What Is a Sub-processor?
TL;DR
A sub-processor is a third party that a processor engages to help handle personal data on behalf of the original controller, such as the cloud host or email infrastructure a software vendor runs on. GDPR Article 28(2) requires the controller to authorise it, and the first processor remains liable for it.
How does sub-processor authorisation work?
Article 28(2) prohibits a processor from engaging another processor without prior specific or general written authorisation from the controller. General authorisation is the normal commercial arrangement: the DPA names the current sub-processors and commits the vendor to inform the controller of any intended addition or replacement, giving an opportunity to object before it happens.
Article 28(4) closes the loop. The same data protection obligations set out in the main contract have to be imposed on the sub-processor, and where the sub-processor fails to meet them the initial processor remains fully liable to the controller. Responsibility does not travel down the chain with the data.
Why does the sub-processor list matter in a vendor review?
The list is the closest thing to a data map a buyer gets without an audit. It shows where data is hosted, in which regions, and which supporting services can see it, which is what determines whether an international transfer is happening and what safeguard covers it. A vendor unable to produce a current list is disclosing something about its own record-keeping.
Reading the list is not the same as approving what it implies, and transfer mechanisms are their own legal question rather than a procurement checkbox. What a definition can usefully supply is the reason the list exists at all, and the fact that the notice-and-object clause around it is worth reading before signing rather than after a change lands.
Frequently asked questions
No. A sub-processor acts on instruction, inside the purpose the original controller set. A third party that decides its own purpose for the data is a controller in its own right, which calls for disclosure and a separate agreement rather than a sub-processing clause.