Sub-Processor Clause
A clause in a data processing addendum that governs when and how a vendor may hand the customer's personal data to a downstream provider, and on what conditions.
Reviewed by GC AI Solutions Team•Updated September 2026

Definition
A sub-processor clause governs when and how a processor, usually your vendor, may engage a downstream provider, a sub-processor, to help process your personal data. Under GDPR Article 28, a processor cannot use a sub-processor without the controller's prior authorization, which is either specific to each sub-processor or general, based on a maintained list with advance notice of changes and a right to object. The processor must flow down equivalent data-protection obligations by contract and remains fully liable to the controller for the sub-processor's performance. It is a defined part of a data processing addendum.
What It Does
For in-house counsel, review the sub-processor clause against the data-protection commitments your company has made to its customers. A practical test: choose a proposed addition to the vendor's list and trace the notice, objection process, available remedy, and obligations that will bind the new provider.
-
Sets how sub-processors are authorized, by specific consent or general authorization
-
Requires advance notice of additions or replacements under general authorization, with an agreed period that allows the controller to assess and object
-
Gives the controller a right to object to a new sub-processor
-
Flows down equivalent data-protection obligations to the sub-processor
-
Keeps the processor liable to the controller for the sub-processor's acts
General authorization from a maintained list, with advance notice and an objection process, is one available model; specific authorization requires approval of each proposed sub-processor.
When You'll See It
Sub-processor terms appear in data processing addenda, SaaS and cloud agreements with a data-processing section, and vendor security exhibits, in any arrangement where a vendor processes personal data on your behalf. The clause sits inside or alongside the DPA, near the security, breach-notification, and international-transfer provisions. The list of sub-processors is often maintained at a URL rather than written into the contract, with the contract setting the rules for changing it.
It matters most where you are a controller passing personal data to a processor and you, in turn, owe data-protection commitments to your own customers or to regulators. The longer the processing chain and the more sensitive the data, the more the authorization model, the objection right, and the flow-down decide whether your obligations reach the bottom of the chain.
Examples
Relativity ODA LLC / KLDiscovery Ontrack, LLC
"The processor has the controller’s general authorisation for the engagement of sub-processors from an agreed list. The processor shall specifically inform in writing the controller of any intended changes of that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s)."Source
23andMe Holding Co. / A&M
"A&M has Company's general authorization for the engagement of sub-processors to assist A&M in Processing Company Personal Data as reasonably necessary to providing the Services; provided, each sub-processor shall be subject to written agreement that complies with applicable Data Protection Law and is no less protective than as set forth herein."Source
Marqeta, Inc., UK Addendum
"Marqeta may engage third party providers including any advisers, contractors, or auditors to Process Personal Data ('Sub-Processors')... and Marqeta shall remain liable for the acts and omissions of its Sub-Processors."Source
Negotiate
Customer or Controller Positions:
Seek visibility into the processing chain and a workable response to proposed changes.
- Require a maintained, accessible sub-processor list, advance written notice of additions or replacements, and the information needed to evaluate and object before processing begins.
- Require a genuine objection process that resolves authorization before the proposed sub-processor processes your data, with an alternative provider or termination of affected processing if agreement cannot be reached.
- Require flow-down of equivalent obligations to each sub-processor, and that the vendor remain liable to you for the sub-processor's acts.
Vendor or Processor Positions:
Seek an authorization process your operations team can administer as providers change.
- Seek general authorization from a maintained list, with a notice and objection process your operations team can administer as providers change.
- Set a workable notice period and limit objections to reasonable data-protection grounds rather than business preference.
- Address sub-processor liability expressly in the liability provisions, and check any proposed cap against applicable data-protection law.
Negotiate notice, the steps for resolving objections before processing begins, and responsibility for sub-processors' data-protection obligations.
Red Flags
-
General authorization with no notice of changes and no objection right, so data can move to an unvetted provider.
-
An objection right with no defined resolution process, leaving uncertainty about authorization, alternative providers, and termination of affected processing.
-
No flow-down obligation, so sub-processors are not bound to equivalent data-protection terms.
-
The processor disclaiming liability for its sub-processors' acts, breaking the accountability chain.
-
A sub-processor list that is not maintained or accessible, so you cannot tell who holds your data.
Sub-Processor Clause FAQs
What is a sub-processor clause?
What is the difference between general and specific authorization for sub-processors?
Can you object to a new sub-processor?
Is the processor liable for its sub-processors?
What does a sub-processor clause require under GDPR Article 28?
Related Clauses
- Data Protection (DPA) ClauseA provision, often a standalone data processing agreement, that governs how a vendor processes personal data on a customer's behalf and meets privacy-law requirements.Read More
- Data Breach Notification ClauseRequires notice of a data breach, including the information needed for the other party to respond.Read More
- Confidentiality ClauseA contractual provision requiring one or both parties to keep specified information secret and use it only for an agreed purpose.Read More
- Assignment ClauseA contractual provision that controls whether a party can transfer its rights or obligations under the contract to a third party.Read More
This content is for informational purposes only and does not constitute legal advice.