Knowledge Hub
for Growth


UK GDPR compliance tips for data processors using sub-processors

Using third-party suppliers to help deliver services has become a key – and sometimes critical – part of how businesses and supply chains operate today, especially in industries like SaaS, e-commerce, and marketing. As a supplier, you may rely heavily on third parties for essential services such as cloud hosting, payment processing, or technical support. However, if you share your clients' personal data with these parties, strict data protection laws apply to ensure their personal data remains safeguarded. 

If you act as a data processor and work with third parties, it’s vital to ensure any sub-processors you engage with comply with UK GDPR requirements and effectively manage the risks associated with processing personal data. 

In this article, our data protection solicitors address common questions and provide valuable tips for processors working with sub-processors to stay compliant with UK GDPR.

Your key responsibilities when engaging sub-processors

As a data processor, you're handling personal data on behalf of a data controller and must only process it according to their instructions. 

Before you bring a sub-processor on board, you must comply with UK GDPR requirements. Take legal advice if you’re unsure whether a third-party supplier or subcontractor could act as a sub-processor. 

Key obligations when appointing a sub-processor include: 

  • Obtain written authorisation from the controller before appointing a sub-processor. This authorisation can be specific or general. 
  • If the controller provides general authorisation, notify the controller of any changes to sub-processors and allow them to object before appointing a new sub-processor. You’ll need a clear process for managing objections. 
  • To maintain UK GDPR compliance, ensure your contract with the sub-processor mirrors or offers equivalent data protection terms to those you’ve agreed with the controller. 

How to assess sub-processor compliance with UK GDPR

Sub-processors are typically third-party vendors engaged by you (the processor) to process personal data on behalf of the controller. Examples include a SaaS platform that stores customer data with a cloud hosting provider or an e-commerce platform that relies on a third-party payment processor. 

UK GDPR applies to all processors, including sub-processors. They must comply with the same strict rules that apply to you. For example, sub-processors must: 

  • Process data only under the controller’s instructions. 
  • Implement strong security measures to protect personal data. 

As a supplier and data processor, you should always ensure robust due diligence processes are in place. Before appointing a sub-processor, you must ensure they meet these standards by conducting due diligence, which includes: 

  • Reviewing their security practices. 

Confirming they have a history of UK GDPR compliance. Verifying that they can meet your contractual obligations. 

How to notify controllers about sub-processor changes

Controllers need to know exactly who is handling their data. Where your contract allows controllers who have given general authorisation to object to sub-processor changes, you must follow a well-documented, written process to notify them. 

Practical tools to help streamline this process include: 

  • Notifying controllers via email when you appoint or change sub-processors. 
  • Keep an up-to-date sub-processor list on your website and inform controllers of any changes. 
  • Use software to manage sub-processor notifications and updates, especially if you work with many sub-processors. 

Make sure your process is both efficient and compliant with legal requirements. For smaller businesses, this can be as simple as sending an email. However, for larger processors, a more sophisticated system may be necessary. 

What to include in sub-processor contracts

Navigating strong sub-processor agreements is important to balance UK GDPR compliance with your business realities. But remember, you’re fully liable to the controller for the performance of the sub-processor’s obligations. So, the contract needs to: 

  • Specify what data the sub-processor will handle and how it will be protected. 
  • Include terms on important issues such as data breach notifications, security requirements, and audit rights. 
  • Ensure the sub-processor agrees to implement appropriate technical and organisational measures. 

Although it may not always be possible to fully flow down the same obligations you have agreed with the controller and enforce them on all sub-processors, seeking legal advice to ensure your contracts are robust is crucial. 

Managing liability risks when using sub-processors

Liability is a key concern when working with sub-processors. If something goes wrong, the controller can hold you responsible for any breaches or issues related to data processing. 

To manage this risk, ensure your contract with the sub-processor includes strong liability provisions, such as: 

  • Indemnity clauses are where the sub-processor agrees to compensate you for any damages caused by their actions. 
  • Insurance requirements, ensuring the sub-processor has sufficient coverage to back up their indemnity obligations. 

Negotiating these clauses with sub-processors can be challenging, but it’s essential to safeguard your business from potential risks. Consult with a data protection lawyer to ensure these provisions are legally sound. 

Tips to streamline sub-processor compliance and stay ahead

To stay compliant with UK GDPR and manage sub-processor relationships effectively, it's important to: 

  • Regularly review and audit your sub-processors to ensure they’re still compliant. 
  • Keep clear and transparent records of your due diligence and ongoing monitoring. 
  • Implement processes and tools to notify controllers of sub-processor changes quickly and easily. 

By establishing a clear and efficient system for managing your sub-processors, you can mitigate risks and ensure ongoing compliance with UK GDPR.  

Protecting your business while staying compliant

If your business relies on sub-processors, there’s much to consider to ensure you meet the strict data protection requirements under UK GDPR. From conducting due diligence to ensuring strong contracts and managing liability risks, there are many steps you must take to stay compliant. 

By following the guidelines in this article, you can protect your business, keep your controllers happy that their data is safe, and avoid the risks associated with non-compliance. 

If you need help navigating the legal complexities of sub-processor appointments, our data protection solicitors are here to assist you in building effective, compliant processes for your business. 

About our expert

Lillian Tsang MBA

Lillian Tsang MBA

Senior Data Protection and Privacy Solicitor
Lillian is an experienced data protection and privacy lawyer who qualified in 2008. She advises clients on a broad range of matters - from strategic compliance with a global stance to day-to-day operations. Her role also includes Harper James' Head of DPOaaS division (Data Protection Officer as a Service), where we act as the external DPO for a business or provide support to existing DPOs.


What next?

Please leave us your details and we’ll contact you to discuss your situation and legal requirements. There’s no charge for your initial consultation, and no obligation to instruct us. We aim to respond to all messages received within 24 hours.

Your data will only be used by Harper James. We will never sell your data and promise to keep it secure. You can find further information in our Privacy Policy.


Our offices

A national law firm

A national law firm

Our commercial lawyers are based in or close to major cities across the UK, providing expert legal advice to clients both locally and nationally.

We mainly work remotely, so we can work with you wherever you are. But we can arrange face-to-face meeting at our offices or a location of your choosing.

Head Office

Floor 5, Cavendish House, 39-41 Waterloo Street, Birmingham, B2 5PP
Regional Spaces

Capital Tower Business Centre, 3rd Floor, Capital Tower, Greyfriars Road, Cardiff, CF10 3AG
Stirling House, Cambridge Innovation Park, Denny End Road, Waterbeach, Cambridge, CB25 9QE
13th Floor, Piccadilly Plaza, Manchester, M1 4BT
10 Fitzroy Square, London, W1T 5HP
Belsyre Court, 57 Woodstock Road, Oxford, OX2 6HJ
1st Floor, Dearing House, 1 Young St, Sheffield, S1 4UP
White Building Studios, 1-4 Cumberland Place, Southampton, SO15 2NP
A national law firm

Like what you’re reading?

Get new articles delivered to your inbox

Join 8,153 entrepreneurs reading our latest news, guides and insights.

Subscribe


To access legal support from just £149 per hour arrange your no-obligation initial consultation to discuss your business requirements.

Make an enquiry