Back to Glossary
Privacy Glossary

Sub-Processor

A third party engaged by a Data Processor to carry out processing activities on behalf of the Data Controller.

GDPRLGPD

Full Definition

A Sub-Processor is any third party that a Data Processor engages to process personal data on behalf of the Data Controller. Under GDPR, processors must obtain the controller's prior written authorisation before engaging sub-processors — either specific authorisation or general authorisation (with the right to object to new sub-processors). Processors remain fully liable to the controller for the sub-processor's compliance. Sub-processor chains must be documented, and the obligations imposed on sub-processors must be at least equivalent to those imposed on the processor under the Data Processing Agreement. Organisations commonly use a public sub-processor list to provide transparency.

Automate your privacy program

TruePrivacy handles DSRs, consent management, data mapping, and breach response — all in one platform.