Glossary Terms

Sub-processor

A third party engaged by a processor to perform part of the personal-data processing for a controller.
On this page

What is a sub-processor?

A sub-processor is a third party engaged by a data processor to perform part of the personal-data processing carried out for a controller. A software provider may rely on sub-processors for cloud hosting, communications, customer support, analytics, security or infrastructure.

The use of a sub-processor extends the processing chain. The original processor remains responsible for following the controller’s instructions and for ensuring that equivalent privacy and security obligations are passed to the sub-processor.

Why do sub-processors matter?

Controllers may contract with one visible provider while personal data is actually processed by many organisations in different countries. Each additional party can introduce security, resilience, transfer and oversight risk. Changes may occur through routine product updates or provider acquisitions.

Accurate sub-processor information is therefore necessary for data mapping, transfer assessments, contracts, incident response and customer transparency.

How are sub-processors approved?

The data-processing agreement should define whether the controller gives specific or general authorisation. Under a general authorisation model, the processor normally provides advance notice of intended changes and an opportunity to object under the agreed terms.

Approval should be supported by proportionate due diligence. The processor should assess security, privacy, locations, continuity, deletion and the nature of the processing before engagement.

How are sub-processors monitored?

The processor should maintain an accurate list, flow down contractual requirements and monitor material changes or incidents. Controllers should review notices and determine whether new locations or services alter risk.

Offboarding should address access removal, deletion and replacement dependencies. The supply chain should be included in incident and business-continuity exercises where the service is critical.

Frequently asked questions

Is every vendor used by a processor a sub-processor?

No. The vendor must process the controller’s personal data as part of the service. Providers without access may not be sub-processors.

Can a sub-processor appoint another sub-processor?

Potentially, if the contractual chain permits it and equivalent obligations and authorisation requirements continue to apply.

Who is liable for the sub-processor?

The original processor normally remains responsible to the controller for the sub-processor’s performance under the agreement.

Do sub-processor changes require a new DPA?

Not always. The existing agreement may provide a notification and objection process, but material changes should be reviewed.

Should sub-processors appear in the privacy notice?

Disclosure requirements vary. Notices commonly identify recipients or categories, while a separate list may provide more detailed transparency.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.