Sub-processor, the processor your processor hired
A sub-processor is a third party engaged by your processor to carry out part of the processing of personal data on your behalf. Under UK and EU GDPR a processor cannot engage one without your prior authorisation, must flow down equivalent obligations, and remains fully liable to you for the sub-processor’s performance. Also called Subprocessor.
What the rules require
Article 28(2) is the operative provision: a processor must not engage another processor without prior specific or general written authorisation from the controller. Where the authorisation is general, the processor must inform the controller of intended changes and give it the opportunity to object — which is why sub-processor pages carry notification mechanisms rather than simply listing names.
Two further obligations matter in practice. The processor must impose the same data protection obligations on the sub-processor by contract, and it remains fully liable to the controller for the sub-processor's performance. You cannot be told that a failure was the sub-processor's and therefore not your supplier's problem.
What to do with the sub-processor list
Read it, and keep reading it. The list is the single best free source of fourth-party data you will get: it is public, it is maintained because it has to be, and it names the parties actually handling your data. Aggregated across your DPAs, it is also the fastest route to seeing concentration — several unrelated vendors naming the same underlying platform.
Subscribe to change notifications where the vendor offers them, and treat a new sub-processor in a new jurisdiction as a trigger for review rather than an administrative update. The objection right in Article 28(2) is only useful if somebody notices in time to exercise it.
Common questions
What is the difference between a processor and a sub-processor?
Can a vendor add sub-processors without telling us?
Is a sub-processor the same as a fourth party?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.