Glossary

Sub-processor

A sub-processor is, under Article 28 of the GDPR, a provider engaged by a processor to carry out all or part of a processing activity on behalf of the controller. Engaging one requires the controller's authorisation and the flow-down of the same contractual obligations.

What Article 28 requires

A processor may not engage a sub-processor without the controller's written authorisation, either specific and prior, or general provided the controller is informed of intended changes and given the opportunity to object. The processor must then impose the same data protection obligations it is bound by, and remains fully liable to the controller for the sub-processor's performance.

Practical consequence for buyers

The sub-processor list is not a nice-to-have: it is part of the compliance file, to be obtained when the DPA is signed, recorded in the records of processing activities and reviewed at every change notification. It is also the most reliable entry point into fourth-party risk: a sub-processor declared for GDPR purposes is often the very same entity as the critical technical dependency.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account