How to Choose a Subprocessor: Security and Compliance Checklist
A practical GDPR-oriented checklist for assessing a subprocessor’s security, contracts, transfers, and ongoing oversight.
To choose a subprocessor, first map what personal data it will handle and the risks of that processing. Then verify that it can provide sufficient guarantees for the specific work, confirm the processor has the required written authorisation and contract protections, assess security and transfer safeguards, and document the decision. Reassess when the service or subprocessor chain changes.
This checklist is oriented to UK GDPR and EU GDPR. Requirements depend on jurisdiction, sector, contract, and processing facts; confirm the applicable rules before relying on it as legal advice. The ICO says its guidance is under review following the Data (Use and Access) Act, so check current official guidance before making a decision.
1. Map the processing before reviewing the provider
A certificate or a general claim of compliance cannot answer whether a provider is suitable for this particular processing. Establish the provider’s role and the data flows first. The controller remains responsible for assessing sufficient guarantees in context.
Ask the internal service owner and the processor to document:
- Parties and instructions: Who is controller, processor, and proposed subprocessor? Who gives documented instructions, and what work is delegated?
- Purpose and activity: What service will the subprocessor deliver, and what operations will it perform on personal data?
- Data and people: Which personal-data categories and data subjects are involved? Identify special-category, criminal-offence, children’s, financial, or other especially sensitive data.
- Duration and access: For how long will processing occur? Which systems, staff, and access paths are involved?
- Locations and onward chain: Where are data stored or accessed, and which further subprocessors or international transfers are expected?
- Change and exit: What happens to the data if the service changes or ends? How will return, export, and deletion be handled?
These details make it possible to judge whether the provider’s guarantees and measures fit the actual processing. The ICO guidance on controller responsibilities says the assessment should account for the nature of processing and risks to people.
2. Verify security and privacy guarantees
Collect evidence in proportion to the processing risk. Industry standards, technical expertise, assistance capability, privacy and security documentation, and adherence to a code of conduct or certification scheme can all inform the assessment. None is an automatic pass or fail by itself.
| Area | What to check |
|---|---|
| Governance | Security ownership, relevant policies, risk assessment, and accountability for this service. |
| Access and people | Identity management, least privilege, privileged access controls, personnel confidentiality, and access review. |
| Data safeguards | Encryption and pseudonymisation where appropriate, plus controls protecting confidentiality and integrity. |
| Availability and recovery | Resilience of processing systems, backup, recovery, and restoration of access after an incident. |
| Testing | Security testing and assessment processes; scope, recency, findings, and remediation evidence. |
| Incident support | Detection, escalation, investigation, notification workflow, and practical support to the controller. |
| Chain oversight | A current subprocessor inventory, oversight approach, and communication of intended changes. |
| Transfers | Data locations, access locations, transfer mechanism, supporting documentation, and safeguards where needed. |
| Controller assistance | Support for individual rights requests, impact assessments, and other controller obligations. |
| Exit | Data return or export, deletion at termination, treatment of backups where applicable, and evidence of completion. |
Article 32 measures, as described by the ICO security guidance, include as appropriate encryption or pseudonymisation, ongoing confidentiality, integrity, availability and resilience, restoration after an incident, and regular testing and assessment.
3. Confirm authorisation and contract flow-down
The processor needs the controller’s prior written authorisation to engage a subprocessor. Establish which model the existing controller-processor arrangement uses:
- Specific written authorisation: The controller approves this particular subprocessor for the relevant processing.
- General written authorisation: The controller approves a list or criteria. The processor must notify the controller of intended additions or replacements and provide an opportunity to object.
Check that the arrangement addresses applicable Article 28 terms: documented instructions, confidentiality, security, subprocessor engagement, assistance with data-subject rights and controller obligations, return or deletion at contract end, and audit and inspection rights. The processor-subprocessor contract must pass down the required data-protection obligations and provide an equivalent level of protection. Under the ICO’s UK GDPR guidance, the processor remains liable to the controller for the subprocessor’s compliance.
For EU arrangements, Commission Implementing Decision (EU) 2021/915 provides standard contractual clauses for controller-processor arrangements. Treat them as a drafting resource to assess against the actual processing and governing law, not as a substitute for reviewing the provider and contract.
4. Scale verification to risk
The EDPB’s Opinion 22/2024 says verification applies regardless of risk, while its extent varies with the measures involved and the risk. A controller may use information supplied by its processor and build on it when it is incomplete, inaccurate, or raises questions. Higher-risk processing calls for increased verification. There is no general duty to request every subprocessing contract systematically; whether to review one is a case-by-case accountability decision.
The following evidence ladder is a practical way to organise that work, not a mandated sequence:
- Review current policies, service description, data-flow details, and security documentation.
- Check assurance reports, certificates, or code adherence for scope, exclusions, dates, and relevance to the service being assessed.
- Ask targeted follow-up questions where evidence is incomplete or does not cover the processing.
- For higher risk, consider deeper technical review, independent audit material, or downstream contract review where needed.
- Record evidence reviewed, uncertainty, mitigations, approver, and review date.
Do not treat a certification as covering systems, locations, or services outside its stated scope. A report that is old, excludes the relevant service, or leaves a material control unanswered may need follow-up.
5. Compare candidates consistently
If there is more than one candidate, apply the same criteria to each and weight them according to the processing:
| Comparison axis | Evidence to compare |
|---|---|
| Processing fit | Role clarity, service scope, purpose, data types, locations, and ability to follow instructions. |
| Security | Relevant controls, assurance scope, incident handling, resilience, and recovery. |
| Contract | Authorisation model, equivalent downstream obligations, assistance, audit, and exit terms. |
| Transparency | Named subprocessors, current information, notice period, and objection process. |
| Transfers | Countries, transfer mechanism, supporting documentation, and supplementary safeguards where needed. |
| Operational support | Rights requests, incident support, impact assessments, and cooperation with the controller. |
| Exit and continuity | Data return or export, deletion, service continuity, and evidence of completion. |
| Evidence quality | Coverage, independence, recency, exclusions, and fit to the service assessed. |
6. Review international transfers
Follow the actual data flows. A subprocessor’s registered location alone does not determine whether a restricted transfer occurs; consider where data are stored, accessed, and made available. If personal data move outside the EEA, identify the transfer mechanism and assess relevant documentation and safeguards. Depending on the circumstances, this may include the transfer ground, a transfer impact assessment, and supplementary measures. Apply the transfer rules for the relevant jurisdiction and the actual arrangement.
7. Manage transparency and changes
Keep the identity of each processor and subprocessor readily available, with enough information to understand its role in the processing chain. The EDPB says processors should proactively provide this information and keep it current.
- Assign an owner to receive and track subprocessor change notices.
- Before a change takes effect where the arrangement allows, assess the new provider’s role, data access, locations, guarantees, and contract flow-down.
- Apply the agreed objection process and capture the decision, conditions, or remediation actions.
- Set review triggers for a material service change, new data type, location change, security incident, or change in the subprocessor chain.
8. Keep a decision record
Use this template to create an auditable record. Add links to the evidence and note its scope and date, rather than recording only that a document was received.
Proposed subprocessor and service:
Processing purpose, data, subjects, duration, and locations:
Controller authorisation route and date:
Risk level and reasons:
Evidence reviewed, scope, dates, and limitations:
Security and privacy gaps and mitigations:
Contract and downstream flow-down confirmed:
Transfers and safeguards reviewed:
Decision, owner, approver, and date:
Conditions, objection deadline, or remediation actions:
Next review trigger/date:
9. Common assessment problems
| Problem | Why it is a problem | Practical response |
|---|---|---|
| “The provider is compliant.” | A broad claim does not show sufficient guarantees for this service and data. | Request scoped evidence, map the processing, and document the fit and gaps. |
| A certificate is treated as blanket approval. | Its scope, exclusions, date, and covered service may not match the proposed processing. | Read the scope and seek focused follow-up for uncovered controls. |
| Only the provider’s country is checked. | Storage location alone may not describe access or the relevant transfer path. | Map storage, access, onward transfers, and applicable safeguards. |
| The change notice has no clear owner. | A general authorisation process can fail operationally if notices are missed or objections cannot be assessed in time. | Assign an inbox or owner, deadline tracking, reviewer, and escalation path. |
| Every subprocessing contract is requested by default. | The EDPB does not describe a general systematic request duty; the need is case-specific. | Decide whether contract review is needed based on risk, gaps, and accountability evidence. |
| No exit evidence is collected. | Return, export, deletion, and backup treatment can remain unclear at termination. | Confirm contractual terms and specify how completion will be evidenced. |
10. Keep the assessment efficient and reliable
Start with the processing map and a consistent evidence request. This reduces repeated questions and exposes missing information early. Reuse current assurance material where its scope fits, then direct follow-up at gaps rather than collecting documents without a decision purpose.
For reliability, record document dates and scope, preserve the source of each assurance claim, and make uncertainty visible. Tie review dates to actual change triggers as well as a scheduled review appropriate to the processing. No universal review interval is specified in the cited material, so set it based on risk, contract, and operational change rate.
Cost the assessment by the exposure and consequence of the processing. Deeper technical or contract review takes more staff or specialist time, so reserve it for higher-risk processing or unresolved material gaps. The cited guidance does not provide a standard cost or fixed effort estimate.
Or skip the browser setup
For a related task such as capturing a provider’s public security or privacy documentation as a review artifact, ScreenshotNeo is a website screenshot API and MCP server for developers. Its one-call API can save a page as an image or PDF; see the ScreenshotNeo documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', res);
- Cookie banners are accepted like a visitor and 60+ known consent platforms, newsletter popups, and chat widgets are removed before capture; each step can be turned off.
- Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers identify the page verdict and billing status.
- An MCP server gives AI agents tools to take screenshots, get page information, and capture PDFs.
- 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000. Every feature is on every plan.
Sign up for ScreenshotNeo: get 1,000 free screenshots a month with no card.
Frequently asked questions
How do I choose a subprocessor?
Map the processing and risks, verify guarantees that fit the work, confirm prior written authorisation and downstream terms, assess transfers and assistance, then document the decision and review triggers.
What should I ask a subprocessor?
Ask what service it performs, what data and systems it can access, where processing occurs, what security and incident controls apply, which providers it depends on, how it supports controller duties, and how data are returned or deleted.
What should a subprocessor security checklist include?
At minimum, cover processing scope, governance, access, confidentiality, data safeguards, resilience and recovery, testing, incidents, onward providers, transfers, assistance, contract flow-down, and exit.
Do I need to approve my processor’s subprocessors?
The processor needs prior specific or general written authorisation from the controller. Under a general authorisation arrangement, the processor must notify intended changes and give the controller an opportunity to object. Check the applicable contract and law for the process and timing.
Do I need to review every subprocessing contract?
The EDPB says there is no general duty to systematically request every such contract. Decide case by case whether reviewing one is necessary to address the risk or demonstrate accountability.


