Sub-Processor Clause

A clause in a data processing addendum that governs when and how a vendor may hand the customer's personal data to a downstream provider, and on what conditions.

Reviewed by

GC AI Solutions Team

Updated

September 2026

Definition

A sub-processor clause governs when and how a processor, usually your vendor, may engage a downstream provider, a sub-processor, to help process your personal data. Under GDPR Article 28, a processor cannot use a sub-processor without the controller's prior authorization, which is either specific to each sub-processor or general, based on a maintained list with advance notice of changes and a right to object. The processor must flow down equivalent data-protection obligations by contract and remains fully liable to the controller for the sub-processor's performance. It is a defined part of a data processing addendum.

What It Does

For in-house counsel, review the sub-processor clause against the data-protection commitments your company has made to its customers. A practical test: choose a proposed addition to the vendor's list and trace the notice, objection process, available remedy, and obligations that will bind the new provider.

  • Sets how sub-processors are authorized, by specific consent or general authorization

  • Requires advance notice of additions or replacements under general authorization, with an agreed period that allows the controller to assess and object

  • Gives the controller a right to object to a new sub-processor

  • Flows down equivalent data-protection obligations to the sub-processor

  • Keeps the processor liable to the controller for the sub-processor's acts

General authorization from a maintained list, with advance notice and an objection process, is one available model; specific authorization requires approval of each proposed sub-processor.

When You'll See It

Sub-processor terms appear in data processing addenda, SaaS and cloud agreements with a data-processing section, and vendor security exhibits, in any arrangement where a vendor processes personal data on your behalf. The clause sits inside or alongside the DPA, near the security, breach-notification, and international-transfer provisions. The list of sub-processors is often maintained at a URL rather than written into the contract, with the contract setting the rules for changing it.

It matters most where you are a controller passing personal data to a processor and you, in turn, owe data-protection commitments to your own customers or to regulators. The longer the processing chain and the more sensitive the data, the more the authorization model, the objection right, and the flow-down decide whether your obligations reach the bottom of the chain.

Examples

Relativity ODA LLC / KLDiscovery Ontrack, LLC

Data Processing Agreement (UK SCCs)

General authorization from a list, with 30-day notice and objection

One-Sided

2023

"The processor has the controller’s general authorisation for the engagement of sub-processors from an agreed list. The processor shall specifically inform in writing the controller of any intended changes of that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s)."

Source

23andMe Holding Co. / A&M

Data Processing Engagement

General authorization with flow-down of protections

One-Sided

2025

"A&M has Company's general authorization for the engagement of sub-processors to assist A&M in Processing Company Personal Data as reasonably necessary to providing the Services; provided, each sub-processor shall be subject to written agreement that complies with applicable Data Protection Law and is no less protective than as set forth herein."

Source

Marqeta, Inc., UK Addendum

Schedule E: Data Processing

Processor remains liable for its sub-processors

One-Sided

2023

"Marqeta may engage third party providers including any advisers, contractors, or auditors to Process Personal Data ('Sub-Processors')... and Marqeta shall remain liable for the acts and omissions of its Sub-Processors."

Source

Negotiate

Customer or Controller Positions:

Customer or Controller Positions:

Seek visibility into the processing chain and a workable response to proposed changes.

  • Require a maintained, accessible sub-processor list, advance written notice of additions or replacements, and the information needed to evaluate and object before processing begins.

  • Require a genuine objection process that resolves authorization before the proposed sub-processor processes your data, with an alternative provider or termination of affected processing if agreement cannot be reached.

  • Require flow-down of equivalent obligations to each sub-processor, and that the vendor remain liable to you for the sub-processor's acts.

Vendor or Processor Positions:

Vendor or Processor Positions:

Seek an authorization process your operations team can administer as providers change.

  • Seek general authorization from a maintained list, with a notice and objection process your operations team can administer as providers change.

  • Set a workable notice period and limit objections to reasonable data-protection grounds rather than business preference.

  • Address sub-processor liability expressly in the liability provisions, and check any proposed cap against applicable data-protection law.

Negotiate notice, the steps for resolving objections before processing begins, and responsibility for sub-processors' data-protection obligations.

Red Flags

  • General authorization with no notice of changes and no objection right, so data can move to an unvetted provider.

  • An objection right with no defined resolution process, leaving uncertainty about authorization, alternative providers, and termination of affected processing.

  • No flow-down obligation, so sub-processors are not bound to equivalent data-protection terms.

  • The processor disclaiming liability for its sub-processors' acts, breaking the accountability chain.

  • A sub-processor list that is not maintained or accessible, so you cannot tell who holds your data.

FAQs

It is a provision in a data processing addendum that governs when and how a vendor may engage a downstream provider to process your personal data, including how that provider is authorized, whether you can object, what obligations flow down to it, and who remains liable.

It is a provision in a data processing addendum that governs when and how a vendor may engage a downstream provider to process your personal data, including how that provider is authorized, whether you can object, what obligations flow down to it, and who remains liable.

Specific authorization means the controller approves each sub-processor individually before it is used. General authorization can cover an agreed list and later additions or replacements, subject to advance notice and an opportunity to object. The agreement should specify the notice period and how objections will be resolved before the proposed processing begins.

Specific authorization means the controller approves each sub-processor individually before it is used. General authorization can cover an agreed list and later additions or replacements, subject to advance notice and an opportunity to object. The agreement should specify the notice period and how objections will be resolved before the proposed processing begins.

Yes. Under GDPR Article 28(2), general authorization must provide an opportunity to object to proposed additions or replacements. Agree the assessment criteria and a process that resolves authorization before the proposed sub-processor processes your data, including an alternative provider or termination of affected processing if agreement cannot be reached.

Yes. Under GDPR Article 28(2), general authorization must provide an opportunity to object to proposed additions or replacements. Agree the assessment criteria and a process that resolves authorization before the proposed sub-processor processes your data, including an alternative provider or termination of affected processing if agreement cannot be reached.

Under GDPR Article 28 the processor remains fully liable to the controller for a sub-processor's performance of the data-protection obligations. A clause that disclaims that liability breaks the accountability chain the law is meant to preserve.

Under GDPR Article 28 the processor remains fully liable to the controller for a sub-processor's performance of the data-protection obligations. A clause that disclaims that liability breaks the accountability chain the law is meant to preserve.

It requires the controller's prior specific or general written authorization before a processor engages a sub-processor, advance notice and an objection right for general authorization, flow-down of equivalent data-protection obligations by contract, and the processor remaining fully liable to the controller for the sub-processor.

It requires the controller's prior specific or general written authorization before a processor engages a sub-processor, advance notice and an objection right for general authorization, flow-down of equivalent data-protection obligations by contract, and the processor remaining fully liable to the controller for the sub-processor.

This content is for informational purposes only and does not constitute legal advice.

Try GC AI Free

Find Every Gap in Your Sub-Processor Clause

Trusted by 2,100+ in-house teams

Upload your contract. In 60 seconds, see every missing trigger, weak notice window, and one-sided fee provision, quoted exactly where it appears.

14-day free · No credit card required

SOC 2

Type II Certified

SOC 3

Certified

GDPR

Compliant

Book a personalized demo call

The AI platform built for in-house legal teams. SOC 2 certified. Zero data retention. See it for yourself.

What to expect:

A walkthrough of the GC AI platform, tailored to your team's use cases.

Answers to your questions about security, integrations, and onboarding.

A 14-day free trial if the platform looks like a fit for your team.

Related Clauses

Data Protection (DPA)

A provision, often a standalone data processing agreement, that governs how a vendor processes personal data on a customer's behalf and meets privacy-law requirements.

Data Breach Notification

A clause requiring a party to notify the other of a security breach affecting its data within a defined window, with defined content, so the other can meet its own legal obligations.

Confidentiality

A contractual provision requiring one or both parties to keep specified information secret and use it only for an agreed purpose.

Assignment

A contractual provision that controls whether a party can transfer its rights or obligations under the contract to a third party.