths. A manager may discuss a sickness case in Teams, approve a change through Outlook, or attach a document stored in SharePoint. Power BI may then consume Dataverse information for workforce reporting. The DPA should reflect those instructions and interfaces where the supplier has access or operational responsibility.
Redline test: If the vendor can't explain how a clause applies to your actual data flow, don't sign the clause simply because the wording looks familiar.
Record the final position in a DPA schedule, attach the approved sub-processor information, and retain the technical and organisational measures as a controlled document. That gives HR, IT, procurement and the supplier one version of the operating rules.
Sample Clause Language and Common Red Flags to Reject
Vendor wording often sounds reassuring while leaving the controller with no practical control. Read each clause against the question, “What can this supplier do tomorrow without asking us?”

Sub-processors
Weak wording:
“The processor may engage other processors at its discretion and remains responsible for their services.”
That doesn't give the employer visibility of an AI CV provider, Right to Work service or support platform. It also avoids the approval mechanism required by the Article 28 framework.
Stronger wording:
“The processor may engage the sub-processors identified in the approved schedule. Any proposed change requires prior written authorisation, or a documented general authorisation process with advance notice, a genuine right to object and a defined remedy where the objection cannot be resolved.”
Reject phrases such as:
- Unrestricted discretion: “We may engage other processors at our discretion.”
- Private assessment only: “We use sub-processors we have assessed as suitable.”
- No useful remedy: “The customer may object, but the processor may continue processing regardless.”
International transfers
Weak wording:
“Data may be transferred outside the UK as needed to provide the services, subject to appropriate safeguards.”
That wording leaves the customer guessing about countries, access routes and legal mechanisms. It's unsuitable for an HR deployment containing identity documents and employee records.
Stronger wording:
“The processor will identify each restricted transfer, the destination and the processing purpose, and will maintain the applicable UK transfer documentation, including the UK International Data Transfer Agreement or another legally recognised mechanism, supported by an appropriate transfer assessment where required.”
Ask for the actual transfer schedule, not a promise that safeguards exist somewhere else.
Breach notification
Weak wording:
“The processor will notify the controller within 72 hours of a breach where legally required.”
The phrase “where legally required” can create an argument about whether the supplier has to notify you. The clause also says nothing about the information HR and IT need to assess their own obligations.
Stronger wording:
“The processor will notify the controller without undue delay after becoming aware of a personal data breach and will provide the known nature and scope of the incident, affected data categories, likely consequences, containment measures and continuing updates as the investigation develops.”
A contract can also specify a practical notification window, such as 24 to 72 hours, provided that the wording doesn't delay notice while the supplier investigates. The data protection by design guidance is useful when checking whether contractual commitments match the system's design.
Apply the same scrutiny to Microsoft Online Services Terms, the Hubdrive addendum and the implementation partner's agreement. Microsoft's platform role, Hubdrive's application role and the partner's delivery role may create different processing responsibilities. Don't assume one document covers all three.
Negotiation Tips for SaaS Vendors and Controllers
Negotiation works best when you separate legal minimums from commercial risk allocation. Article 28 tells you what the processor contract must contain. Liability caps, indemnities, service credits and audit mechanics often require a commercial decision based on the employer's risk appetite.
A practical negotiation sequence
Start with the clauses that can stop the deployment from operating lawfully:
-
Map the parties and instructions. Name the controller, processor and any implementation party. Put the processing instructions in a schedule that references the Dynamics 365 HR design, approved environments, support access and connected services.
-
Demand sub-processor transparency. Require a current list with processing purpose, location and access type. Use written approval or a controlled notice and objection model. A supplier shouldn't be able to introduce a service that reads candidate documents without a documented process.
-
Set a workable incident route. Name the security and privacy contacts, define the information the supplier must provide, and connect the supplier's escalation process to your internal IT security workflow.
-
Challenge the liability position. Check whether the main agreement's cap applies to data protection breaches, confidentiality failures and security incidents. If the risk is material, negotiate a separate treatment rather than accepting a standard cap without analysis.
-
Make audit rights usable. Accepting independent assurance can be sensible, but the contract should still allow targeted investigation, regulator access and evidence review when a Dynamics 365 HR issue arises.
-
Control exit. Agree how the customer will export records and how the supplier will handle copies, documents, test data and backups. Don't leave deletion to an undocumented internal policy.

Keep the customer's governance aligned
Every material DPA change should trigger an update to the organisation's records of processing activities and supplier register. If a new sub-processor is added, the HR operational owner should know how to raise a change request and where to record the decision. IT security should receive the same information that privacy and procurement receive.
Keep a redline tracker with four columns: clause, supplier position, customer position and agreed operational owner. That stops legal negotiations from becoming disconnected from the configuration team. A clause promising restricted access is meaningless if nobody confirms the corresponding Entra ID roles.
Watch the following video for a concise visual explanation of the negotiation priorities:
A Dynamics 365 HR project commonly involves three contractual layers. Microsoft provides the platform and associated service terms. Hubdrive provides the HR application layer. The implementation partner configures, integrates and supports the solution. Your procurement file should identify the processing performed at each layer, rather than treating “the Microsoft solution” as a single supplier.
How It All Fits Together in a DynamicsHub-Style HR Deployment
A mid-market employer might begin with recruitment. AI CV parsing and scoring process candidate information, so the DPA should identify the purpose, the provider involved and the limits on reuse. If the supplier can access CVs during configuration or support, that access belongs in the documented instructions and security measures.
During onboarding, the organisation may store and verify Right to Work documents through an integrated UK module. The DPA needs to identify the relevant service, retention approach, access roles and any sub-processor involved in verification. A generic “employee data” description is too broad to help the HR team decide what happens when a document reaches the end of its retention period.
Live employment records then sit in Dynamics 365 HR and Dataverse, with reporting data feeding Power BI. Where the deployment uses the customer's own Microsoft 365 tenant, the contract and technical design should still explain who can administer the environment, who can support it and how exports are controlled. Microsoft Entra ID can support the access model, but the DPA must assign the operational responsibility for configuring and reviewing that model.
Offboarding tests whether the DPA is real. The employer needs a clear process for returning or deleting employee data, documents, reports and support copies when the supplier relationship ends. The data protection impact assessment guidance can help teams examine the higher-risk parts of the data flow before the system goes live.
For organisations evaluating this model, DynamicsHub implements and supports Hubdrive's HR Management for Microsoft Dynamics 365, including hire-to-retire processes, Dataverse-based integration and UK-focused HR controls. The commercial decision still requires your own DPA review. No platform removes the controller's responsibility to understand its processing arrangements.
Frequently Asked Questions About Data Processing Agreements
Do we need a DPA for internal Microsoft 365 tools?
You need to assess the roles involved. If an external supplier processes employee data on your behalf, Article 28 requirements apply to that controller-processor arrangement. Internal use of Microsoft 365 doesn't automatically create a separate DPA between departments, but external implementation, support and application providers still need careful review.
Who signs when a partner implements the HR system?
The controller should ensure that every party acting as a processor is covered by an appropriate contract. That may involve separate agreements with the platform provider, application provider and implementation partner, depending on their roles and access.
Can we rely on Microsoft and Hubdrive's standard DPAs?
Use standard terms as a starting point, not as a substitute for your deployment schedule. Add your actual HR purposes, data categories, support access, sub-processors, transfers, retention and deletion arrangements.
What breach notification timing should we require?
Require notice without undue delay, with a defined practical window where appropriate, plus the information your privacy and IT teams need to investigate. A notification should allow you to assess whether the incident involves personal data and what action follows. The GDPR compliance checklist can support the wider review.
DynamicsHub helps UK organisations implement Hubdrive's HR Management for Microsoft Dynamics 365 with practical data flows, access controls, retention considerations and supplier governance built into the deployment. Visit DynamicsHub to discuss your HR transformation, phone 01522 508096 today, or send us a message through our contact page.