Sub-processor
What is Sub-processor?
A third party engaged by a data processor to carry out specific processing activities on behalf of the data controller.
Terms that appear alongside sub-processor
Each of these is named in at least one of the same controls as sub-processor. The number is how many controls name both.
- gdpr 24 shared controls
- breach notification 23 shared controls
- audit 20 shared controls
- data protection 19 shared controls
- compliance 17 shared controls
- encryption 15 shared controls
- data subject 15 shared controls
- confidentiality 14 shared controls
Frameworks that govern sub-processor
What the standards actually require on sub-processor
Requirements naming sub-processor across 6 standards, quoted from the control text.
Sections 24-26 of the Jamaica DPA 2020 establish the framework for Joint Controllers + Processors + Sub-Processors + and Records of Processing Activities.
JM-DPA2020-Joint-Controller-Processor-Sec24-25-26-Arrangements-Allocation-Responsibilities-Contracts · Jamaica DPA 2020 Joint Controllers + Processors + Sections 24-26 + Arrangements + Allocation of Responsibilities + Contracts + Records of Processing Activities (ROPA) + Sub-Processors + Vendor Management →Third-Party AI Supplier Assurance addresses the complex AI supply chain where most enterprises consume foundation models + cloud AI services + AI-enabled SaaS rather than build from scratch.
JP-AIG-Third-Party-AI-Supplier-Assurance-Foundation-Model-Provider-AISI-Evaluation-Voluntary-Audit · Japan AI Guidelines Third-Party AI Supplier Assurance + Foundation Model Provider + AISI Evaluation + Voluntary Audit + ISO/IEC 42001 AI Management System + Sub-Processor + Cloud AI Service Provider + Open Source AI Governance →Tell the data owner which sub-processors will access their personal or sensitive data before that processing starts.
CCM-DSP-14 · Disclosure of Data Sub-processors →Section 5 of Kentucky CDPA establishes the Processor Contract framework + closely modelled on VCDPA Virginia + GDPR Article 28. (1) Section 5 Processor Definition: (a) Person processing personal data on behalf of controller;
KY-CDPA-Processor-Contracts-Section5-Confidentiality-Subprocessor-Authorisation-Audits-Sub-Processor · Kentucky CDPA Processor Contracts + Section 5 + Confidentiality + Subprocessor Authorisation + Audits + Sub-Processor Flow-Down + Documented Instructions + Data Deletion + Cooperation + Mandatory Contract Terms →Engage processors only under written contract specifying confidentiality, security measures, and processing instructions; control sub-processor chain.
AM-DPA-07 · Processor and Sub-Processor Oversight →Third-Party + Outsourcing + Cloud Service Provider cybersecurity is critical per FSA Cybersecurity Guidelines + FISC Cloud Guidelines (FISC Anzen Taisaku Kijun - Cloud Computing Edition). (1) Outsourcing Governance: (a) Outsourcing Policy + Board Approval;
JP-FSA-CYB-Third-Party-Outsourcing-Cyber-Risk-Cloud-Service-Provider-Due-Diligence-Audit-Right-Sub-Processor-Visibility-Concentration-Risk · Japan FSA Cybersecurity Third Party + Outsourcing Cyber Risk + Cloud Service Provider Due Diligence + Audit Right + Sub-Processor Visibility + Concentration Risk + Data Sovereignty + ISMAP Certification + FISC Cloud Guidelines →Questions people ask about sub-processor
What is Sub-processor?
Why is Sub-processor important for compliance?
Which compliance frameworks address Sub-processor?
Where can I learn more about Sub-processor?
See how Sub-processor applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.