For the complete documentation index, see llms.txt. This page is also available as Markdown.

Subprocessors and Vendors

Contents

1. What is a subprocessor?

A subprocessor is a third party that a data processor engages to help process personal data on behalf of the original data controller.

Imagining your business is an SaaS startup, the data flow might look something like this:

  1. Your business collects the name, email address and payment details of a new user. You are the data controller, deciding what data to collect and why (to bill the user).

  2. Your business uses a cloud hosting provider to store your users’ personal data. The cloud hosting provider is acting on your instructions and so functions as the data processor.

  3. The cloud hosting provider uses various third parties to help deliver its service. For example, it contracts a data monitoring service. This data monitoring service is still processing your business’s users’ personal data, but as a subprocessor. Importantly, your business remains responsible for these subprocessors’ data processing.

You have obligations to carefully monitor the processing activities of your subprocessors.

2. What is a vendor?

A vendor is any third party provider which provides goods or services to your business.

Vendors which process the personal data for which your business is responsible are also processors/ subprocessors under GDPR.

Let us take the use of Motion, for instance. Motion is a vendor that your company may use for internal scheduling.

  • If your startup uses Motion for scheduling between team members, it is likely processing personal data such as employee names and email addresses. Your startup is the data controller, Motion is the data processor, and any third party Motion uses to assist with data processing is a subprocessor for your startup’s purposes.

  • If your startup uses Motion to schedule tasks which do not reference the names or personal data of any individuals, it is simply a vendor, not a data processor under GDPR.

3. Disclosing your subprocessors

Internal disclosure

Your business should keep careful internal records of processors and subprocessors linked to the business.

This is for the purpose of:

  • Regulatory compliance

    • If your business decides to process any kind of personal data, it has obligations around ensuring the compliance of entities which help carry out that processing (processors and subprocessors).

      • For example, you must only use processors that provide guarantees to implement certain technical and organisational data protection safeguards.

  • Data location

    • Your business may contractually only be able to process data in certain jurisdictions in which case it must be particularly attentive to the location of subprocessors.

  • Security

    • In case of data breaches, it is important to know the subprocessor will inform you within 72 hours of discovery and will cooperate with you on remediation.

    • They must also keep records of the incident which they can disclose to you.

    • These will help you conduct risk assessments and reduce security breach potential.

Public disclosure

Your business should also publicly disclose details of your processors and subprocessors on your website.

This is for the purpose of:

  • Regulatory compliance

    • GDPR and other data protection regulations require disclosures of linked subprocessors to employees and users (as data subjects).

  • Trust

    • Publishing clear records of your subprocessors also constitutes part of your commitment to transparency and helps maintain trust from users and investors.

What should you disclose about your subprocessors?

  • A list of all subprocessors your company is using to help process customer data and customer personal information

  • You should consider also answering the following questions for each subprocessor:

    • In which country does this processing take place?

    • What service does the subprocessor provide? (e.g. email deliverability metrics)

    • What type of data is processed (personal health information, personal information, customer data)

  • Confirmation of the typical notice period users can expect before changes to subprocessors and integrations take place (usually 30 to 60 days).

4. Engaging a new subprocessor?

You must notify consumers in advance of any changes to the data flows e.g. additions of subprocessors. This is in order to give them the opportunity to object within a time period. If your business has a separate data controller (i.e., an outside party determines the purposes of your business’s processing), you must also inform this controller of any new subprocessors in order to give them the chance to object.

When you engage a new subprocessor, there may be a significant change to the flow of personal data; therefore, you must notify controllers, employees and users before processing begins.

5. What can you do today to improve your approach to subprocessors?

  • Make sure your business has clear internal records of the processors and subprocessors with access to the employee and user data you collect or process.

  • Ensure clear public disclosure of processors and subprocessors on your business’s website for users, investors and other potential stakeholders to consult.

  • Investigate appointing a DPO/ Privacy Partner. Having a DPO/ Privacy Partner on board can be really helpful for ensuring regulatory compliance with subprocessor obligations whilst easing the workload for your team.

Last updated