Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk6 min

What Is a Subprocessor? Definition, Examples, and Responsibilities

A subprocessor handles personal data downstream on a processor’s behalf. Understand approval, contract protections, oversight, and liability under the EU and UK GDPR frameworks.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A subprocessor is a processor that another processor engages to handle personal data on its behalf. In a typical chain, a controller decides why and how personal data is processed, a processor handles it for the controller, and a subprocessor handles part of that work under the processor’s instructions. The original processor remains accountable to the controller for the subprocessor’s performance; outsourcing the work does not erase the controller’s own compliance duties.

What is a subprocessor?

“Subprocessor” describes a downstream role in a personal-data processing chain. A processor engages another organization to carry out some processing for it, and that organization acts on the processor’s instructions. The European Data Protection Board’s small-business guidance describes processors as handling personal data on a controller’s behalf and under its instructions; a downstream processor receives its instructions from the processor that engaged it.

The chain may look like this:

Controller → Processor → Subprocessor → (possibly another processor)

The label alone does not determine an organization’s legal role. Assess what it actually does with personal data, whose purposes it serves, and whose instructions it follows. The UK Information Commissioner’s Office (ICO) notes that “sub-processor” is useful shorthand, not a term taken from the UK GDPR itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is the difference between a controller, processor, and subprocessor?

Role What it does Whose instructions guide it?
Controller Determines the purposes and means of processing personal data. It determines the purposes and means; it does not act as a processor on another party’s behalf.
Processor Processes personal data on behalf of a controller. The controller’s instructions.
Subprocessor Processes personal data on behalf of a processor as part of the processor’s service to the controller. The processor that engaged it, subject to the obligations passed down from the controller–processor arrangement.

These roles can include businesses, public authorities, agencies, or other bodies. A company’s marketing description or contract label is not enough to classify it: examine the actual processing arrangement.

What are examples of subprocessors?

Cloud storage and analysis

The ICO describes an organization using a cloud service to store and analyze its data: the organization is the controller and the cloud provider is its processor. If the cloud provider engages another service to perform part of the entrusted personal-data processing, that downstream service may be a subprocessor, depending on the actual arrangement.

Mailing and subscriptions

A company that handles magazine subscriptions and home mailings for a publisher can be the publisher’s processor. If that mailing company then uses another provider to process subscriber data on its behalf, the further provider may sit downstream as a subprocessor.

Marketing services

A marketing company that sends vouchers to a hairdresser’s customers on the hairdresser’s behalf illustrates a processor relationship. A business engaged by the marketing company to process those customer details may be another link in the chain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These examples explain the roles; they do not establish that a particular provider is always a processor or subprocessor. The service, data flows, instructions, and contracts in the specific arrangement matter.

Does a controller have to approve subprocessors?

Under Article 28(2) of the EU GDPR, a processor cannot engage another processor without the controller’s prior specific or general written authorisation. The UK GDPR has a parallel Article 28 framework, but requirements can differ under other national or sector-specific laws.

Specific written authorisation

The controller approves a particular downstream provider for a defined processing arrangement. This can give the controller a direct approval point for that engagement.

General written authorisation

The controller authorises a broader arrangement, such as an agreed list or process. The processor must inform the controller about intended additions or replacements and give it an opportunity to object. The notice-and-objection process should be practical enough for the controller to review a change before it takes effect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

EDPB Opinion 22/2024 says controllers should have current information about all processors and subprocessors readily available. Relevant information includes each entity’s name, address, contact person, and description of processing. For a proposed subprocessor, useful review details also include processing locations and safeguards.

What should a subprocessor agreement cover?

Article 28(4) requires the processor to impose on its subprocessor the relevant data-protection obligations from the controller–processor arrangement, through a contract or other permitted legal act. The subprocessor must provide sufficient guarantees for appropriate technical and organizational measures. The downstream wording need not be identical to the upstream contract, but it must preserve the required level of protection.

The ICO’s UK GDPR guidance describes processor terms addressing security, assistance with individuals’ rights, support for breach response and impact assessments, deletion or return of data at the end of the service, and audit information and access. In reviewing an arrangement, parties should also examine:

  • The precise processing activity and personal-data categories assigned downstream.
  • The subprocessor’s identity, contact point, operating location, and locations from which data can be accessed.
  • How the processor will notify the controller of additions or replacements, and how the controller can object.
  • Security measures and evidence that the subprocessor provides sufficient guarantees.
  • Assistance with data-subject requests, incidents, and impact assessments.
  • International transfers, transfer safeguards, and remote access where relevant.
  • Incident escalation, audit or assurance materials, and end-of-contract deletion or return.

These are practical review topics, not a substitute for checking the applicable law and contract. EDPB Opinion 22/2024 says the extent of a controller’s verification may vary with the nature of the measures and the risk, while the duty to verify sufficient guarantees applies regardless of risk.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who is liable if a subprocessor has a data breach?

Article 28(4) says the initial processor remains fully liable to the controller for the subprocessor’s performance of its data-protection obligations. This is a responsibility within the controller–processor relationship; it does not mean every consequence of an incident is automatically assigned to one party in every situation.

The controller retains its own GDPR responsibilities, including selecting processors that provide sufficient guarantees and being able to demonstrate compliance and oversight. The ICO also explains that, in the UK, a subprocessor may be liable for damage where it breaches processor-specific UK GDPR obligations or acts against lawful controller instructions relayed through the processor. Contractual recourse between parties depends on the contract, and the precise outcome depends on the applicable law and facts.

In practice, document the chain, keep change notices and authorisations, and make sure incident reporting and cooperation duties can work across each link. Outsourcing processing does not transfer all responsibility away from the controller or initial processor.

How to review a proposed subprocessor

  1. Map the processing. Identify the personal data involved, what each provider will do, and whose instructions govern each activity.
  2. Confirm the authorisation route. Check whether the controller gave specific or general written authorisation and, for general authorisation, whether the notice and objection process is clear.
  3. Get current identity details. Record each provider’s name, address, contact person, processing description, and relevant processing or access locations.
  4. Check safeguards and transfers. Review security evidence, assistance commitments, international transfer arrangements, and the controller’s ability to verify the guarantees.
  5. Test operational protections. Confirm incident escalation, rights-request and impact-assessment support, audit arrangements, and deletion or return at termination.
  6. Keep the record current. Update the processing chain when providers or activities change, and preserve the notice, review, objection, and approval history.

Example: assessing a screenshot service in a processing chain

If a business uses a website screenshot service and personal data is included in the submitted URL or captured page, assess the service’s actual role and data handling rather than assuming its label decides the answer. A technical service provider might be a processor or subprocessor in a particular arrangement, but that classification depends on its processing, purpose, instructions, and contract. For example, ScreenshotNeo is a website screenshot API and MCP server for developers; whether it belongs in a particular organization’s processing chain requires reviewing that organization’s use and terms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.