Sub-processor
A sub-processor (the GDPR speaks of "another processor") is a processor engaged by a processor to carry out specific processing activities on behalf of the controller. Under Art. 28(2) GDPR the processor may not engage a sub-processor without the prior specific or general written authorisation of the controller; in the case of general authorisation, the processor must inform the controller of any intended addition or replacement, giving the controller the opportunity to object. Under Art. 28(4) the processor must impose on the sub-processor, by contract, the same data protection obligations as those set out in its own contract with the controller, and remains fully liable to the controller for the sub-processor's performance.
Sub-processor chains are long in clinical research and digital health. A CRO acting as processor for the sponsor will itself use EDC, eCOA and safety database vendors, translation agencies, cloud hosting providers, help-desk providers and freelance monitors; each of these is a sub-processor, and each may use further sub-processors such as infrastructure providers. Where a sub-processor is located in a third country, the processor must ensure a Chapter V transfer mechanism, and the controller's transfer impact assessment must extend down the chain.
Operationally, controllers should require a maintained sub-processor list (often Annex III of the SCCs or a schedule to the DPA), a notice period and objection right for changes, security and audit commitments that flow down, and breach notification timelines that leave room for the controller's own 72-hour deadline. The EDPB Opinion 22/2024 confirmed that the controller must be able to identify every sub-processor in the chain and to verify that guarantees are in place, although the depth of verification can be proportionate to risk. iliomad's vendor assessment service maps these chains for sponsors and HealthTech companies.
