Sub-Processor Register
Definition
Sub-Processor Register
A sub-processor register is the maintained list of every third party a provider uses to process personal data on a client’s behalf. The register is the artefact — the contract clause creates the obligation, and the list is what actually satisfies it.
That separation matters when buyers evaluate providers — a clause promising transparency is easy to write, and a current published register with dates and locations is evidence that it exists.
A useful register names more than the company. Each entry should carry the processing activity, the country, the category of data and the date the supplier was added.
Registers are also the input to everything else. Transfer assessments, audit planning and incident response all depend on knowing who is actually in the chain.
Key takeaways
- The register is a maintained list; the sub-processor clause is the contractual right behind it.
- Each entry needs activity, location, data category and the date of addition.
- Notification of changes should be advance, not simultaneous with the change.
- An objection right is only meaningful if it carries a consequence when exercised.
How it works
The provider maintains the list, publishes or supplies it, and notifies clients before adding anyone new. The client reviews each addition against its own transfer and risk position.
The obligation begins in law. A processor “shall not engage another processor without prior specific or general written authorisation of the controller”, which is what makes the register necessary at all.
| Field | Why it is needed | Commonly omitted |
|---|---|---|
| Supplier name and entity | Identifies the legal counterparty | Group name only, not the entity |
| Processing activity | Scopes what they actually do | Described too broadly |
| Country of processing | Drives transfer analysis | Region given instead of country |
| Data categories | Sizes the exposure | Left blank |
| Date added or removed | Supports incident timelines | Never recorded |
The date field is the one nobody keeps — without it, a buyer investigating an incident cannot establish who was in the chain on the day it happened.
Protections must follow down the chain. The same obligations “shall be imposed on that other processor by way of a contract or other legal act”, so the register should confirm that flow-down is in place.
Regulators treat the written contract as the foundation. UK guidance states that whenever a controller uses a processor, “a written contract needs to be in place between the parties”.
Examples
Registers are simple documents that reveal a great deal about a provider’s discipline. The four cases below show what good and poor practice looks like in outsourcing.
A provider publishes a dated register at a stable web address and emails clients 30 days before any addition. The sub-processor clause gives clients an objection window that actually works.
A buyer asks for a register and receives a list of six company names with no countries. The right to audit clause is used to obtain the missing detail.
A provider notifies a change on the day it takes effect. The objection right is technically preserved and practically worthless, since the data has already moved.
A buyer reconciles the register against its own transfer records and finds two suppliers it never assessed. The gap is closed before the next audit cycle.
Related terms
Supplier transparency involves a right, a record and a verification mechanism. The entries below separate the provision from the artefact and from the tools that test both.
- Data processing agreement: the wider instrument in which that provision sits.
- GDPR outsourcing: the regime creating the authorisation requirement behind the register.
- Multi-vendor outsourcing: a model where several registers must be reconciled against each other.
- Vendor management outsourcing: the function that should be reading the register each quarter.
- Confidentiality clause: the obligation each listed supplier must also be bound by.
FAQ
Is a register legally required?
Not by name in most regimes, but the authorisation and flow-down duties are. A maintained list is how providers demonstrate compliance with both.
How much notice should changes get?
Thirty days before the change takes effect is a reasonable standard. Notification on the day preserves the right in form only.
What happens if a client objects?
Whatever the clause provides. A workable objection right lets the client terminate the affected service without penalty if no alternative is offered.
Should the register be public?
Publishing it is good practice and increasingly common. Where commercial sensitivity prevents it, a register supplied under the contract serves the same purpose.
Does it cover suppliers who do not touch data?
Not usually. The register covers processors handling personal data, though many buyers keep a wider supplier list for operational risk purposes.
How does this differ from a sub-processor clause?
The clause is the contractual right to be told and to object. The register is the document that carries the information the right depends on.
Providers can showcase their transparency practices at the Outsource Accelerator hubs.







Independent




