Skip to main content
Category: Data Transfers

Sub-Processor Onward Transfer

Also known as: Onward Transfer to a Sub-Processor, Sub-Processor Transfer
Simply put

A sub-processor is a processor that another processor hires to help handle personal data on a controller's behalf. A sub-processor onward transfer happens when personal data that has already been transferred to one organisation is passed on further to such a sub-processor, typically located in another country. Where that further transfer crosses the relevant borders, it generally needs its own safeguards and contractual conditions rather than relying only on the original arrangement.

Formal definition

A sub-processor onward transfer refers to the further transmission of personal data from a processor to a sub-processor (a processor engaged by another processor) in circumstances involving a restricted or international transfer. Under the ICO's international transfer guidance, an onward transfer generally occurs when an organisation located outside the UK, having received a restricted transfer, transfers that data further. Such onward transfers are typically expected to be governed by appropriate transfer tools and by contractual terms; ICO guidance indicates that controllers may prohibit or impose conditions on onward transfers within their contract with the processor, and should consider whether contractual limits of liability are sufficient. Within the EU Standard Contractual Clauses framework, where a processor wishes to engage a sub-processor, the parties may arrange for the sub-processor to adhere to the initially concluded SCCs (Module 3, processor-to-processor). Some SCC provisions also contemplate that an onward transfer may proceed on specific grounds, such as where it is necessary to protect the vital interests of a data subject or another natural person, with any onward transfer remaining subject to applicable conditions. The precise transfer mechanisms, adequacy positions, and required supplementary measures evolve over time and differ between the UK GDPR and EU GDPR regimes; practitioners should verify the current position against the applicable official texts and regulator guidance.

Why it matters

Sub-processor onward transfers are a common weak point in data protection compliance because responsibility can become diffuse as data moves down a supply chain. A controller may carefully vet its direct processor and put appropriate transfer tools in place, only for that processor to engage a sub-processor in a third country whose safeguards were never separately assessed. Where the further transfer crosses the relevant borders, it generally requires its own lawful transfer mechanism and contractual conditions, rather than resting on the assumption that the original arrangement automatically covers everyone downstream.

The issue matters for accountability. ICO guidance indicates that controllers may prohibit or impose conditions on onward transfers within their contract with the processor, and should consider whether contractual limits of liability are sufficient. In practice this means the contractual chain has to be constructed deliberately, so that obligations flow from controller to processor to sub-processor without gaps. Under the EU Standard Contractual Clauses framework, where a processor wishes to engage a sub-processor, the parties may arrange for the sub-processor to adhere to the initially concluded SCCs using Module 3 (processor-to-processor), which is one recognised way of extending safeguards to the next link in the chain.

Because transfer mechanisms, adequacy positions, and expectations around supplementary measures evolve over time and can diverge between the UK GDPR and EU GDPR regimes, a snapshot of what is permissible today should not be treated as settled or permanent. Organisations should verify the current position against the applicable official texts and regulator guidance before relying on any particular route for a sub-processor onward transfer.

Who it's relevant to

Controllers
Controllers determine whether and how their processors may engage sub-processors and pass data onward. ICO guidance indicates they can prohibit or impose conditions on onward transfers in their contract, and should consider whether contractual limits of liability across the chain are sufficient. They remain accountable for ensuring appropriate safeguards apply wherever the data ultimately travels.
Processors engaging sub-processors
A processor that hires a sub-processor is the party arranging the onward step. Where the further transfer is a restricted or international transfer, the processor typically needs to put an appropriate transfer tool in place, such as arranging for the sub-processor to adhere to the initially concluded SCCs using Module 3, and to flow down the relevant contractual obligations.
Data protection officers and compliance leads
Those responsible for oversight need to map sub-processing chains, confirm that each onward transfer rests on a valid mechanism, and monitor changes in adequacy positions and transfer tools. Because expectations evolve and can differ between the UK GDPR and EU GDPR, they should periodically re-verify arrangements against current regulator guidance rather than treating past sign-off as permanent.
Legal and contracting teams
Legal teams draft and negotiate the clauses that govern onward transfers, including prohibitions, conditions, and liability provisions. They need to ensure the contractual chain from controller to processor to sub-processor is coherent and that any permitted grounds for onward transfer, such as protecting the vital interests of a data subject or another natural person, are correctly reflected and remain subject to applicable conditions.

Inside Sub-Processor Onward Transfer

Sub-Processor
A processor engaged by another processor to carry out specific processing activities on behalf of the controller. Under Article 28 GDPR, a processor may generally only engage a sub-processor with the controller's prior specific or general written authorisation, and must flow down data protection obligations equivalent to those in its own agreement with the controller.
Onward Transfer
A further transfer of personal data from an initial recipient (for example, a processor) to a subsequent recipient (a sub-processor), which may occur within the same jurisdiction or across borders. Where the sub-processor is located outside the EEA, or where data moves beyond the original importing country, the onward transfer typically triggers Chapter V transfer requirements in addition to Article 28 obligations.
Chain of Contractual Obligations
The flow-down of data protection terms from controller to processor and then to sub-processor. The initial processor generally remains fully liable to the controller for the performance of the sub-processor's obligations, so the contractual chain must ensure equivalent protections are preserved at each link.
Transfer Mechanism for Onward Transfers
Where an onward transfer crosses into a third country without an adequacy decision, an appropriate transfer tool is typically required, such as Standard Contractual Clauses (including their onward transfer provisions), Binding Corporate Rules, or another Chapter V mechanism. The applicable mechanism and any supplementary measures should be assessed for the specific transfer; these tools evolve and should be verified against current official text.
Authorisation and Notification
The controller's right to authorise sub-processors, whether by specific approval or via a general authorisation with prior notice of intended changes and an opportunity to object. This governs whether and how a sub-processor may be added to the chain.
Transfer Impact Assessment (Contextual)
An assessment of the laws and practices in the destination country of the onward transfer to determine whether the chosen transfer tool provides an essentially equivalent level of protection, and whether supplementary measures are needed. The scope and expectations for such assessments continue to develop through regulator guidance and case law.

Common questions

Answers to the questions practitioners most commonly ask about Sub-Processor Onward Transfer.

Does a sub-processor's onward transfer require fresh consent from the data subject each time?
Generally no. Consent is only one of several Article 6 bases and is not a universal requirement for engaging a sub-processor or for onward transfers. The lawfulness of a sub-processor's onward transfer typically depends on the controller's original legal basis, the processor's compliance with Article 28 obligations (including obtaining the controller's authorisation for sub-processors), and, where the transfer leaves the EEA, the use of an appropriate transfer mechanism. Treating each onward transfer as needing separate data subject consent is a common misconception; the position is instead governed by the contractual chain and applicable transfer tools, subject to assessment.
Is a sub-processor the same as a controller once it receives and further transfers the data?
Not typically. A sub-processor generally remains a processor acting on behalf of the original processor and, ultimately, the controller, and does not become a controller merely by receiving or onward transferring the data. Roles turn on who determines the purposes and means of processing rather than on the fact of transfer. A party could take on controller responsibilities if it begins to determine purposes and means for its own ends, but that is a factual assessment. Conflating a sub-processor with a controller misstates the allocation of responsibilities in the processing chain.
How should the controller's authorisation of sub-processors be documented in practice?
Article 28 requires that a processor not engage a sub-processor without the controller's prior specific or general written authorisation. In practice this is typically documented within the Data Processing Agreement, using either a named list of approved sub-processors or a general authorisation coupled with a notification-and-objection process for changes. Where general authorisation is used, the processor generally informs the controller of intended additions or replacements so the controller can object. Organisations should verify the specific drafting against their DPA and the current text of the Regulation.
What contractual terms should flow down to a sub-processor?
The processor generally must impose on the sub-processor, by contract or other legal act, data protection obligations that are substantially the same as those in the processor's own agreement with the controller, in particular those required under Article 28. This typically includes obligations on security, confidentiality, assisting with data subject rights and breach handling, and restrictions on further sub-processing. The processor generally remains fully liable to the controller for the sub-processor's performance. Exact flow-down wording should be checked against the governing DPA.
What should be in place before a sub-processor transfers personal data outside the EEA?
For transfers outside the EEA, an appropriate transfer mechanism generally needs to be in place, such as an adequacy decision covering the destination, Standard Contractual Clauses, or Binding Corporate Rules where applicable, potentially supported by supplementary measures identified through a transfer risk assessment. Because adequacy decisions, transfer tools, and expectations around supplementary measures evolve, and because UK GDPR arrangements can differ, the chosen mechanism should be validated against the current position for the relevant jurisdiction at the time of the transfer.
How can a controller maintain oversight of onward transfers deep in the sub-processing chain?
Controllers typically maintain oversight through the DPA and its flow-down requirements, an up-to-date list of authorised sub-processors, notification rights for changes, audit and information rights, and records of the transfer mechanisms applied at each link. Because the processor generally remains responsible to the controller for its sub-processors, contractual visibility down the chain is important. The degree of oversight expected can vary with the risk of the processing and may be subject to differing regulator expectations, so approaches should be assessed case by case.

Common misconceptions

Once the controller-to-processor transfer is covered by a transfer mechanism, the onward transfer to a sub-processor in a third country is automatically covered too.
Each onward transfer generally needs to be considered on its own footing. Transfer tools such as Standard Contractual Clauses contain specific onward transfer provisions, and a further transfer into a third country without adequacy typically requires an appropriate mechanism and, subject to assessment, supplementary measures for that leg of the chain.
A processor can freely appoint sub-processors and pass data down the chain as it sees fit.
Under Article 28 GDPR, engaging a sub-processor generally requires the controller's prior specific or general written authorisation, the flow-down of equivalent data protection obligations, and, in most cases, the initial processor remaining liable to the controller for the sub-processor's performance.
Consent from data subjects is always the legal basis needed to permit an onward transfer to a sub-processor.
Sub-processing and onward transfers are governed primarily by Article 28 (contractual controls) and, where applicable, Chapter V (transfer mechanisms). The lawfulness of the underlying processing rests on one of the Article 6 bases, which need not be consent; treating consent as a universal requirement conflates distinct concepts.

Best practices

Maintain an up-to-date inventory of all sub-processors in the chain, including their locations, to identify which onward transfers cross into third countries and may trigger Chapter V requirements.
Ensure written contracts flow down data protection obligations equivalent to those between controller and processor at each link, consistent with Article 28.
Confirm the authorisation model with the controller (specific or general), and where general authorisation applies, provide prior notice of intended sub-processor changes and an opportunity to object.
For onward transfers into third countries without an adequacy decision, select an appropriate transfer tool and document a case-specific assessment of destination-country laws and any supplementary measures, verifying the tools against the current official text.
Preserve records demonstrating the contractual chain and transfer assessments, recognising that the initial processor generally remains liable to the controller for its sub-processors.
Periodically review the transfer chain, as adequacy decisions, transfer mechanisms, and regulator guidance evolve and a prior position may no longer reflect the current requirements.