Subprocessor Management: The Subprocessor List and GDPR Subprocessor Duties
Your vendors have vendors. Every one of them that touches personal data on your behalf is a subprocessor, and the chain is longer than the list you maintain. When an access or deletion request arrives, that chain is the set of places you are accountable for searching, whether or not you can name everyone in it.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
A subprocessor is a vendor engaged by your processor to help it deliver the service you bought, where that vendor also handles personal data you are responsible for. Your support desk runs on someone else's cloud. Your payroll provider sends payslips through an email delivery service. Your analytics tool routes events through a data pipeline vendor. None of those companies signed a contract with you, and all of them hold data about your customers and employees.
GDPR Article 28(2) says a processor shall not engage another processor without prior specific or general written authorization from the controller, and that under a general authorization the processor must inform you of any intended changes concerning the addition or replacement of other processors, giving you the opportunity to object. Article 28(4) requires the same data protection obligations to be imposed on the subprocessor by contract, and adds the part that matters when something goes wrong: where the other processor fails to fulfil its data protection obligations, the initial processor remains fully liable to the controller for the performance of that other processor's obligations.
The EDPB raised the bar in Opinion 22/2024, adopted in October 2024. Its position is that a controller should have the identity of every processor and subprocessor in the chain readily available, including name, address and a contact person, so that it can demonstrate compliance and act on data subject requests. Not just the vendors you signed with. The whole chain. Where the processing is high risk, you are expected to go further than reading what the processor tells you and actually check that the guarantees hold.
US state law is thinner and more uneven. Colorado at C.R.S. 6-1-1305(5) is the only state that gives you a say before the fact: a processor may engage a subcontractor only after giving the controller an opportunity to object, and then only under a written contract carrying the processor's own obligations. Virginia at 59.1-579(B), Texas at 541.104, Utah at 13-61-301 and Iowa at 715D.5 all require the flow-down contract and none of them require prior notice or an objection window. California does not use the word subprocessor at all: 11 CCR 7051(b) requires subcontracts to comply with the same rules, and because a recipient without a compliant contract is not a service provider or contractor, an undisclosed link in the chain can turn a routine vendor transfer into a sale or sharing you have to offer an opt-out for.
All of that is contract work. The operational half is different, and it is the half with a clock on it: when a request lands, you have between 30 and 45 days to say what you hold about one person, and the honest scope of that search is the chain, not the vendor list.
Obtainer covers the operational half. It intakes the request, searches your product database, warehouse, support desk, billing, marketing and vendor systems, reports the source system behind every record it surfaces, compiles one reviewable manifest, tracks the statutory deadline, and keeps a timestamped record of what was searched and when. That record is what reconciles the list you maintain against the systems that actually hold data. Nothing is disclosed or erased automatically. A human reviews, redacts and approves. Obtainer helps you comply. It is not legal advice, so authorizing a subprocessor, objecting to one, and judging whether its guarantees are sufficient stay with your team. Self-serve from a planned $49/mo.
Last updated August 2026
Why it fits
Privacy, legal, and vendor management teams who have to name every party holding data and then search them.
The subprocessor list is your search scope, not a compliance artifact
Teams maintain the list because a customer questionnaire asks for it, then file it. Read it the other way around and it is the answer to the only question that matters when a request arrives: where does this person's data actually live? Every entry is a system you may have to search and a party you may have to ask. The list drifts quietly, through a free trial that became production, a departmental card, an integration switched on for one project, or a vendor that changed its own hosting provider. When the list and reality diverge you get responses that are incomplete in ways nobody notices until a regulator or the data subject notices for you. Obtainer reports the source system behind every record it surfaces, which is how the maintained list gets reconciled against evidence rather than against memory.
Liability flows to your processor. The deadline still runs against you.
Article 28(4) is genuinely useful: if a subprocessor fails, your processor stays fully liable to you for its performance, so you are not left chasing a company you never contracted with. What that clause does not do is buy you time. The GDPR one-month clock and the 45-day state clocks run against you while you wait for a vendor to ask its vendor. You are the one who has to answer, on the date, whether or not the fourth party down the chain replies. Which is why the practical question is never who is liable. It is how much of your deadline you can afford to spend asking, and how much of the answer you can get without asking at all.
Colorado is the only state that lets you object before the fact
Under C.R.S. 6-1-1305(5) a processor may engage a subcontractor only after giving the controller an opportunity to object, and then under a written contract requiring the subcontractor to meet the processor's own obligations. That mirrors GDPR Article 28(2), and no other US state has it. Virginia, Texas, Utah and Iowa all require the flow-down contract and give you no notice and no veto, so the chain can lengthen without anything reaching you. Practically, that means your objection rights come from the agreement you negotiated rather than from the statute, in every state but one. Worth knowing before you accept a vendor DPA that reserves the right to update its subprocessor list on its own website.
More use cases
Related features
Questions
Common questions about this
What is a subprocessor?
A subprocessor is a third party engaged by your processor to process personal data on your behalf as part of delivering the service you bought. If you use a support desk and that support desk hosts its data with a cloud provider and sends notification emails through a delivery service, both of those are your subprocessors. You have no direct contract with them. Under GDPR Article 28(4) your processor must impose the same data protection obligations on them and stays fully liable to you if they fail.
What is the difference between a processor and a subprocessor?
Position in the chain, not function. A processor is engaged directly by the controller and processes personal data on the controller's documented instructions. A subprocessor is engaged by that processor to help it perform the service, and it processes the same data one step further down. Both are processors under the GDPR and both are bound by the same categories of obligation. The practical difference is that you sign with the processor and only ever reach the subprocessor through it.
What is the difference between a subprocessor and a subcontractor?
Mostly vocabulary. The GDPR says another processor and the industry says subprocessor. US state privacy laws say subcontractor: C.R.S. 6-1-1305(5) and Va. Code 59.1-579(B) both use that word for the same relationship. A subcontractor in the ordinary commercial sense is any party your vendor hires, including ones that never touch personal data, such as a cleaning company. Only the ones that process personal data on your behalf carry the privacy obligations, so the privacy question is what the subcontractor handles rather than what it is called.
Does GDPR require a subprocessor list?
It does not use those words, but the effect is close. Article 28(2) requires prior specific or general written authorization before your processor engages another, and under a general authorization the processor must inform you of intended additions or replacements so you can object, which only works if there is a list to compare against. EDPB Opinion 22/2024 goes further and takes the position that a controller should have the identity of every processor and subprocessor in the chain readily available, including name, address and a contact person. In practice that is a subprocessor register, and it is your obligation rather than your vendor's.
Do you need consent to add a subprocessor?
You need authorization from the controller, which is not the same as consent from the individual. Article 28(2) allows it to be specific, naming the subprocessor, or general, permitting additions subject to notice. Almost every SaaS vendor uses the general form: it publishes a subprocessor list, commits to a notice period before changes, and gives the customer a window to object. Whether an objection actually stops the change depends on what the agreement says happens next, and many say only that you may terminate. Read that clause before you rely on it.
Does the CCPA have subprocessor requirements?
Yes, under a different name. California has no processors, so there is nothing called a subprocessor in the regulations. What 11 CCR 7051(b) does is require that a service provider or contractor which engages another entity to help it perform its services enters a contract that complies with the same rules. The consequence sits in 7051 itself: a person without a contract complying with subsection (a) is not a service provider or contractor, and the business's disclosure of personal information to that person may be considered a sale or sharing for which the consumer must be given an opt-out. A broken link in the chain is not just a paperwork gap in California.
Who is liable if a subprocessor causes a data breach?
Under the GDPR, Article 28(4) makes your processor fully liable to you for the subprocessor's performance of its data protection obligations, so your contractual recourse runs to the party you signed with. That does not make you a bystander. As controller you remain responsible for having used only processors providing sufficient guarantees under Article 28(1), for your Article 33 breach notification duties, and for the security of the processing overall. In the US state laws the point is made directly: the Colorado Privacy Act says a contract may not relieve a controller or a processor of the liabilities imposed by its role.
How do subprocessors affect a data subject access request?
They set the true scope of the search. A request asks what you hold about a person, and data held by a subprocessor on your behalf is still data you hold. So the honest answer covers systems you do not operate and, in some cases, companies you never contracted with, while the one-month GDPR clock and the 45-day state clocks run against you. That is why maintaining the chain matters operationally rather than as paperwork: it tells you where to look first, which vendors you have to ask, and how much of the deadline you can afford to spend waiting for a reply.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.