Skip to content
← All terms

Glossary · Privacy & regulation

Sub-processor

A sub-processor is a third party a data processor engages to help process personal data on a controller’s behalf — a cloud host, for example. GDPR requires the controller’s prior authorization and a flow-down contract.

Processors rarely operate in isolation: a SaaS vendor acting as processor for its customer (the controller) typically relies on infrastructure providers, backup services, or specialized tooling that also touch personal data. Each of those is a sub-processor, and GDPR Article 28(2) and 28(4) require the primary processor to obtain either specific or general written authorization from the controller before engaging one, and to bind the sub-processor to data-protection obligations at least as protective as those in the original DPA.

Where general authorization is used — common in SaaS contracts — the processor must give the controller a mechanism to object to new sub-processors, usually via advance notice and a published, kept-current list. This is why many vendors maintain a public sub-processor page: it satisfies the transparency obligation without requiring bespoke sign-off for every new one.

Liability doesn’t evaporate down the chain — the primary processor remains responsible to the controller for a sub-processor’s compliance, which is why the flow-down contractual terms matter as much as the notification process itself.

Related terms