| name | sub-processor-management |
| title | Sub-Processor Management |
| description | GDPR Article 28(2) sub-processor approval workflow management. Covers prior specific and general authorization mechanisms, change notification procedures, objection windows, flow-down obligation enforcement, and sub-processor chain risk monitoring. |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/sub-processor-management |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Sub-Processor Management
Overview
GDPR Article 28(2) establishes that a processor shall not engage another processor (sub-processor) without prior specific or general written authorisation of the controller. Where general authorisation is granted, the processor must inform the controller of any intended changes concerning the addition or replacement of sub-processors, giving the controller the opportunity to object. This creates an ongoing management obligation that extends through the entire processing chain.
The EDPB Guidelines 07/2020 (paragraph 93) emphasize that the controller's Article 28(1) due diligence obligation extends to oversight of sub-processor arrangements, and that the processor remains fully liable for the sub-processor's compliance.
At Summit Cloud Partners, the Sub-Processor Management Program ensures visibility and control over the entire processing chain for all vendor relationships involving personal data.
Authorization Models
Model A: Prior Specific Authorization
Under this model, the controller individually approves each sub-processor before engagement.
When to Use:
- High-risk processing (special category data, large-scale processing, cross-border transfers)
- Processing involving sensitive industries (healthcare, financial services)
- When the controller requires direct assessment of each sub-processor
Process:
| Step | Action | Timeline |
|---|
| 1 | Processor identifies need for new sub-processor | — |
| 2 | Processor submits sub-processor details to controller | Pre-engagement |
| 3 | Controller conducts due diligence on proposed sub-processor | 15 business days |
| 4 | Controller issues written approval or rejection | 5 business days |
| 5 | If approved, processor executes sub-processor DPA | Before processing begins |
| 6 | Processor provides controller with confirmation of sub-processor DPA execution | 5 business days |
Model B: General Written Authorization with Notification
Under this model, the controller grants blanket authorization for sub-processing, subject to a notification and objection mechanism.
When to Use:
- Standard-risk processing
- SaaS vendors with dynamic infrastructure providers