• AUG Certified badgeAUG (Authorized User Group) Certified
  • IND Recognised SponsorIND Recognised Sponsor
  • Nasscom Certified badgeNasscom Certified
  • SNA Certified badgeSNA Certified
  • AUG Certified badgeAUG (Authorized User Group) Certified
  • IND Recognised SponsorIND Recognised Sponsor
  • Nasscom Certified badgeNasscom Certified
  • SNA Certified badgeSNA Certified
  • 4.9 stars on G2
European Directives & Compliance

What Is a Sub-processor?

European Directives & Compliance 4 min read Updated Jun 2026

A sub-processor is a third party that a data processor engages to handle personal data on its behalf, as part of delivering a service to the original data controller. Under GDPR, sub-processors must be bound by the same data protection obligations as the primary processor, and the controller must be informed of their use.

Quick Fact

A data processor cannot simply bring in a sub-processor without notice; GDPR requires either the controller's prior written authorization or, at minimum, advance notification with the chance to object.

Sub-processor at a Glance

AttributeDescription
DefinitionA third party processing data on behalf of a data processor
Legal BasisArticle 28(2) and (4), GDPR
Authorization RequiredController's general or specific written consent
Contractual RequirementSame data protection obligations flow down to the sub-processor
Common ExamplesCloud hosting providers, payroll sub-vendors, IT support services
LiabilityThe original processor remains liable for the sub-processor's compliance

Why Does It Matter?

Modern service delivery, especially payroll, HR tech, and EOR services, often relies on layers of vendors behind the scenes. If a processor engages a sub-processor without proper authorization or fails to impose equivalent data protection terms on them, both the processor and, indirectly, the controller face compliance risk. Understanding the sub-processor chain is essential for companies that want visibility into where their employee data actually goes.

When Is It Used?

Sub-processor rules become relevant whenever a company:

  • Uses an EOR, payroll provider, or HR platform that in turn relies on other vendors, such as cloud hosting or local payroll processing partners.
  • Needs to review a vendor's sub-processor list before signing a service agreement.
  • Requires notification rights over any new sub-processor a vendor plans to engage.
Example

A UK company hires employees in Poland through an Employer of Record. The EOR uses a local Polish payroll bureau as a sub-processor to run payroll calculations. Under GDPR, the EOR must have informed the UK company of this sub-processor relationship and ensured the Polish payroll bureau is contractually bound to the same data protection standards.

Common Misconceptions

“A processor can freely add sub-processors without informing the controller.”

No. GDPR requires either general written authorization with notification of changes, or specific written consent for each new sub-processor.

“Sub-processors aren't directly responsible for GDPR compliance.”

No. Sub-processors are bound by the same data protection obligations imposed on the primary processor and can face liability for their own violations.

“Once a sub-processor is engaged, the original processor is no longer responsible.”

No. The original processor remains liable to the controller for the sub-processor's compliance with data protection obligations.

“Sub-processor arrangements are irrelevant to the controller's own compliance.”

No. Controllers should understand their processors' sub-processor chains, since ultimate accountability for how personal data is handled still rests with the controller.

Bottom Line

A sub-processor is a vendor engaged further down the data processing chain, subject to the same GDPR obligations as the primary processor, with the controller's visibility and consent required. Companies using EOR, payroll, or HR services should ask for sub-processor transparency as part of standard due diligence.

Want visibility into your data chain?

We'll map where your employee data flows and make sure every sub-processor meets GDPR standards.

Book a demo