Independent comparison · no paid rankings
Home / Blog / Compliance / Sub-processors: retain the right to know who intervenes

Sub-processors: retain the right to know who intervenes

Your European host relies on US cloud, global CDN, offshore support — without a solid sub-processor clause, you do not know who touches your data.

Hébergeurs.eu Editorial Team 3 min read Updated Jul 19, 2026

"100% European" migration. Due diligence: the DPA lists a French host — and in the annex, US object storage, global CDN, support ticketing in India. Nobody had reread last year's sub-processor update. The internal register still showed a purely European chain.

GDPR requires your host as processor to strictly frame sub-processors. You must be able to know who intervenes, on what, and challenge a change that degrades your protection level. This is not optional legal detail for sensitive projects: it is the condition for explaining your processing chain to an auditor or enterprise client.

Clauses to require in the DPA

First require an initial list with names, countries, purpose, and data concerned — not wording like "standard industry providers." Add prior notification before any new sub-processor or processing country change. Provide an objection right with time to refuse, plus alternative or penalty-free termination for legitimate disagreement.

Flow-down imposes the same GDPR obligations cascaded to the last link. Finally, an audit mechanism — access to necessary information or third-party report — verifies the contractual promise holds in practice.

Contract gapConsequenceRequirement
No listRegister blind spotUpdated annex
No notificationLate discoveryEmail plus thirty days
No objectionRisk lock-inTermination for cause

Signing a DPA without sub-processor annex means accepting a black box.

Day-to-day operation

Subscribe to host trust center alerts. Link each sub-processor to your processing register. Cross-read backup location and Cloud Act in the contract if an American actor appears in the chain.

Compare provider transparency via the directory before renegotiation or migration.

When to renegotiate or migrate

If the host refuses prior notification, changes a critical sub-processor without notice, or adds American cloud without documented transfer mechanism, renegotiation — or migration — becomes priority. Waiting for a client audit to discover the real chain costs more than a solid clause from the start.

The peak: the "EU" stack turning multijurisdictional

Decide and move forward without blind spots

Reread your DPA and sub-processor annex this week, list gaps versus your internal register, then renegotiate notification and objection rights if needed. Use the compare tool to compare actor transparency and see Audit a hosting provider to structure your next annual review.

Frequently asked questions

What is a sub-processor?

A host's third party processing your data — datacenter, CDN, support, backup. It must be documented in the DPA and your register.

Must the host request authorization?

General or specific authorization per DPA. Require prior notification and objection right with documented alternative.

Where to find the current list?

DPA annex, trust center, or provider register. Update your register on any change.

What if a sub-processor is outside the EU?

Verify SCC, adequacy, or transfer assessment. Object if risk is incompatible with your project.


Keep the right to know before a new logo appears in the chain — not after a surprise audit.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →