Back to Compliance

Data Processing Agreement

CareLedgerPro

Version 1.1 — Last updated: 19 July 2026

What this agreement is

CareLedgerPro provides a Data Processing Agreement (DPA) for customers where CareLedgerPro processes personal data on their behalf. The DPA is designed to reflect the controller-processor contract requirements under UK GDPR Article 28 and to support the Data Protection Act 2018.

In most cases, the care provider is the data controller and decides why and how personal data is processed. CareLedgerPro acts as the data processor and processes personal data only on the controller's documented instructions.

The security measures described in this Agreement are implemented in part by CareLedgerPro and in part by our sub-processors (hosting, authentication, payments, email). CareLedgerPro is not independently certified against ISO 27001, SOC 2, Cyber Essentials, or DSPT. Controllers who require certified processors should assess this before adopting the Service.

Why a DPA matters for regulated care providers

Care providers handle personal data about the people they support, including identity details, financial records, and, in some cases, sensitive information. A DPA helps ensure that this processing is governed by clear contractual terms and appropriate safeguards.

The agreement gives both parties clarity about their responsibilities and supports accountability, audit readiness, and procurement review. It also helps demonstrate that personal data is handled under defined contractual controls.

What the DPA covers

The DPA sets out:

  • Subject matter, duration, nature and purpose of processing — how and why CareLedgerPro processes personal data on the controller's behalf, and for how long.
  • Categories of personal data and data subjects — the relevant categories of information and the individuals whose data is processed.
  • Processing only on documented instructions — CareLedgerPro processes personal data only in line with the controller's documented instructions, unless otherwise required by law.
  • Confidentiality obligations — personnel authorised to process personal data are subject to confidentiality duties.
  • Security measures — appropriate technical and organisational measures are applied to protect personal data.
  • Use of sub-processors — sub-processors may be engaged only under the conditions set out in the DPA and under written terms that impose the required data protection obligations.
  • Assistance to the controller — support with data subject requests, breach response, audits, inspections, and Data Protection Impact Assessments (DPIAs).
  • Deletion or return of data — personal data is returned or deleted at the end of the contract, unless retention is required by law.
  • Liability and compliance commitments — the agreement sets out the parties' responsibilities for meeting applicable data protection obligations.

How it works with CareLedgerPro

CareLedgerPro processes personal data only to provide the contracted service. The care provider decides which service users, staff, and records are entered into the platform and remains responsible for its controller obligations, while CareLedgerPro provides the platform, infrastructure, and relevant security controls needed to process that data on the provider's behalf.

CareLedgerPro's DPA should also sit alongside its wider security and governance materials, including its security overview, incident response arrangements, retention and deletion policies, and sub-processor information, so that customers can see how the contractual commitments are supported in practice.

Roles and responsibilities

Controller (care provider)

  • Decides the purpose and lawful basis for processing.
  • Manages staff access, internal governance, and training as part of its own compliance responsibilities.
  • Handles data subject requests and regulatory correspondence as controller.

Processor (CareLedgerPro)

  • Processes personal data only on documented instructions.
  • Implements appropriate technical and organisational security measures.
  • Assists the controller with relevant processor obligations under the DPA, including support for breaches, rights requests, and DPIAs.
  • Ensures sub-processors are engaged under appropriate written terms and remains accountable to the controller for their relevant performance.

Request a signed DPA

Customers that require a signed Data Processing Agreement for procurement, audit, or regulatory purposes can request one by contacting CareLedgerPro. The current DPA template can then be provided for review and execution.

Email support@careledgerpro.co.uk

Disclaimer — This page is a summary of the Data Processing Agreement and is not legal advice. The registered provider remains responsible for its own controller obligations, including lawful basis, governance, and regulatory compliance.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.