Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a subprocessor by first mapping the personal-data processing and its risks, then verifying that the provider offers sufficient guarantees for that specific work. Confirm the processor has the required written authorisation, the downstream contract carries equivalent data-protection obligations, and you have a workable process for incidents, changes, transfers, assistance and exit. Document the decision and revisit it when the processing or subprocessor chain changes.

This checklist is oriented to UK GDPR and EU GDPR. Applicable law and guidance can vary by jurisdiction, sector, contract and processing facts; the UK Information Commissioner’s Office (ICO) says its guidance is under review following the Data (Use and Access) Act. Check the current rules before using this as a compliance determination.

How do I choose a subprocessor?

  1. Define the work and data. Establish what the proposed subprocessor will do, whose data it will handle, where and how it will access that data, and the risks to individuals.
  2. Check sufficient guarantees. Gather evidence about security, expertise, privacy practices, assistance and resilience that is relevant to this service and proportionate to its risk. The ICO explains that the controller is responsible for assessing whether its processor is competent to process personal data in line with UK GDPR requirements: ICO guidance on controller responsibilities.
  3. Verify authorisation and contract flow-down. Confirm whether the controller gave specific or general written authorisation, and whether the processor’s agreement with the subprocessor imposes the required data-protection obligations with an equivalent level of protection.
  4. Assess evidence, transfers and operational duties. Check assurance scope and recency; test how incidents, rights requests, impact assessments and international transfers will be handled.
  5. Record and monitor. Document evidence, gaps, mitigations, decision ownership and review triggers. Keep subprocessor identities and processing information current.

A provider’s general claim that it is “compliant” is not, by itself, an assessment of whether it is suitable for your processing. The controller’s assessment should reflect the nature of the processing and risks to data subjects. The European Data Protection Board (EDPB) says verification applies regardless of risk, while the extent of verification should scale with risk and the measures involved: EDPB Opinion 22/2024.

Scope the processing before reviewing evidence

Ask the internal service owner and the processor for a clear description of the proposed subprocessor’s role. Without this baseline, it is difficult to decide what guarantees are sufficient or what controls are appropriate.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Who are the controller, processor and proposed subprocessor, and who gives documented instructions?
  • What service, purpose and processing activities are involved?
  • Which personal-data and data-subject categories are in scope? Identify special-category, criminal-offence, children’s, financial or other especially sensitive information.
  • How long will processing last, and in which locations, systems and access paths will data be handled?
  • Which other subprocessors are in the chain, and are onward transfers expected?
  • What changes when the service changes or ends, including return, export and deletion?

These details help connect the evidence to the real work and the potential impact on individuals. The ICO’s guidance on processor contracts and duties describes required contractual and security considerations: ICO guidance on contracts and liabilities.

What should I ask a subprocessor?

Direct questions to the processor and, where appropriate, the proposed subprocessor. Request evidence tied to the service rather than relying only on broad company-wide statements.

Security and resilience

  • Who owns security risk for this service, and which governance policies apply?
  • How are identities, access rights and privileged access managed? What confidentiality obligations apply to personnel?
  • How are confidentiality, integrity, availability and resilience protected? Are encryption or pseudonymisation used where appropriate?
  • How are systems tested and assessed, and what is the scope and date of the evidence you can provide?
  • How are backups, recovery and restoration of access handled following an incident?
  • How are incidents detected, escalated and investigated, and what assistance will be provided to the controller?

Article 32 measures described by the ICO include, as appropriate, encryption or pseudonymisation; ongoing confidentiality, integrity, availability and resilience; restoration of availability and access after an incident; and regular testing and assessment of security measures.

Privacy assistance and operational fit

  • Can the provider support the processor and controller with data-subject rights requests?
  • What cooperation is available for impact assessments and other controller obligations?
  • How does the provider follow documented instructions and communicate constraints or proposed changes?
  • What information is available about its own subprocessors, their roles and locations, and how are they overseen?
  • At termination, how can data be returned or exported, deleted, and deletion evidenced—including applicable treatment of backups?

The ICO lists relevant industry standards, technical expertise, assistance capability, privacy and information-security documentation, and adherence to a code of conduct or certification scheme as possible considerations. These are examples, not an exhaustive checklist or an automatic pass/fail test.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Confirm authorisation and downstream contract protections

Under the UK GDPR framework described by the ICO, the processor needs the controller’s prior written authorisation to engage a subprocessor. Establish which model your arrangement uses and verify that it is reflected in the contract and the actual change process.

Specific written authorisation

The controller approves a particular subprocessor for the relevant processing. Confirm the approved entity, service and scope rather than treating approval of a corporate group or product name as automatically covering every processing activity.

General written authorisation

The controller approves a list or criteria for subprocessors. The processor must notify the controller of intended changes and provide an opportunity to object. Check that the notice process gives enough information and time for a meaningful assessment and objection before a change takes effect, as provided by the arrangement.

Contract terms to confirm

The binding processor contract should address applicable Article 28 requirements, including documented instructions, confidentiality, security, subprocessor engagement, assistance with data-subject rights and controller obligations, return or deletion at contract end, and audit and inspection rights. The processor-subprocessor contract must pass down the required data-protection obligations and provide an equivalent level of protection for the personal data. Under the ICO’s guidance, the processor remains liable to the controller for the subprocessor’s compliance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For EU arrangements, Commission Implementing Decision (EU) 2021/915 provides standard contractual clauses for controller-processor arrangements. Treat them as a drafting resource to assess against the facts and governing law, not as a substitute for checking the provider, processing and contract.

How much verification is enough?

The EDPB’s Opinion 22/2024 states that verification applies regardless of risk, but its extent varies with the nature of the measures and the risks. A controller may build on information supplied by its processor and seek more where it is incomplete, inaccurate or raises questions. Higher-risk processing warrants increased verification. The opinion does not establish a general duty to request every subprocessing contract; whether to request or review one is a case-by-case accountability decision.

The following evidence ladder is a practical way to implement risk-scaled verification, not a mandated EDPB sequence:

  1. Review the basics: current policies, service description, data-flow information and security documentation.
  2. Check assurance evidence: examine reports, certificates or code adherence for scope, exclusions, dates and fit to the particular service.
  3. Ask targeted follow-up questions: resolve gaps or evidence that does not cover the processing at issue.
  4. Increase scrutiny when risk warrants it: consider deeper technical review, independent audit material or downstream contract review where needed to demonstrate compliance.
  5. Record the result: capture what was reviewed, remaining uncertainty, compensating measures, approver and review date.

Compare candidates using the same criteria

If there is more than one plausible provider, assess each against the same axes and weight them according to the processing. A lower-risk service may need less depth of evidence than a service handling sensitive data or creating substantial risks to individuals.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Comparison axis Evidence to compare
Processing fit Role clarity, service scope, purpose, data types, locations and ability to follow instructions.
Security Relevant controls, independent-assurance scope, incident handling, resilience and recovery.
Contract Authorisation model, equivalent downstream obligations, assistance, audit and exit terms.
Transparency Named subprocessors, current information, notice period and objection process.
Transfers Countries, transfer mechanism, supporting documentation and supplementary safeguards where needed.
Operational support Support for rights requests, breach response, impact assessments and cooperation with the controller.
Exit and continuity Data return or export, deletion, service continuity and evidence of completion.
Evidence quality Coverage, independence, recency, exclusions and relevance to the service being assessed.

Manage transparency and changes over time

Keep the identities of processors and subprocessors readily available, with enough information to understand each party’s role in the processing chain. The EDPB says the processor should proactively provide this information and keep it up to date; its public summary of Opinion 22/2024 also addresses current subprocessor information.

Assign an owner to receive change notices and a workflow to assess them. Before a notified change takes effect where the arrangement permits, assess the new provider’s role, data access, location, guarantees and contract flow-down. Set review triggers for material changes to service scope, data, locations, access paths, the subprocessor chain or applicable risk.

Check international transfers against actual data flows

If personal data moves outside the European Economic Area (EEA), identify the applicable transfer mechanism and review supporting documentation and safeguards relevant to that transfer. The EDPB opinion discusses documentation such as the transfer ground, transfer impact assessment and possible supplementary measures in the circumstances it addresses. Apply the rules of the relevant jurisdiction to the actual data flows: a subprocessor’s location alone does not establish whether a restricted transfer occurs.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Decision record template

Keep a concise record that lets another reviewer understand the decision and its basis. Adapt these fields to your organisation’s governance process:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Proposed subprocessor and service
  • Processing purpose, data, data subjects, duration and locations
  • Controller authorisation route and date
  • Risk level and reasons
  • Evidence reviewed, including scope, dates and limitations
  • Security and privacy gaps and mitigations
  • Contract and downstream flow-down confirmation
  • Transfers and safeguards reviewed
  • Decision, owner, approver and date
  • Conditions, objection deadline or remediation actions
  • Next review trigger or date

Or skip the browser setup

For a technical workflow that needs a clean screenshot of a vendor’s public privacy, security or subprocessor page, ScreenshotNeo offers a one-request screenshot API. It is not a substitute for reviewing contracts, controls or transfer evidence.

cURL example: See the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts cookie or consent banners as a visitor and removes 60+ known consent platforms, newsletter popups and chat widgets before capture; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. An MCP server provides take_screenshot, get_page_info and capture_pdf for AI agents and MCP clients. The Free plan includes 1,000 screenshots a month without a card; paid plans start at $5 for 3,000 shots. Learn more at ScreenshotNeo, or sign up free for 1,000 screenshots a month with no card.

Frequently Asked Questions

Do I need to approve my processor’s subprocessors?

Under the UK GDPR framework described by the ICO, the processor needs your prior written authorisation, which may be specific or general. In a general-authorisation arrangement, the processor must notify you of intended changes and give you an opportunity to object.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should I request every subprocessing contract?

No general duty to systematically request every subprocessing contract is established in EDPB Opinion 22/2024. Decide case by case whether contract review is needed to verify the arrangement and demonstrate accountability.

What should a subprocessor security checklist include?

At minimum, assess controls and evidence relevant to the processing: access and confidentiality, appropriate encryption or pseudonymisation, resilience and recovery, testing, incident support, subprocessor oversight, assistance with controller duties, transfers and secure exit.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.