Skip to content

Why Is Sub-Processor Due Diligence Important Under Data Protection Law?

Table of Contents

In our data-heavy world, companies often engage third parties to process personal data on their behalf. Often, a data processor will engage third-party ‘sub-processors’ to process specific personal data on behalf of a data controller (usually their customer). Several legal rules will apply under the stringent UK GDPR data protection law regime in this case. Due diligence is vital for a data processor to comply with data protection law, as it helps ensure that a sub-processor will fully safeguard a controller’s data. This article will explore sub-processor due diligence and why it is essential under data protection law. 

What Does Sub-Processing Mean?

UK GDPR compliance requires a thorough understanding of the dynamic between data controllers and processors. 

Data controllers decide how and why personal data is processed. Processors, acting on their behalf, carry out the specific instructions of the controllers. 

Processors may also involve additional ‘sub-processors’ for specific reasons, creating a data processing chain. 

Examples of data sub-processors include cloud service providers, such as Microsoft Azure or Amazon Web Services. Their services can be crucial for businesses. 

What Is Sub-Processor Due Diligence?

Under data protection law rules, data processors have a huge responsibility to ensure the security and safety of personal data when involving sub-processors. This requires careful due diligence on any third-party sub-processors brought into the data processing chain. 

Front page of publication
GDPR Essentials Factsheet

This factsheet sets out how your business can become GDPR compliant.

Download Now

Selecting a sub-processor carries significant risks. To protect themselves from liability, processors must evaluate potential sub-processors to ensure compliance with UK GDPR and enter into a robust sub-processing agreement

Due diligence involves investigating factors such as their strategies for preventing unauthorised data processing and loss, their technical security protocols, procedures for data destruction, internal controls for managing data security risks, and employee training. 

Continue reading this article below the form
Need legal advice?
Call 0808 196 8584 for urgent assistance.
Otherwise, complete this form and we will contact you within one business day.

Why Is Sub-Processor Due Diligence Important?

Sub-processor due diligence is vital for many reasons, including:

  • a processor will be fully liable to the ultimate controller for the sub-processor’s compliance with UK GDPR with respect to processing the controller’s data. If a sub-processor is at fault, the controller could claim against the processor for their omissions;
  • commercially, using a poor sub-processor could result in reputational damage for a processor. For instance, the controller customer may not want to work with a processor again if their sub-processor has caused problems, such as a data breach due to poor data security;
  • controllers must give prior authorisation for the use of sub-processors. In some cases, controllers will need to provide specific approval of a sub-processor. Robust due diligence and strong evidence of good data practices can help convince a controller to approve a particular sub-processor; and
  • generally, due diligence and documenting such efforts can help demonstrate accountability and UK GDPR compliance. 

Processors should thoroughly document their due diligence procedures, regularly conduct audits or reviews, and maintain comprehensive records of all data categories processed by sub-processors. These records should be readily accessible for data protection regulators upon request.

What Should Sub-Processor Due Diligence Involve?

Due diligence by a processor should assess how the sub-processor adheres to UK GDPR compliance, including questions such as: 

  • Is the sub-processor and its business activities UK GDPR compliant?
  • Does the sub-processor have appropriate technical and security measures to protect personal data? Are those measures sufficient for the data processing projects, e.g. if the data is high-risk?
  • Can the sub-processor comply with the same processing terms you agreed upon with the ultimate controller? You will need to ‘flow down’ your obligations to the sub-processor. 
  • Is there any risk of a data breach by the sub-processor?
  • What processes and policies do they have in place for destroying personal data?
  • Do they provide training to their staff who will handle personal data?

These are some key questions you should consider during your initial due diligence. However, once you have signed a contract with them, you should continue to review their performance by conducting regular audits and reviews to ensure they comply with their contractual obligations. 

By conducting thorough due diligence, processors can assess the sub-processors’ technical and organisational safeguards, data security practices, and overall compliance with UK GDPR. This can significantly mitigate risk and demonstrate a proactive approach to data protection.

Overall, due diligence will enable you to select appropriate sub-processor partners you can trust and rely upon. 

Key Takeaways

Sub-processor due diligence ensures compliance with data protection laws, particularly under the stringent UK GDPR regime. As companies commonly procure third-party sub-processors to handle personal data, verifying that these third-party businesses will safeguard the personal data entrusted to them becomes vital.  

Sub-processor due diligence involves assessing various factors, including the sub-processor’s compliance with UK GDPR principles, their technical and security measures, and their ability to adhere to processing terms agreed upon with the controller. 

Due diligence helps mitigate risks such as data breaches and ensures that sub-processors align with the controller’s obligations. By conducting thorough due diligence and ongoing reviews, processors can select reliable sub-processor partners and demonstrate a proactive approach to data protection, helping to foster trust and compliance within the data processing chain.

If you need advice on UK GDPR compliance and appointing a sub-processor, contact LegalVision’s experienced IT lawyers as part of our LegalVision membership. For a low monthly fee, you will have unlimited access to lawyers to answer your questions and draft and review your documents. Call us today on 0808 196 8584 or visit our membership page.

Register for our free webinars

Deal Structures 101: Understanding Equity, ASAs and Convertible Notes

Online
As a startup founder, understand your capital raising options. Register for our free webinar today.
Register Now

Common Legal Pitfalls for SaaS and Online Businesses

Online
Protect your online or SaaS business from common legal pitfalls. Register for our free webinar.
Register Now

GDPR Compliance Essentials for SMEs

Online
Ensure our business is compliant with GDPR and build trust with customers. Register for our free webinar.
Register Now
See more webinars >
Sej Lamba

Sej Lamba

Read all articles by Sej

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

We’re an award-winning law firm

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2023 Economic Innovator of the Year Finalist - The Spectator

  • Award

    2023 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2023 Future of Legal Services Innovation - Legal Innovation Awards