A sub-processor transfer assessment looks beyond your direct supplier to the companies it uses, and asks whether personal data will be adequately protected at every step of the chain, including where it leaves the European Economic Area. Many organizations assess their immediate processor carefully and then discover that the data is also handled by a support provider in one country, a hosting company in another and an analytics vendor in a third. This guide explains how the standard contractual clauses treat sub-processors, how to map the chain, how to assess onward transfers, which questions to ask processors, how to handle changes and how to keep records.
Why sub-processors matter for transfers
Under Article 28 of the GDPR, a processor may engage another processor only with the controller’s prior specific or general written authorization, and must impose the same data protection obligations on the sub-processor by contract. The processor remains fully liable to the controller for the sub-processor’s performance. When a sub-processor is located, or accesses data, outside the EEA, a further transfer occurs, and it needs its own Chapter V safeguard and its own assessment. The Court of Justice’s Schrems II judgment requires that the level of protection be verified for each transfer, so the chain has to be examined link by link.
Our guide to the transfer impact assessment template gives the general structure, and this article adds what is specific to chains.
What the standard contractual clauses say about sub-processors
The Commission’s 2021 standard contractual clauses, adopted by Implementing Decision (EU) 2021/914, contain clauses on sub-processors and onward transfers. You can read the decision on EUR-Lex. In the modules for transfers to processors, the clauses give the parties a choice between specific prior authorization of sub-processors and general written authorization with a defined notice period and an opportunity to object. The importer must give the exporter enough information to exercise its right to object, must have a written contract with the sub-processor providing the same data protection obligations, and must provide a copy of that agreement on request, subject to commercial confidentiality. The clauses also restrict onward transfers to third parties outside the EEA unless the recipient is bound by the clauses or another adequate safeguard applies.
Check which option your contract uses, since it decides whether you approve each sub-processor in advance or can only object after notice.
Mapping the chain for a sub-processor transfer assessment
You cannot assess what you cannot see, so build a map of the data path. Ask your processor for its current list of sub-processors, and for each one obtain the following information.
| Item | What to record |
|---|---|
| Identity | Legal name, address, parent company |
| Role | What service it provides and what processing it performs |
| Data | Categories of personal data it can access or hold |
| Location | Where data is stored, processed and accessed from |
| Transfer mechanism | Adequacy decision, standard clauses or other tool between processor and sub-processor |
| Further sub-processors | Whether it uses others, and where they are |
Include remote support and maintenance access, backups and disaster recovery sites, customer support tools and analytics services. These are common places for unnoticed transfers. Our guide to controller and processor entries in the RoPA shows how to keep the record of who holds what.
Assessing each onward transfer in a sub-processor transfer assessment
For each sub-processor outside the EEA that can reach your data, assess the destination in the same way as for a direct transfer: identify the transfer tool, analyze the law and practice of the country, consider the sub-processor’s own experience with access requests and decide whether supplementary measures are needed. Country-level research can be reused across sub-processors in the same country. See our guide to assessing third-country laws and the article on supplementary measures for data transfers.
Focus your effort by risk
A processor with dozens of sub-processors cannot all be assessed in depth. Prioritize those with access to data in clear form, those in countries with broad government access powers, those that handle sensitive data or large volumes and those that are hard to replace. For low-risk cases, such as a sub-processor that only handles encrypted data and never holds the keys, a shorter record may be enough, provided the reasoning is written down.
Questions to ask the processor
- Which sub-processors handle our data, and where are they located?
- What transfer mechanism is used between you and each sub-processor outside the EEA?
- Can sub-processors access data in clear form, and who holds any encryption keys?
- Have any received government access requests for data of this kind, and how were they handled?
- How and when do you notify changes to the list, and how can we object?
- Do you audit sub-processors, and can you share summaries of the results?
- Can you restrict our data to certain sub-processors or regions?
Keep written answers with the assessment, and follow up where they are incomplete. Our guide to the third-party risk management framework shows how to combine this with wider supplier due diligence.
Handling changes after a sub-processor transfer assessment
Lists change often. Set up a way to receive notices, such as a subscription to the processor’s update page or a named contact, and a process for reviewing them within the notice period. When a new sub-processor is proposed, check whether it involves a new transfer, run the assessment and decide whether to object. Where you object and the processor cannot accommodate you, the contract usually gives a right to terminate, so prepare for the practical consequences of that decision. Record the outcome of each notice, including the decision not to object and the reasons.
Chains inside a corporate group need the same attention, since group companies in different countries are still separate recipients. Our guide to the intra-group transfer impact assessment explains how to handle them.
A short worked example
A company uses a customer support platform hosted in the EU. The provider’s sub-processor list shows a ticketing component run by a subsidiary in a third country without an adequacy decision, and an email delivery service in the United States that is certified under the Data Privacy Framework. The company records the provider’s transfers under the standard clauses, checks the certification of the email service, and obtains a copy of the standard clauses between the provider and its subsidiary. It assesses the third country’s laws and finds broad access powers, so it asks whether the ticketing data can be pseudonymized and whether the subsidiary needs clear text. The provider agrees to restrict support access to named staff and to keep tickets encrypted at rest with keys held in the EU. The company records the assessment and sets a quarterly check of the sub-processor page.
Records for a sub-processor transfer assessment
Keep the current sub-processor list with dates, the authorization option used, notices received and responses, the transfer tool for each link, the assessment for each significant transfer, supplementary measures, correspondence with the processor and the review schedule. Link the record to the supplier file and to your record of processing activities so that changes are picked up in both. Review at least annually and on each notice of change, and record who carried out each review, since a review nobody can identify is easy to dispute later.
Common mistakes in a sub-processor transfer assessment
Organizations look only at the direct processor, accept a static list without checking updates, overlook remote support access, assume the processor’s assurances cover all sub-processors, fail to obtain a copy of the sub-processor contract, do not monitor notices and cannot show that they considered an objection. Another is failing to notice that many sub-processors share the same underlying provider, concentrating exposure.
Using a ready structure
If you want a starting structure for the assessment and register, the Transfer Impact Assessment Report and Workbook provides a structured report, scoring and working register in which each link of the chain can be recorded. Whichever tool you use, make the sub-processor transfer assessment part of your regular supplier oversight, not a one-time exercise at signature.
Sub-processor transfer assessment FAQ
Do I need to assess my processor’s sub-processors?
Where a sub-processor is outside the EEA or can access data from outside it, a transfer occurs and must be covered by a transfer mechanism and assessed. The processor remains responsible, but you must be satisfied that protection is adequate.
Can I object to a new sub-processor?
Under the standard clauses, the parties choose specific authorization or general authorization with notice and an opportunity to object. Check which applies in your contract and follow the process.
Who is liable for a sub-processor’s failure?
The processor remains fully liable to the controller for the performance of its sub-processors, but the controller still has its own duties to verify safeguards.
How do I keep track of changes?
Subscribe to the processor’s notices, name an internal owner, review each change within the notice period and record the decision and reasons.
Can I rely on the processor’s own assessment?
You can use it as input, but as controller you remain responsible for satisfying yourself that the transfer is adequately protected, based on your own analysis of your data and context.