Subprocessor Register
A subprocessor register is a maintained list of the third-party companies that a data processor engages to help handle personal data on behalf of its customers, who are typically the data controllers. It is commonly published or shared so that those customers can see which additional parties are involved in processing their data. The register supports the requirement that a processor generally must not bring in another processor (a subprocessor) without the controller's prior written authorisation.
A subprocessor register is a governance artefact maintained by a data processor that identifies the third-party entities (subprocessors) it engages to process personal data on behalf of, and under the instructions of, the controller. Under the UK GDPR, a processor must not engage a subprocessor without the controller's prior specific or general written authorisation; where general authorisation is used, the register typically functions as the mechanism through which the controller is informed of intended additions or replacements so it may exercise any right to object. The register generally records each subprocessor's identity and the nature or purpose of the processing (for example hosting, email, support, or localisation services). This entry describes the register as an accountability and transparency tool and does not address the specifics of subprocessor contractual flow-down clauses, cross-border transfer mechanisms, retention obligations, or enforcement consequences, and treatment may differ under the EU GDPR and other regimes such as the CCPA/CPRA. Maintaining a register does not by itself establish valid authorisation; demonstrable evidence of the controller's authorisation and of appropriate contractual arrangements is generally required.
Why it matters
A subprocessor register addresses a structural feature of modern data processing: a processor rarely handles personal data entirely on its own infrastructure. It typically relies on a chain of further third parties for hosting, email, customer support, localisation, and similar services. Under the UK GDPR, a processor generally must not engage another processor without the controller's prior specific or general written authorisation, and the register is the practical mechanism through which many processors surface those onward engagements to their controller customers. Without such visibility, a controller cannot meaningfully assess or object to who else is involved in processing data for which it remains accountable.
The register also serves an accountability function. Controllers under governance frameworks generally need demonstrable evidence, not merely stated intent, that onward processing is authorised and appropriately governed. A published or shared register helps a controller track additions and replacements of subprocessors and, where general authorisation is used, exercise any right to object. It is worth stressing that maintaining a register does not by itself establish valid authorisation or compliant contractual arrangements; it is a transparency and record-keeping artefact that supports those obligations rather than substituting for them.
Who it's relevant to
Inside Subprocessor Register
Common questions
Answers to the questions practitioners most commonly ask about Subprocessor Register.