Skip to main content
Data Protection / GDPR

Sub-processor

A sub-processor is a further processor engaged by a processor with the controller's authorisation under Art. 28(2) GDPR, and to whom the same data protection obligations must be passed on by contract.

A sub-processor (also sub-contracted processor or sub-service provider) is a company that processes personal data on behalf of a processor, which in turn processes that data for a controller. Typical examples are the data centre behind a SaaS provider, an outsourced second-level support team, a backup or monitoring provider, or a maintenance contractor with remote access. The GDPR contains no separate legal definition for sub-processors: in law they are simply another processor within the meaning of Art. 4(8) GDPR, which means the same rules apply along the entire chain – including any further links engaged below the first sub-processor.

Under Art. 28(2) GDPR a processor must not engage another processor without the controller's prior specific or general written authorisation. In practice the general authorisation prevails: the data processing agreement contains a list of approved sub-processors, and the processor must inform the controller in advance of any intended changes – that is, the addition or replacement of further providers – so that the controller can object. Notice periods, communication channels and the consequences of an objection (such as a special right of termination) have to be agreed contractually, because the GDPR sets no deadlines of its own. The authorisation is a precondition for lawfulness: passing data to a sub-processor that has not been authorised makes the disclosure unlawful.

Art. 28(4) GDPR provides for the obligations to flow down the chain: the same data protection obligations that apply between the controller and the processor must be imposed on the sub-processor by contract or another legal act – in particular sufficient guarantees for appropriate technical and organisational measures under Art. 32 GDPR. Where the sub-processor fails to fulfil those obligations, the initial processor remains fully liable to the controller for the performance of the sub-processor's obligations. Liability towards data subjects under Art. 82 GDPR applies in addition, and infringements of Art. 28 can be fined under Art. 83(4)(a) GDPR. None of this relieves the controller: under Art. 24 and Art. 28(1) GDPR it must satisfy itself of the reliability of the entire chain. If a link in that chain sits in a third country, a transfer mechanism under Chapter V GDPR is required as well – usually the standard contractual clauses (Module 3, processor to processor) together with a transfer impact assessment.

Legal Basis

Art. 28(2) and Art. 28(4) GDPR (in conjunction with Art. 4(8), Art. 32, Art. 82 and Art. 83(4)(a) GDPR)

Practical Example

An insurance broker uses a CRM system delivered as SaaS. In the data processing agreement it granted a general authorisation under Art. 28(2) GDPR and accepted an annex listing three sub-processors: the cloud data centre in Frankfurt, an email delivery service and a backup provider. When the vendor announces that it intends to add a support provider based in India, the privacy coordinator reviews the documentation within the 30-day objection period agreed in the contract. She asks for evidence that the same obligations have been imposed on the new sub-processor under Art. 28(4) GDPR, examines its technical and organisational measures, the standard contractual clauses in Module 3 and a current transfer impact assessment. Because remote access to health data from the third country is not sufficiently safeguarded, she objects in time; the vendor then limits support to an EU-based team. The change is documented in the record of processing activities and in the sub-processor annex.

FAQ

No. Alongside specific authorisation, Art. 28(2) GDPR also allows a general written authorisation, typically granted through a sub-processor list in the data processing agreement. The processor must then notify the controller in advance of any intended addition or replacement, and the controller may object. Without an authorisation no further provider may be engaged.
Under Art. 28(4) GDPR the engaging processor remains fully liable to the controller for the performance of the sub-processor's obligations. Liability towards data subjects under Art. 82 GDPR applies in addition, and the controller stays responsible for selecting and monitoring the whole chain under Art. 24 and Art. 28(1) GDPR.
In that case the requirements of Chapter V GDPR apply on top of Art. 28 GDPR. Usually the standard contractual clauses in Module 3 (processor to processor) are concluded and supplemented by a transfer impact assessment; where an adequacy decision covers the recipient – for example certified US companies under the EU-US Data Privacy Framework – no additional transfer mechanism is needed.

How preeco supports you

Learn how our software supports you with this topic.

Learn more