Subprocessor
A subprocessor is a third-party vendor or service provider that a data processor engages to help carry out part of the work it performs on behalf of a customer, often involving the handling of personal data. For example, when a software company you use relies on another vendor to store or process customer information, that vendor is acting as a subprocessor. In short, it is a downstream provider that supports the primary processor's activities.
A subprocessor is a downstream third-party processor engaged by a primary data processor to perform part of the processing activity conducted on behalf of a controller (the customer). In practice, the subprocessor has or may have access to, or otherwise processes, personal data received from the primary processor. Because subprocessor relationships extend the chain of data handling beyond the primary processor, they are typically relevant to vendor management, contractual flow-down obligations, and the disclosure requirements that arise in compliance engagements; the specific obligations depend on scope, applicable criteria, and the governing agreements.
Why it matters
Subprocessors extend the chain of data handling beyond the primary processor that a customer directly engages, which means personal data may flow to parties the customer never selected or contracted with directly. Because this downstream access can introduce risk that is not immediately visible, subprocessor relationships are a recurring focus of vendor and third-party management programs and of the disclosure obligations that arise in compliance engagements.
In a SOC 2 examination, controls related to vendor and subprocessor oversight commonly fall within the Common Criteria addressing risk management and monitoring of third parties, though the specific controls tested depend on scope and the criteria selected. Under ISO/IEC 27001, the management of supplier and downstream relationships is typically addressed through the risk assessment process and the reference controls in Annex A that concern supplier relationships, with applicability determined by the Statement of Applicability. In both cases, an unmanaged subprocessor can represent a gap between the assurances an organization provides to its customers and the actual reach of its data-handling arrangements.
Contractual flow-down is central to managing this risk: obligations the primary processor owes its customer generally need to be reflected in agreements with subprocessors so that protections are preserved down the chain. It is important to note, however, that a SOC 2 report attests only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS; neither guarantees that every subprocessor in a supply chain meets the same standards unless those relationships fall within the assessed scope.
Who it's relevant to
Inside Subprocessor
Common questions
Answers to the questions practitioners most commonly ask about Subprocessor.