Discovery queue open Typical turnaround: one working day The register Method Talk to a reviewer
subprocessor.org
Six sources. One reviewed list. Re-checked daily.See how the work flows →
Same engine, different job to be done.Compare the tiers →
We publish observations and dated records, never legal conclusions.Read the method →
Free to read. No account.Open the register →
regulation

What each rule actually asks
of your sub-processor list.

Seven regimes, summarised for the person who has to produce something rather than cite something. Each section names its source so your counsel can check us instead of taking our word for it.

Last reviewed 17 August 2026 Scope EU, UK, US Not legal advice
RegimeApplies toWhat it wants from your listIn force
GDPR Art. 28Any processor of EU personal dataPrior notice of sub-processor changes, and a real chance to object2018
EDPB Opinion 22/2024Controllers and processorsA list kept current, with enough detail to form a viewOct 2024
DORAEU financial entities and their ICT providersThe subcontracting chain, in a register, annuallyJan 2025
NIS2Essential and important entitiesSupplier risk addressed as a security measureOct 2024
SCCs & transfersAnyone exporting EU dataWhere each entity actually processes2021
UK GDPRUK controllers and processorsThe same duty, its own regulator and transfer tools2021
CCPA / CPRABusinesses in scope in CaliforniaNamed service providers and contract flow-down2020–23

01 GDPR Article 28

the short version

Your processor cannot bring in a sub-processor without telling you first and giving you a chance to object. The law does not say how many days — your contract does.

Article 28(2) allows either specific authorisation for each sub-processor, or general authorisation with an obligation to inform the controller of intended additions or replacements, so the controller has the opportunity to object. General authorisation is what almost every SaaS contract uses in practice.

Article 28(4) requires the same data protection obligations to flow down to the sub-processor, and leaves the original processor fully liable for their performance.

What it means for your list

  • The notice period is contractual, not statutory. Fifteen to thirty days is common; your annex is what governs, and it is worth knowing which of your vendors gave you which.
  • “Informed” means informed — a change made quietly to a web page is a weak basis for saying a controller had the opportunity to object.
  • You need to be able to show, later, that you knew and what you decided. That is a record, not a recollection.

Source: Regulation (EU) 2016/679, Article 28(2) and 28(4).

02 EDPB Opinion 22/2024

the short version

Adopted October 2024. It raised the practical bar: knowing the chain, keeping the information current, and being able to act on it.

The Opinion addresses controllers’ obligations when engaging processors and sub-processors, and the expectation that a controller has the information needed to verify that appropriate safeguards exist throughout the chain — not only at the first tier.

What it means for your list

  • Depth matters. Your processor’s sub-processors are in scope of your diligence, which is why fourth-party visibility stopped being an academic concern.
  • “Current” is doing work in that sentence. A list last touched two years ago does not evidence much.
  • Being able to demonstrate the position at a past date matters as much as knowing it today.

Source: EDPB Opinion 22/2024, adopted 7 October 2024.

03 DORA

the short version

Applies since 17 January 2025. Financial entities must maintain a register of every ICT contractual arrangement — including the subcontracting chain beneath each one — and report it annually.

The Digital Operational Resilience Act requires a register of information covering all ICT third-party arrangements, with additional detail where the arrangement supports a critical or important function. The register is submitted to competent authorities, who use it to map concentration risk across the sector.

What it means for your list

  • Vendor-level is not enough. The chain beneath each vendor has to be identified, which is exactly the data a sub-processor list contains.
  • It is an annual cycle with a fixed shape, so the work is predictable — and assembling subcontracting depth by email each year is where firms consistently report losing time.
  • Concentration is the point of the exercise. Knowing that eleven of your vendors sit on the same cloud provider is the finding, not a footnote.

Source: Regulation (EU) 2022/2554, in application from 17 January 2025.

04 NIS2

the short version

Supply chain security is named as a required measure, with management accountable for it.

Directive (EU) 2022/2555 requires essential and important entities to take appropriate measures covering, among other things, supply chain security — including the relationships between each entity and its direct suppliers or service providers. Member State transposition was due by 17 October 2024, so the detail varies by country.

What it means for your list

  • Different framing, same underlying data: who is in your chain, and what changed.
  • Management bodies can be held accountable, which tends to change how quickly this gets resourced.
  • Check your own Member State’s implementation — timing and scope genuinely differ.

Source: Directive (EU) 2022/2555, Article 21(2)(d).

05 Standard Contractual Clauses and transfers

the short version

You cannot document a transfer you have not noticed. Where each entity processes is part of the list, not a separate exercise.

The 2021 Standard Contractual Clauses remain the workhorse for exports from the EEA, alongside the EU–US Data Privacy Framework where the recipient is certified. Both depend on knowing which entities are involved and where they process.

What it means for your list

  • A country column is not decoration. A sub-processor quietly moving a workload from Ireland to the United States is a transfer event.
  • Certification status changes over time, so a snapshot taken at signature is not durable evidence.
  • Dated records are what let you show which basis applied when.

Source: Commission Implementing Decision (EU) 2021/914; EU–US Data Privacy Framework adequacy decision, July 2023.

06 UK GDPR

the short version

Substantially the same duty, a different regulator, and its own transfer paperwork.

UK GDPR retains the Article 28 structure, supervised by the ICO. International transfers use the International Data Transfer Agreement or the UK Addendum to the EU SCCs. Organisations operating in both regimes generally run one list and two sets of transfer instruments.

Source: UK GDPR Article 28; ICO international transfers guidance.

07 CCPA and CPRA

the short version

Different vocabulary, overlapping evidence. “Service provider” and “contractor” carry contractual requirements that flow down.

California’s regime requires specific contract terms with service providers and contractors, including limits on use and onward disclosure, and expects businesses to disclose the categories of third parties involved. The definitions do not map cleanly onto processor and sub-processor, so the classification work matters.

What it means for your list

  • One inventory can serve both regimes if it records role and purpose, not just names.
  • The distinction between a service provider and a third party is exactly the scope judgement we make during discovery, and it is a judgement rather than a lookup.

Source: California Civil Code §1798.100 et seq., as amended by the CPRA.

08 What we do not claim

worth being blunt

Nothing on this page is legal advice, and no product makes you compliant.

These summaries exist because the same underlying evidence — who is in your chain, where they process, and what changed on which date — satisfies part of what several different regimes ask for. That is a genuine efficiency, and it is the honest limit of the claim.

We publish observations and dated records. We do not tell you whether you are compliant, we do not assert that any company is in breach, and where we cite a regulation we name it so you can read the source rather than our summary of it. Talk to your own advisers about how any of this applies to you.

One inventory. Several regimes asking for it.

Discovery is free, a named reviewer checks it, and nothing is published without your approval.