What is a sub-processor?
A sub-processor is a party engaged by your processor to carry out part of the personal data processing. Think of a cloud provider used by your payroll service, or an email service used by your CRM vendor.
Art. 28(2) and (4) of the GDPR regulate the conditions under which a processor may engage sub-processors.
Two forms of authorisation
The GDPR recognises two forms of authorisation for engaging sub-processors:
1. Specific prior written authorisation
For each new sub-processor, the processor seeks explicit consent from the controller. This gives you maximum control but can be cumbersome in practice with large vendors that use many sub-processors.
2. General written authorisation
The processor has a general authorisation to engage sub-processors but must inform the controller in advance of any changes (additions or replacements). The controller then has the right to object.
In practice, most SaaS vendors work with a general authorisation and publish a sub-processor list on their website.
Notification obligation for changes
When a processor works with a general authorisation, they must inform the controller of changes to the sub-processor list before the change takes effect. The processor must give the controller sufficient time to object.
Practical considerations:
- Agree a reasonable notice period in the DPA (30 days is common)
- Specify how notification takes place (email, dashboard, website)
- Regularly check whether your vendors have updated their sub-processor lists
Right to object
If you disagree with a new sub-processor, you have the right to object. The DPA should specify what happens when an objection is raised. Possible outcomes:
- The processor finds an alternative sub-processor
- The processor performs the relevant processing itself
- If no solution is possible: termination of the agreement
Contractual requirements for sub-processors
Art. 28(4) GDPR requires the processor to impose the same data protection obligations on each sub-processor as those in the DPA with the controller. This includes:
- Instruction-bound processing
- Confidentiality
- Security measures (Art. 32)
- Assistance with data subject rights
- Deletion or return after termination
- Audit rights
The original processor remains fully liable to the controller for the sub-processor's compliance.
Risks of poor sub-processor management
- Data outside the EEA: a sub-processor may process data in a country outside the EEA without appropriate safeguards
- Insufficient security: a sub-processor with weak security poses a risk to your data
- Non-compliance: if you do not know which sub-processors are used, you cannot demonstrate compliance
- Fines: supervisory authorities can impose fines for insufficient oversight of processors
Practical tips
- Maintain an up-to-date overview of all sub-processors per vendor
- Set alerts for changes in sub-processor lists
- Verify that new sub-processors meet your security requirements
- Assess whether data is transferred outside the EEA and what safeguards are in place
- Use DPAkit to automatically monitor sub-processor changes and track objection deadlines
Summary
Sub-processor management is a crucial but often underestimated part of GDPR compliance. By setting clear terms in your DPAs and actively monitoring changes, you retain control over who processes your personal data.