Glossary

Sub-processor

A sub-processor is any third-party service that processes personal data on your behalf while you process it on your customer’s behalf. If your customer is the controller and you’re the processor, your cloud provider, email service, support desk, and analytics tooling are sub-processors — a chain of data handling that privacy law makes you responsible for.

Your obligations

Under GDPR (and mirrored in most DPAs), you must maintain a public or on-request list of sub-processors, flow down equivalent data-protection obligations to each one via their DPAs, and notify customers before adding or changing sub-processors — typically with a window to object. That notification mechanism (mailing list, RSS, trust-page changelog) is a real operational commitment, not legal boilerplate.

Why security reviews care

Your security posture is bounded by your weakest sub-processor. Enterprise reviewers cross-check your sub-processor list against your architecture claims, and an undisclosed sub-processor discovered mid-review reads as either sloppiness or concealment. Keep the list accurate, minimal, and reviewed whenever engineering adopts a new tool — shadow SaaS has a habit of becoming an undisclosed sub-processor.

Related Terms

Business Associate Agreement — A BAA is the HIPAA-required contract between covered entities and vendors handling PHI — what it must contain and why missing BAAs trigger enforcement.

Data Processing Agreement (DPA) — A DPA is the contract governing how a processor handles personal data on a controller's behalf — required under GDPR whenever a vendor touches personal data.