Data Protection
Data protection / UK GDPR obligations
If you touch the client's customer or personal data, UK law requires the contract to spell out how you handle it, so a missing clause is a gap for both of you. The required terms include only processing on the client's instructions, keeping data secure and confidential, and deleting or returning it at the end. Just check the security and liability duties are proportionate to the small volume of data a freelancer usually handles.
What to look for
If the freelancer will handle personal data on the client's behalf, whether the contract includes the Article 28 processor terms UK GDPR requires, and whether the obligations imposed are proportionate to what the freelancer actually does with data.
How Clause rates it
Wording you can ask for
Where the Freelancer processes personal data on the Client's behalf, the Freelancer shall: process it only on the Client's documented instructions; keep it confidential; apply appropriate technical and organisational security measures; not engage sub-processors without consent; assist the Client with data-subject requests and security obligations; and delete or return the data at the end of the engagement.
The UK angle
UK GDPR Article 28 makes these processor terms mandatory whenever a freelancer processes personal data for a client; the ICO treats such freelancers as 'processors' and requires a written contract covering these points.
See this on your own contract.
Paste your contract and watch these rules light up your own clauses.