Sub-processor
A sub-processor is a further processor engaged by a processor with the controller's authorisation under Art. 28(2) GDPR, and to whom the same data protection obligations must be passed on by contract.
A sub-processor (also sub-contracted processor or sub-service provider) is a company that processes personal data on behalf of a processor, which in turn processes that data for a controller. Typical examples are the data centre behind a SaaS provider, an outsourced second-level support team, a backup or monitoring provider, or a maintenance contractor with remote access. The GDPR contains no separate legal definition for sub-processors: in law they are simply another processor within the meaning of Art. 4(8) GDPR, which means the same rules apply along the entire chain – including any further links engaged below the first sub-processor.
Under Art. 28(2) GDPR a processor must not engage another processor without the controller's prior specific or general written authorisation. In practice the general authorisation prevails: the data processing agreement contains a list of approved sub-processors, and the processor must inform the controller in advance of any intended changes – that is, the addition or replacement of further providers – so that the controller can object. Notice periods, communication channels and the consequences of an objection (such as a special right of termination) have to be agreed contractually, because the GDPR sets no deadlines of its own. The authorisation is a precondition for lawfulness: passing data to a sub-processor that has not been authorised makes the disclosure unlawful.
Art. 28(4) GDPR provides for the obligations to flow down the chain: the same data protection obligations that apply between the controller and the processor must be imposed on the sub-processor by contract or another legal act – in particular sufficient guarantees for appropriate technical and organisational measures under Art. 32 GDPR. Where the sub-processor fails to fulfil those obligations, the initial processor remains fully liable to the controller for the performance of the sub-processor's obligations. Liability towards data subjects under Art. 82 GDPR applies in addition, and infringements of Art. 28 can be fined under Art. 83(4)(a) GDPR. None of this relieves the controller: under Art. 24 and Art. 28(1) GDPR it must satisfy itself of the reliability of the entire chain. If a link in that chain sits in a third country, a transfer mechanism under Chapter V GDPR is required as well – usually the standard contractual clauses (Module 3, processor to processor) together with a transfer impact assessment.
Legal Basis
Art. 28(2) and Art. 28(4) GDPR (in conjunction with Art. 4(8), Art. 32, Art. 82 and Art. 83(4)(a) GDPR)
Practical Example
An insurance broker uses a CRM system delivered as SaaS. In the data processing agreement it granted a general authorisation under Art. 28(2) GDPR and accepted an annex listing three sub-processors: the cloud data centre in Frankfurt, an email delivery service and a backup provider. When the vendor announces that it intends to add a support provider based in India, the privacy coordinator reviews the documentation within the 30-day objection period agreed in the contract. She asks for evidence that the same obligations have been imposed on the new sub-processor under Art. 28(4) GDPR, examines its technical and organisational measures, the standard contractual clauses in Module 3 and a current transfer impact assessment. Because remote access to health data from the third country is not sufficiently safeguarded, she objects in time; the vendor then limits support to an EU-based team. The change is documented in the record of processing activities and in the sub-processor annex.