TPRM glossary

Sub-processor, the processor your processor hired

A sub-processor is a third party engaged by your processor to carry out part of the processing of personal data on your behalf. Under UK and EU GDPR a processor cannot engage one without your prior authorisation, must flow down equivalent obligations, and remains fully liable to you for the sub-processor’s performance. Also called Subprocessor.

What the rules require

Article 28(2) is the operative provision: a processor must not engage another processor without prior specific or general written authorisation from the controller. Where the authorisation is general, the processor must inform the controller of intended changes and give it the opportunity to object — which is why sub-processor pages carry notification mechanisms rather than simply listing names.

Two further obligations matter in practice. The processor must impose the same data protection obligations on the sub-processor by contract, and it remains fully liable to the controller for the sub-processor's performance. You cannot be told that a failure was the sub-processor's and therefore not your supplier's problem.

What to do with the sub-processor list

Read it, and keep reading it. The list is the single best free source of fourth-party data you will get: it is public, it is maintained because it has to be, and it names the parties actually handling your data. Aggregated across your DPAs, it is also the fastest route to seeing concentration — several unrelated vendors naming the same underlying platform.

Subscribe to change notifications where the vendor offers them, and treat a new sub-processor in a new jurisdiction as a trigger for review rather than an administrative update. The objection right in Article 28(2) is only useful if somebody notices in time to exercise it.

Common questions

What is the difference between a processor and a sub-processor?
A processor handles personal data on the controller’s behalf under a data processing agreement. A sub-processor is engaged by that processor to carry out part of the work. The controller’s contract is with the processor, which stays fully liable for what its sub-processors do.
Can a vendor add sub-processors without telling us?
Not lawfully under UK or EU GDPR. Engagement requires prior specific or general written authorisation, and where the authorisation is general the processor must inform you of intended additions or replacements and give you the chance to object. That is the mechanism behind published sub-processor lists and change notifications.
Is a sub-processor the same as a fourth party?
A sub-processor is a fourth party, but the terms are not interchangeable. Sub-processor is a data protection term limited to personal data processing. Fourth party is broader and covers any supplier your supplier depends on, including ones that never touch personal data.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.