Subprocessor
A company that a processor engages to carry out part of its processing of personal data for a controller, such as a vendor's cloud host or email provider.
Under the GDPR, a processor may engage another processor only with the controller’s prior written authorisation, specific or general. With a general authorisation, the processor must tell the controller about any intended addition or replacement, giving it the chance to object (Article 28(2)). The same data protection obligations must be passed down to the subprocessor by contract (Article 28(4)).
In practice, SaaS vendors name their subprocessors in a list on their website and announce changes there or by email. A new entry can mean customer data reaches a new company, a new country or an AI provider.
Source: GDPR Art. 28(2) and (4) ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.