Skip to content

Subprocessor

Definition

A third party engaged by a vendor (the processor) to perform part of the service that involves the organisation's data. Under GDPR and India's DPDP Act 2023, the controller's data protection obligations flow down to subprocessors, so a TPRM programme must extend to subprocessors of critical vendors, not just the vendor itself.

Role
Third party engaged by a vendor to perform part of a service
Regulatory context
GDPR, India's DPDP Act 2023
Obligation flow
Controller's data protection duties extend to subprocessors
Programme scope
TPRM must cover subprocessors of critical vendors

Common questions

Why can't an organisation just trust its direct vendor's data protection promises?+

A vendor's promises only cover what the vendor itself does with the data, but a subprocessor further down the chain may have weaker controls, different jurisdiction, or its own further subcontractors. Regulators treat the controller as accountable for the whole chain, which is why due diligence has to extend past the first-tier vendor.

What does GDPR require regarding subprocessors specifically?+

It requires the processor to obtain the controller's authorisation before engaging a subprocessor, flow down the same data protection obligations contractually, and remain liable to the controller for the subprocessor's performance. Failure to do this properly is a common finding in vendor risk audits.

Related terms

Due Diligence Questionnaire (DDQ)
A structured questionnaire sent to a prospective vendor before onboarding, asking the vendor to describe its security controls, certifications, incident history, subprocessor...
Offboarding Controls
The set of actions taken when a vendor relationship ends: revoking access credentials, recovering or destroying shared data, terminating network connectivity, and...
Right-to-Audit Clause
A contractual provision that gives the organisation the right to audit or assess the vendor's security controls, either directly or through a...
Third-Party Risk
The information security, operational, legal, or reputational risk introduced to an organisation by its relationships with external parties including vendors, suppliers, cloud...
Vendor Tiering
The classification of vendors into risk tiers, typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low), based on factors such...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.