Sub-Processor
A sub-processor is a third-party vendor that a data processor brings in to help handle personal data while providing services to another organization. For example, if a company processes personal data on behalf of its customers and then hires an outside service to help with part of that work, that outside service is a sub-processor. Under the GDPR, a processor typically cannot engage a sub-processor without the controller's prior written authorization.
In the context of the GDPR and UK GDPR, a sub-processor is a third-party data processor engaged by a primary data processor that has, or will have, access to or processes personal data originating from a data controller. The engagement of a sub-processor is subject to the controller's prior specific or general written authorization, as reflected in ICO guidance. This entry is scoped to data protection processing roles and does not address the distinct governance and model risk management concepts used in AI oversight; sub-processor obligations arise from data protection law rather than from model risk frameworks, and the specific contractual and authorization requirements may vary by jurisdiction and by the terms of the underlying data processing agreement.
Why it matters
The sub-processor concept matters because responsibility for personal data does not end at the first vendor in a chain. When a processor engages another party to help deliver its services, personal data can move further away from the controller who remains accountable for it. Under the GDPR and UK GDPR, this is why a processor typically cannot bring in a sub-processor without the controller's prior authorization, whether specific or general, as reflected in ICO guidance. The requirement gives the controller visibility and a degree of control over who ultimately handles data collected under its responsibility.
For compliance and privacy professionals, sub-processor arrangements are a common source of gaps between contractual promises and operational reality. A data processing agreement may commit a processor to specific safeguards, but if a downstream sub-processor is engaged without proper authorization or without equivalent obligations flowing down, the controller can lose assurance over how its data is protected. Maintaining an accurate, current list of sub-processors and honoring notification and objection mechanisms are therefore practical control points that map directly to the written authorization requirement.
This entry is scoped to data protection processing roles under the GDPR and UK GDPR and does not address AI governance or model risk management concepts. Sub-processor obligations arise from data protection law rather than from model risk frameworks, and the specific contractual and authorization requirements vary by jurisdiction and by the terms of the underlying data processing agreement. Readers should treat the precise mechanics of authorization and notification as dependent on the applicable law and the agreement in force rather than as a single universal standard.
Who it's relevant to
Inside Sub-Processor
Common questions
Answers to the questions practitioners most commonly ask about Sub-Processor.