Sub-Processor Onward Transfer
A sub-processor is a processor that another processor hires to help handle personal data on a controller's behalf. A sub-processor onward transfer happens when personal data that has already been transferred to one organisation is passed on further to such a sub-processor, typically located in another country. Where that further transfer crosses the relevant borders, it generally needs its own safeguards and contractual conditions rather than relying only on the original arrangement.
A sub-processor onward transfer refers to the further transmission of personal data from a processor to a sub-processor (a processor engaged by another processor) in circumstances involving a restricted or international transfer. Under the ICO's international transfer guidance, an onward transfer generally occurs when an organisation located outside the UK, having received a restricted transfer, transfers that data further. Such onward transfers are typically expected to be governed by appropriate transfer tools and by contractual terms; ICO guidance indicates that controllers may prohibit or impose conditions on onward transfers within their contract with the processor, and should consider whether contractual limits of liability are sufficient. Within the EU Standard Contractual Clauses framework, where a processor wishes to engage a sub-processor, the parties may arrange for the sub-processor to adhere to the initially concluded SCCs (Module 3, processor-to-processor). Some SCC provisions also contemplate that an onward transfer may proceed on specific grounds, such as where it is necessary to protect the vital interests of a data subject or another natural person, with any onward transfer remaining subject to applicable conditions. The precise transfer mechanisms, adequacy positions, and required supplementary measures evolve over time and differ between the UK GDPR and EU GDPR regimes; practitioners should verify the current position against the applicable official texts and regulator guidance.
Why it matters
Sub-processor onward transfers are a common weak point in data protection compliance because responsibility can become diffuse as data moves down a supply chain. A controller may carefully vet its direct processor and put appropriate transfer tools in place, only for that processor to engage a sub-processor in a third country whose safeguards were never separately assessed. Where the further transfer crosses the relevant borders, it generally requires its own lawful transfer mechanism and contractual conditions, rather than resting on the assumption that the original arrangement automatically covers everyone downstream.
The issue matters for accountability. ICO guidance indicates that controllers may prohibit or impose conditions on onward transfers within their contract with the processor, and should consider whether contractual limits of liability are sufficient. In practice this means the contractual chain has to be constructed deliberately, so that obligations flow from controller to processor to sub-processor without gaps. Under the EU Standard Contractual Clauses framework, where a processor wishes to engage a sub-processor, the parties may arrange for the sub-processor to adhere to the initially concluded SCCs using Module 3 (processor-to-processor), which is one recognised way of extending safeguards to the next link in the chain.
Because transfer mechanisms, adequacy positions, and expectations around supplementary measures evolve over time and can diverge between the UK GDPR and EU GDPR regimes, a snapshot of what is permissible today should not be treated as settled or permanent. Organisations should verify the current position against the applicable official texts and regulator guidance before relying on any particular route for a sub-processor onward transfer.
Who it's relevant to
Inside Sub-Processor Onward Transfer
Common questions
Answers to the questions practitioners most commonly ask about Sub-Processor Onward Transfer.