Vendor risk

What is a subprocessor?

A subprocessor is a third party that a service provider (a processor) engages to process personal data on its behalf, such as a hosting, email, or analytics provider. Under GDPR, a processor may only use subprocessors with the customer's authorization.

Definition

A subprocessor is a third party engaged by a processor to carry out specific processing of personal data on behalf of, and under the instructions of, that processor.

Background

In GDPR terms, a controller decides why and how personal data is processed, and a processor processes it on the controller's behalf. Most SaaS vendors are processors, and they in turn rely on other services (cloud hosting, transactional email, error monitoring) that touch the data. Those downstream services are subprocessors. GDPR Article 28 says a processor must not engage a subprocessor without the controller's prior authorization, must flow the same data-protection obligations down by contract, and remains responsible for the subprocessor's performance.

Why it matters

Subprocessors are part of your data supply chain, so buyers need to know who they are and where data goes. Publishing an accurate subprocessor list is a standard transparency practice, and keeping it correct matters: your privacy commitments and your actual subprocessor list must agree.

Step by step

  1. Identify every third party that processes personal data on your behalf.
  2. Ensure a data processing agreement is in place with each, flowing down your obligations.
  3. Publish a current subprocessor list and note where data is processed.
  4. Give customers a way to be notified of new subprocessors, per your DPA.
  5. Review the list whenever your infrastructure or vendors change.

Examples

  • A SaaS product lists its cloud host, email provider, and error-monitoring service as subprocessors.
  • A vendor adds a new analytics provider and updates its subprocessor list and customer notifications accordingly.

Common mistakes

  • Listing subprocessors inconsistently across the privacy policy and the public subprocessor page.
  • Adding a subprocessor without a data processing agreement in place.
  • Failing to notify customers of new subprocessors when the DPA requires it.

FAQ

What is the difference between a processor and a subprocessor?

A processor processes personal data on behalf of a controller (the customer). A subprocessor is a third party the processor engages to help with that processing. Under GDPR Article 28, the processor stays responsible for its subprocessors.

Why do vendors publish a subprocessor list?

For transparency and to satisfy data processing agreements. Customers need to know who touches their data and where, and many DPAs require advance notice of new subprocessors so customers can object.

Related

What is a data processing agreement? → What is vendor risk management? → Keel subprocessors →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free