What It Does
For in-house counsel, review the sub-processor clause against the data-protection commitments your company has made to its customers. A practical test: choose a proposed addition to the vendor's list and trace the notice, objection process, available remedy, and obligations that will bind the new provider.
Sets how sub-processors are authorized, by specific consent or general authorization
Requires advance notice of additions or replacements under general authorization, with an agreed period that allows the controller to assess and object
Gives the controller a right to object to a new sub-processor
Flows down equivalent data-protection obligations to the sub-processor
Keeps the processor liable to the controller for the sub-processor's acts
General authorization from a maintained list, with advance notice and an objection process, is one available model; specific authorization requires approval of each proposed sub-processor.
When You'll See It
Sub-processor terms appear in data processing addenda, SaaS and cloud agreements with a data-processing section, and vendor security exhibits, in any arrangement where a vendor processes personal data on your behalf. The clause sits inside or alongside the DPA, near the security, breach-notification, and international-transfer provisions. The list of sub-processors is often maintained at a URL rather than written into the contract, with the contract setting the rules for changing it.
It matters most where you are a controller passing personal data to a processor and you, in turn, owe data-protection commitments to your own customers or to regulators. The longer the processing chain and the more sensitive the data, the more the authorization model, the objection right, and the flow-down decide whether your obligations reach the bottom of the chain.
Examples
Relativity ODA LLC / KLDiscovery Ontrack, LLC
Data Processing Agreement (UK SCCs)
General authorization from a list, with 30-day notice and objection
One-Sided
2023
"The processor has the controller’s general authorisation for the engagement of sub-processors from an agreed list. The processor shall specifically inform in writing the controller of any intended changes of that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s)."
23andMe Holding Co. / A&M
Data Processing Engagement
General authorization with flow-down of protections
One-Sided
2025
"A&M has Company's general authorization for the engagement of sub-processors to assist A&M in Processing Company Personal Data as reasonably necessary to providing the Services; provided, each sub-processor shall be subject to written agreement that complies with applicable Data Protection Law and is no less protective than as set forth herein."
Marqeta, Inc., UK Addendum
Schedule E: Data Processing
Processor remains liable for its sub-processors
One-Sided
2023
"Marqeta may engage third party providers including any advisers, contractors, or auditors to Process Personal Data ('Sub-Processors')... and Marqeta shall remain liable for the acts and omissions of its Sub-Processors."
Negotiate
Seek visibility into the processing chain and a workable response to proposed changes.
Require a maintained, accessible sub-processor list, advance written notice of additions or replacements, and the information needed to evaluate and object before processing begins.
Require a genuine objection process that resolves authorization before the proposed sub-processor processes your data, with an alternative provider or termination of affected processing if agreement cannot be reached.
Require flow-down of equivalent obligations to each sub-processor, and that the vendor remain liable to you for the sub-processor's acts.
Seek an authorization process your operations team can administer as providers change.
Seek general authorization from a maintained list, with a notice and objection process your operations team can administer as providers change.
Set a workable notice period and limit objections to reasonable data-protection grounds rather than business preference.
Address sub-processor liability expressly in the liability provisions, and check any proposed cap against applicable data-protection law.
Negotiate notice, the steps for resolving objections before processing begins, and responsibility for sub-processors' data-protection obligations.
Red Flags
General authorization with no notice of changes and no objection right, so data can move to an unvetted provider.
An objection right with no defined resolution process, leaving uncertainty about authorization, alternative providers, and termination of affected processing.
No flow-down obligation, so sub-processors are not bound to equivalent data-protection terms.
The processor disclaiming liability for its sub-processors' acts, breaking the accountability chain.
A sub-processor list that is not maintained or accessible, so you cannot tell who holds your data.
FAQs
This content is for informational purposes only and does not constitute legal advice.



