ScreenshotNeo

BlogGuides

What Is a Subprocessor? Definition, Examples, and Responsibilities

A subprocessor handles personal data on behalf of a processor. Learn how the GDPR approval, contract, oversight, and liability rules work.

By the ScreenshotNeo team4 October 202610 min read

A subprocessor is a processor engaged by another processor to handle personal data on that processor’s behalf and under its instructions. Under EU GDPR Article 28, the processor needs the controller’s prior specific or general written authorisation, must flow down relevant data protection obligations, and remains fully liable to the controller for the subprocessor’s performance.

The controller sits at the top of the relationship: it determines why and how personal data is processed. The processor acts for the controller. A subprocessor acts for the processor. The label alone does not settle a provider’s role; examine what data it handles, whose purposes it serves, and whose instructions it follows.

1. What is a subprocessor?

A subprocessor is a downstream processor in a personal-data processing chain. It may perform part of a service that the original processor provides to a controller, such as hosting or another operation involving the controller’s personal data.

The European Data Protection Board’s small-business guide describes a processor as an entity that processes personal data on behalf of a controller and follows the controller’s instructions. A subprocessor similarly follows instructions, but they come from the processor that engaged it. Either role may be held by a company, public authority, agency, or other body.

“Subprocessor” is common shorthand. The UK Information Commissioner’s Office (ICO) says the term itself is not used in the UK GDPR. The useful question is what the provider actually does in the processing relationship.

2. What is the difference between a controller, processor, and subprocessor?

Role Whose purposes or instructions guide the processing? Position in the chain
Controller Determines the purposes and means of processing. Decides why and how personal data is processed.
Processor Processes data on the controller’s behalf, following the controller’s instructions. Engaged by the controller.
Subprocessor Processes data on the processor’s behalf, following the processor’s instructions. Engaged by a processor; may itself use another processor downstream.

A simplified chain is:

Controller → Processor → Subprocessor → (possibly another processor)

For example, a publisher may decide to use a mailing company to handle magazine subscriptions. The publisher is the controller and the mailing company may be its processor. If that mailing company uses another provider to process the entrusted subscriber information on its behalf, that provider may be a subprocessor. The actual service, data flow, instructions, and contracts determine the classification.

3. What are examples of subprocessors?

Common arrangements can include a processor using a separate service to perform part of its processing work. The label depends on the particular service and arrangement, not just the industry or product category.

  • Cloud services: An organisation may use a cloud provider to store and analyse its data. The ICO gives this as an example of a controller–processor relationship. If the cloud provider in turn uses another service to process the entrusted personal data on its behalf, that downstream service may be a subprocessor.
  • Mailing operations: A publisher may ask a separate company to handle magazine subscriptions and home mailings. A further provider used by the mailing company to process that personal data could sit downstream as a subprocessor.
  • Marketing campaigns: A business may ask a marketing company to send offers to its customers. If the marketing company uses another provider to process the customer information on its behalf, that provider may be a subprocessor.

These are illustrations of roles, not findings about any named provider. A company may act as a controller for one activity and a processor for another. Review the data and service involved rather than relying on a company’s marketing description.

4. Does a controller have to approve subprocessors?

Under EU GDPR Article 28(2), a processor must not engage another processor without the controller’s prior specific or general written authorisation.

The two approaches work differently:

Authorisation method How it works What to check
Specific written authorisation The controller approves a particular downstream provider and the relevant engagement. Whether the approval describes the provider and processing clearly enough for the arrangement.
General written authorisation The controller authorises a defined approach or set of subprocessors. The processor must notify the controller of intended additions or replacements and give the controller an opportunity to object.

General authorisation is not permission to make invisible changes. The change-notice and opportunity-to-object process still matters. The parties should make clear how notices are delivered and how the controller can raise an objection.

EDPB Opinion 22/2024 says controllers should have current information identifying the processors and subprocessors in the chain. Relevant information includes a provider’s name, address, contact person, and description of its processing. For a proposed subprocessor, also clarify relevant processing locations and safeguards so the controller can assess the change.

5. What should be in a subprocessor agreement?

Article 28(4) requires the processor to impose on the subprocessor the relevant data-protection obligations from the controller–processor relationship through a contract or other permitted legal act. The subprocessor must provide sufficient guarantees for appropriate technical and organisational measures.

The downstream wording does not have to be identical to the upstream contract, but it must preserve the required level of protection. The agreement and related operational process should cover the obligations relevant to the processing, including:

  • Scope: the processing activity, purposes, duration, personal-data categories, and data-subject categories assigned to the subprocessor.
  • Identity and access: the subprocessor’s legal identity, contact point, relevant processing and access locations, and any onward processing arrangements.
  • Instructions and confidentiality: how the subprocessor follows the processor’s documented instructions and ensures that authorised people are subject to confidentiality obligations.
  • Security: the technical and organisational measures and the evidence supporting the subprocessor’s sufficient guarantees.
  • Assistance: support for data-subject rights requests, personal-data breaches, and data protection impact assessments where relevant.
  • Changes: the authorisation method, advance notice of intended additions or replacements where general authorisation applies, and a practical route for objections.
  • Transfers: relevant international transfers, transfer safeguards, and remote access arrangements where applicable.
  • Audit and assurance: information needed to demonstrate compliance, available assurance materials, and audit rights or access consistent with the applicable contract and law.
  • End of service: deletion or return of personal data and copies at the end of the service, subject to applicable legal requirements.
  • Incident handling: escalation contacts, timing, and cooperation so the processor can meet its own obligations.

This is a practical review list, not a substitute for the contract or advice on a particular arrangement. The ICO describes processor terms concerning security, assistance with individual rights, breach and impact-assessment support, deletion or return, and audit information and access.

6. Who is liable if a subprocessor has a data breach?

There is no single answer that makes every party’s obligations disappear. The responsibilities operate at different links in the chain.

  1. The initial processor remains fully liable to the controller for the subprocessor’s performance of its data-protection obligations under GDPR Article 28(4).
  2. The controller retains its own compliance duties. These include selecting processors that provide sufficient guarantees and being able to demonstrate its compliance and oversight.
  3. The subprocessor may have direct obligations and exposure under applicable law. The ICO explains that, in the UK, a subprocessor may be liable for damage where it breaches processor-specific UK GDPR obligations or acts against lawful instructions relayed through the processor. Contractual recourse also depends on the contract.

A breach does not automatically establish who owes compensation or what remedy applies. The answer depends on the facts, the applicable law, the parties’ conduct, and their contracts. Outsourcing processing does not transfer all responsibility to the downstream provider.

7. How should a controller review a subprocessor change?

Use a repeatable review so the authorisation is meaningful and the processing chain stays visible:

  1. Identify the change. Record the subprocessor’s legal name, contact person, address, and the processing it will perform.
  2. Map the data and access. Note personal-data categories, data subjects, processing locations, remote access, and any further downstream providers.
  3. Check the authorisation route. Confirm whether the controller gave specific or general written authorisation and, for a general authorisation, whether the required notice and opportunity to object are available.
  4. Review guarantees and safeguards. Assess relevant technical and organisational measures and any transfer safeguards against the processing and its risks.
  5. Check the contract flow-down. Confirm the relevant upstream protections are imposed on the subprocessor and that the processor can obtain information or assistance needed to meet its duties.
  6. Keep the record current. Update the processing-chain inventory and preserve the notice, review, decision, and relevant assurance information.

EDPB Opinion 22/2024 says the extent of verification may vary with the nature of the measures and the risk, while the duty to verify sufficient guarantees applies regardless of risk. A lower apparent risk does not remove the need to check guarantees.

8. Does the same rule apply in the UK and other countries?

The EU GDPR and UK GDPR have parallel Article 28 frameworks for engaging another processor, flowing down protections, and allocating responsibilities. The ICO’s relevant guidance says it is under review following the Data (Use and Access) Act, so check current UK guidance before relying on it.

Do not assume that every national, non-EU, non-UK, or sector-specific privacy regime uses identical definitions, approval rules, or liability provisions. For a real processing chain, check the law that applies to the parties and data, along with any sector rules and contract terms.

9. Where ScreenshotNeo fits in a processing chain

For developers capturing website screenshots, ScreenshotNeo is a website screenshot API and MCP server made by Yorker Media. Whether a provider is a processor or subprocessor depends on the actual service, personal data involved, instructions, and contracts; a product description alone does not determine the legal role. Review the applicable terms and processing details for your arrangement.

For documentation and API details, see the ScreenshotNeo documentation. The service offers 1,000 screenshots per month free with no card; paid plans start at $5 for 3,000 shots, and every feature is on every plan.

Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.

10. Troubleshooting a subprocessor review

Problem Why it happens What to do
A provider’s role is unclear. Teams rely on a product name or vendor label instead of tracing the actual processing. Map the personal data, activity, purpose, and instructions. Determine whether the provider acts for the controller, a processor, or for its own purposes.
A new provider appears without a clear approval record. The parties may have overlooked the prior written authorisation requirement or failed to retain it. Check the controller–processor terms and approval records. Establish the applicable specific or general authorisation process before the engagement, and document the outcome.
The controller receives a change notice but cannot assess it. The notice omits identity, processing details, locations, or safeguards. Request the missing information and keep the current chain inventory complete so the controller can assess and, where applicable, object.
The subprocessor contract has weaker protections. Downstream terms were copied incompletely or do not address the relevant processing. Compare the downstream obligations with the applicable upstream requirements and add the relevant protections and assistance duties.
The processor assumes the controller’s approval removes its responsibility. Authorisation is confused with the processor’s continuing accountability. Keep the processor’s Article 28(4) liability and the controller’s own compliance duties visible in the contract and operating process.
The provider uses remote access or another downstream service that is not listed. The inventory tracks storage location but not access or onward processing. Ask about access locations, support access, and further subprocessors; assess transfer implications and update the chain record.
A team treats a general approval as blanket permission for future changes. The change-notice and objection steps were not designed or followed. Set a clear notice route and sufficient opportunity for the controller to assess intended additions or replacements and object.

11. Performance, reliability, and cost considerations

Subprocessor oversight is an ongoing operational process, not only a contract signature. Keep the provider inventory current, assign an owner to review changes, preserve notice and approval records, and know how to reach each provider during an incident. These practices make it easier to understand where personal data flows and which party must act.

For cost and procurement, compare the work needed to assess safeguards, maintain notices, answer audits, manage transfers, and support deletion or return at the end of service. The dossier does not establish a standard price or performance benchmark for subprocessors; those depend on the service and contract. Assess the actual processing and evidence rather than assuming a lower price or a familiar vendor name establishes suitability.

12. Frequently asked questions

Can a subprocessor appoint another subprocessor?

A further downstream processor may be engaged only subject to the applicable authorisation and contractual requirements. Make sure the chain and change process cover onward processing.

Does every vendor a processor uses count as a subprocessor?

No. The role depends on whether the vendor processes personal data on behalf of the processor under its instructions. A supplier that does not perform that kind of processing may have a different role.

Does the subprocessor contract need to copy the main processing agreement word for word?

No. The wording need not be identical, but it must impose the relevant obligations and preserve the required level of protection.

Is a subprocessor list enough to meet oversight duties?

A list helps make the chain visible, but the controller also needs sufficient information to assess the processing and guarantees, and the processor must follow the applicable authorisation and change-notice process.

Does this explanation settle a specific contract or jurisdiction?

No. This article explains the EU GDPR framework and cites UK ICO guidance separately. Check current local law, sector rules, facts, and contract terms for a particular arrangement.

Sources

This article is a practical explanation of the cited framework, not legal advice. Verify current guidance and the law applicable to your processing arrangement.