What Is a Sub-processor?
A sub-processor is a third party that a data processor engages to handle personal data on its behalf, as part of delivering a service to the original data controller. Under GDPR, sub-processors must be bound by the same data protection obligations as the primary processor, and the controller must be informed of their use.
A data processor cannot simply bring in a sub-processor without notice; GDPR requires either the controller's prior written authorization or, at minimum, advance notification with the chance to object.
Sub-processor at a Glance
| Attribute | Description |
|---|---|
| Definition | A third party processing data on behalf of a data processor |
| Legal Basis | Article 28(2) and (4), GDPR |
| Authorization Required | Controller's general or specific written consent |
| Contractual Requirement | Same data protection obligations flow down to the sub-processor |
| Common Examples | Cloud hosting providers, payroll sub-vendors, IT support services |
| Liability | The original processor remains liable for the sub-processor's compliance |
Why Does It Matter?
Modern service delivery, especially payroll, HR tech, and EOR services, often relies on layers of vendors behind the scenes. If a processor engages a sub-processor without proper authorization or fails to impose equivalent data protection terms on them, both the processor and, indirectly, the controller face compliance risk. Understanding the sub-processor chain is essential for companies that want visibility into where their employee data actually goes.
When Is It Used?
Sub-processor rules become relevant whenever a company:
- Uses an EOR, payroll provider, or HR platform that in turn relies on other vendors, such as cloud hosting or local payroll processing partners.
- Needs to review a vendor's sub-processor list before signing a service agreement.
- Requires notification rights over any new sub-processor a vendor plans to engage.
A UK company hires employees in Poland through an Employer of Record. The EOR uses a local Polish payroll bureau as a sub-processor to run payroll calculations. Under GDPR, the EOR must have informed the UK company of this sub-processor relationship and ensured the Polish payroll bureau is contractually bound to the same data protection standards.
Common Misconceptions
No. GDPR requires either general written authorization with notification of changes, or specific written consent for each new sub-processor.
No. Sub-processors are bound by the same data protection obligations imposed on the primary processor and can face liability for their own violations.
No. The original processor remains liable to the controller for the sub-processor's compliance with data protection obligations.
No. Controllers should understand their processors' sub-processor chains, since ultimate accountability for how personal data is handled still rests with the controller.
A sub-processor is a vendor engaged further down the data processing chain, subject to the same GDPR obligations as the primary processor, with the controller's visibility and consent required. Companies using EOR, payroll, or HR services should ask for sub-processor transparency as part of standard due diligence.
Want visibility into your data chain?
We'll map where your employee data flows and make sure every sub-processor meets GDPR standards.
AUG (Authorized User Group) Certified
IND Recognised Sponsor
Nasscom Certified
SNA Certified
Nasscom Certified