Subprocessor

Direct answer

A subprocessor is a downstream service provider engaged by a processor to handle personal data on the controller's behalf.

A subprocessor is a third party that a processor uses to deliver part of the contracted service while still handling personal data linked to the controller's environment.

In practice, subprocessors often include cloud hosting providers, support vendors, infrastructure tools, and specialist integrations that sit one level below the main vendor relationship.

That is why teams need a current subprocessor inventory, change-notice process, and evidence that vendor oversight is tied to reality instead of a stale spreadsheet.

Related Articles

Related Terms

Subprocessor | Compliance Glossary | ComplySafe.io | ComplySafe.io