Skip to main content
Back to knowledge base
Guide

Managing sub-processors under the GDPR

When your vendor (processor) engages another party to process personal data, that party is a sub-processor. The GDPR sets specific requirements for engaging sub-processors. This article explains how to manage this properly.

28 March 20267 min read

What is a sub-processor?

A sub-processor is a party engaged by your processor to carry out part of the personal data processing. Think of a cloud provider used by your payroll service, or an email service used by your CRM vendor.

Art. 28(2) and (4) of the GDPR regulate the conditions under which a processor may engage sub-processors.

Two forms of authorisation

The GDPR recognises two forms of authorisation for engaging sub-processors:

1. Specific prior written authorisation

For each new sub-processor, the processor seeks explicit consent from the controller. This gives you maximum control but can be cumbersome in practice with large vendors that use many sub-processors.

2. General written authorisation

The processor has a general authorisation to engage sub-processors but must inform the controller in advance of any changes (additions or replacements). The controller then has the right to object.

In practice, most SaaS vendors work with a general authorisation and publish a sub-processor list on their website.

Notification obligation for changes

When a processor works with a general authorisation, they must inform the controller of changes to the sub-processor list before the change takes effect. The processor must give the controller sufficient time to object.

Practical considerations:

  • Agree a reasonable notice period in the DPA (30 days is common)
  • Specify how notification takes place (email, dashboard, website)
  • Regularly check whether your vendors have updated their sub-processor lists

Right to object

If you disagree with a new sub-processor, you have the right to object. The DPA should specify what happens when an objection is raised. Possible outcomes:

  • The processor finds an alternative sub-processor
  • The processor performs the relevant processing itself
  • If no solution is possible: termination of the agreement

Contractual requirements for sub-processors

Art. 28(4) GDPR requires the processor to impose the same data protection obligations on each sub-processor as those in the DPA with the controller. This includes:

  • Instruction-bound processing
  • Confidentiality
  • Security measures (Art. 32)
  • Assistance with data subject rights
  • Deletion or return after termination
  • Audit rights

The original processor remains fully liable to the controller for the sub-processor's compliance.

Risks of poor sub-processor management

  • Data outside the EEA: a sub-processor may process data in a country outside the EEA without appropriate safeguards
  • Insufficient security: a sub-processor with weak security poses a risk to your data
  • Non-compliance: if you do not know which sub-processors are used, you cannot demonstrate compliance
  • Fines: supervisory authorities can impose fines for insufficient oversight of processors

Practical tips

  • Maintain an up-to-date overview of all sub-processors per vendor
  • Set alerts for changes in sub-processor lists
  • Verify that new sub-processors meet your security requirements
  • Assess whether data is transferred outside the EEA and what safeguards are in place
  • Use DPAkit to automatically monitor sub-processor changes and track objection deadlines

Summary

Sub-processor management is a crucial but often underestimated part of GDPR compliance. By setting clear terms in your DPAs and actively monitoring changes, you retain control over who processes your personal data.

Monitor sub-processors with DPAkit

DPAkit helps you track and monitor sub-processor changes across all your vendors.

Start for free