Glossary
Sub-processor
Also called: subprocessor, sub-contracted processor
A sub-processor is a third party a processor engages to help process personal data on a controller's behalf. Under the GDPR the processor remains liable for its performance and must give notice before the list changes, so the controller can object.
Sub-processor explained
Why the list matters
It is your supply chain. Every party on it can, in principle, access data you are responsible for, and you carry the accountability for their processing even though you never contracted with them directly. A vendor unwilling to publish the list is asking you to accept an unknown supply chain.
What a useful entry contains
The party, what it does, what categories of data it touches, the country it processes in, and the safeguard relied on for any transfer out of the UK or EEA. A list of company names without those four columns cannot be assessed.
Notice and objection
The rights that make the list operative rather than informational. A stated notice period before a new sub-processor is engaged — thirty days is the common standard — a defined way of giving that notice, and a right to object with a termination remedy if no reasonable alternative exists.
Without them, the list tells you what happened rather than letting you decide.
Keeping it current
An inaccurate sub-processor list is a breach of the data processing addendum rather than a website error, because the addendum incorporates it by reference. Reviewing it is a scheduled task, not something to do when a customer asks.
FAQ
Sub-processor: common questions
Do we need to approve each sub-processor individually?
Usually general authorisation with notice and a right to object, rather than case-by-case approval, which does not scale for either party. Specific approval is negotiable for higher-risk processing.
Is a cloud hosting provider a sub-processor?
Yes, and normally the most significant one, because it holds the data at rest. Any list that omits the hosting provider is incomplete.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
Dernière revue: 28 août 2026. Browse the full glossary.