Sub-Processor Disclosure
Sub-processor disclosure is the practice of telling customers which downstream vendors a service provider has engaged to help handle personal data on the provider's behalf. It typically takes the form of a published or contractually shared list of these downstream parties. The purpose is to give the organization whose data is being processed visibility into who, beyond their direct provider, may access or handle that data.
Sub-processor disclosure refers to the obligation or practice by which a data processor identifies the downstream processors (sub-processors) it has engaged to carry out part of the processing activity on behalf of a controller. In this context a sub-processor is a third-party service or vendor engaged by the primary processor to assist in handling personal data; disclosure commonly extends to any sub-processor with potential access to customer data, such as those engaged by a cloud service provider. Under EDPB guidance, processors are expected to provide details of every sub-processor down the chain to the ultimate controller, along with associated information, meaning disclosure is not limited to first-tier engagements but is intended to reach further down the processing chain. Scope note: disclosure identifies who the sub-processors are and supports transparency and objection rights; it does not by itself verify or assure that those sub-processors have adequate controls, nor does it substitute for independent assessment or ongoing monitoring. Applicability and specific obligations vary by jurisdiction and by the terms of the applicable data processing agreement.
Why it matters
When an organization entrusts personal data to a service provider, that provider frequently relies on its own downstream vendors to deliver the service. Without disclosure of these sub-processors, the organization whose data is being processed has no visibility into who, beyond its direct contractual counterparty, may access or handle that data. Sub-processor disclosure exists to close that visibility gap: it identifies the downstream parties in the processing chain so that the controller can exercise oversight, evaluate concentration in particular vendors or regions, and act on rights it may hold, such as objecting to a proposed sub-processor engagement. Under EDPB guidance, this transparency is intended to reach beyond first-tier engagements and extend to every sub-processor down the chain, along with associated information provided to the ultimate controller.
The practical value of disclosure is that it makes downstream dependencies legible rather than hidden. In many programs, a maintained sub-processor list is what allows a data protection or vendor risk team to map where personal data actually flows, to reconcile that flow against the applicable data processing agreement, and to trigger contractual objection or notice mechanisms when a new sub-processor appears. It also informs adjacent risk assessments, since a downstream vendor with access to customer data may introduce concentration risk or geographic exposure that the direct relationship alone does not reveal.
It is important to be clear about what disclosure does and does not accomplish. Identifying who the sub-processors are supports transparency and objection rights, but it does not by itself verify or assure that those sub-processors maintain adequate controls, nor does it substitute for independent assessment or ongoing monitoring. A disclosed list is a starting point for oversight, not evidence of it. Specific obligations and their enforceability vary by jurisdiction and by the terms of the applicable data processing agreement, so the weight a given disclosure carries depends heavily on the surrounding legal and contractual context.
Who it's relevant to
Inside Sub-Processor Disclosure
Common questions
Answers to the questions practitioners most commonly ask about Sub-Processor Disclosure.
