Ga naar inhoud

Privacy & data ·

Subprocessors: due diligence under GDPR and NIS2 in 2026

You chose your suppliers carefully, but who chose theirs? Behind every SaaS tool you use there are often dozens of subprocessors — the hosting party, the email provider, the analytics service. The GDPR requires you to keep an overview of them, and NIS2 and enterprise customers ask for assurance across the whole chain. Assessing everything equally thoroughly is impossible; the key is tiering.

Why subprocessors are a blind spot

Your data processing agreement with a SaaS supplier allows it to engage subprocessors. Fine — but responsibility for the data stays with you and your customer. If a subprocessor in a third country leaks data, you are the one who has to explain it to your customer and possibly the supervisor. Without an overview of that chain, you do not even know the risk you carry.

A practical approach

  • Register: record the chain per processor — processor → subprocessor → country → data type. That shows at a glance where your sensitive data ends up and whether it leaves the EU.
  • Tiering: classify subprocessors by risk. Tier 1 = critical (touches customer data or admin rights); tier 2 = supporting (limited or no personal data).
  • Assurance by risk: for tier 1 ask for solid evidence — a SOC 2 report, an ISO certificate or a robust data processing agreement (DPA). For tier 2 a short questionnaire often suffices.
  • Notification: agree contractually that you are informed of subprocessor changes within a reasonable period.

Link this to your GDPR records, ISO 27701 and your vendor management.

How deep should you go?

Proportionality is the key word. You need not audit every sub-subprocessor of your hosting party; that is both impossible and unnecessary. Focus your depth on tier 1: the handful of parties that can actually reach your most sensitive data. For the rest it suffices to have them in view and record the standard assurance. That way you spend your time on the risks that really matter.

The pitfall of quiet changes

SaaS suppliers change their subprocessors regularly — and not always loudly. A new subprocessor in a different jurisdiction can shift your compliance status unnoticed. So update your register at least quarterly, and where possible use your suppliers’ trust centers or subprocessor notifications to stay informed automatically. Assign a fixed owner to this register, or it will age.

What the auditor or customer wants to see

In a supplier audit or a GDPR check, people do not want a theoretical policy but your current register, the tiering logic, and the assurance evidence for your tier 1 parties. If you can also show you update it quarterly and respond to changes, you demonstrate real control over your chain — exactly what NIS2 and enterprise customers demand.

Common mistakes

  • No tiering — assessing everything equally heavily stalls; assessing nothing is a risk.
  • Filling in the register once — without a quarterly update you miss quiet subprocessor changes.
  • Looking only at the direct processor — the risk often sits a layer deeper.
  • No owner — a register without someone responsible is outdated within six months.

Getting started

Start with a register of your main SaaS suppliers and map their subprocessors. Tier them, and collect assurance for tier 1. Want to know more about privacy in the chain? See ISO 27701 or take the free readiness scan.

Deep dive in the knowledge base

Continue in ISO Ready

Manage actions, risks and evidence in one line of sight toward certification.

Visit ISO Ready

← Back to overview