If you’re using a supplier to host *any* EU citizens personal data (including log entries, emails, documents, HR records, backups) then when GDPR starts in May 2018 you need to have a written contract with them that includes:


And that the supplier will

If you fail to to include such terms in your processor contracts, the ICO could fine you the greater of €10m or 2% of total annual turnover. Gulp!
For more detail on GDPR see this article by Rawlinson Butler:
http://www.rawlisonbutler.com/blog/data-protection-need-include-data-processor-contracts/