Knowledge

Subcontractors in outsourcing: how to control subprocessors and the full supply chain

A provider may deliver part of the service through partners. Keep responsibility, data and continuity visible across the entire chain.

Subcontractors in outsourcing: how to control subprocessors and the full supply chain

A company signs with one provider, but delivery rarely stops at one organisation. Postal operators, carriers, data centres, software vendors, maintenance companies or a secondary production site may all participate. Each can affect deadlines, confidentiality, quality and the ability to reconstruct what happened. Outsourcing governance must therefore extend beyond the prime contractor.

Not every subcontractor is a subprocessor under the GDPR. A subprocessor is an entity engaged by a processor to process personal data on the controller's behalf. Another partner may deliver a service without accessing personal data. The legal distinction matters, but operational governance should make both relationships visible through one current supply-chain map and risk-based controls.

A list of names is not a supply-chain map

A list answers who, but not what, where or with what consequence. For each dependency record the activity, data or mail involved, location, systems, criticality, downstream dependencies and replacement route. The NCSC recommends mapping suppliers to understand the network, manage cyber risk and perform effective due diligence.

A useful register includes the entity, role, service scope, data access, processing countries, relationship owner, assessment date, result, next review and contingency. Connect it to provider due diligence instead of maintaining a spreadsheet that is updated only before an audit.

Classify each partner before applying controls

RoleExampleKey control question
Operational subcontractorcarrier collecting sealed containersAre hand-over, responsibility and claims documented?
Subprocessorhosting or system provider with data accessIs authorisation valid and are equivalent data duties imposed?
Infrastructure supplierproduction equipment maintenanceIs technical access limited, supervised and logged?
Critical dependencyoperator required to meet a statutory deadlineHow quickly can an alternative be activated?

The same company may play different roles in different workflows. A courier carrying a sealed container may not access the contents, while a platform hosting scanned mail may be a subprocessor. Classification follows the actual activity, not the label used in a contract.

GDPR authorisation does not remove accountability

Article 28 GDPR states that a processor must not engage another processor without the controller's prior specific or general written authorisation. Under a general authorisation, the processor must inform the controller about intended changes and give it an opportunity to object. The same data-protection obligations in the main contract must be imposed on the next processor.

If the subprocessor fails, the initial processor remains fully liable to the controller for the performance of those obligations. The client should not be passed from one link to another. The prime contract needs one accountable provider that governs partners, collects evidence and remains responsible for the contracted result.

Design a workable change-approval mechanism

  • Advance notice: allow time for a real assessment before the new partner starts.
  • Complete information: identify the entity, role, service, location, data categories, safeguards and start date.
  • Objection criteria: define unacceptable locations, missing controls or concentration risk.
  • Outcome: provide an alternative, keep the current arrangement or allow termination of the affected scope.
  • Decision trail: retain the register version, risk assessment, approval and effective date.

A subcontractor replacement is a process change. Manage it through the change-request and version-control procedure, especially when it affects a system, country, lead time or reporting.

Assess in proportion to risk

Not every partner needs the same questionnaire. Depth should reflect data access, ability to stop the workflow, volume, reversibility, location and further dependencies. A label supplier with no data access may need a basic quality and continuity review. A cloud operator storing personal data needs deeper scrutiny of security, privacy, backup, incidents and transfers.

NIS2 includes supply-chain security among cybersecurity risk-management measures and calls for consideration of vulnerabilities specific to each direct supplier and the overall quality of its practices. Organisations outside its direct scope can still use this as a sound governance principle.

Nine controls that work in practice

  1. Service map: show how data, documents and physical mail move between entities.
  2. Owner: assign accountability for each relationship and review.
  3. Flow-down contract: pass through confidentiality, security, quality, audit, retention and incident duties.
  4. Least access: expose only the data and systems required for the role.
  5. Controlled hand-over: use batch IDs, counts, sealed containers and collection evidence.
  6. Incident chain: set deadlines for detection, escalation and fact sharing at every link.
  7. Evidence: collect current reports, test results, access reviews and corrective actions.
  8. Replaceability: test alternatives, data export, material return and minimum contingency capacity.
  9. Review: reassess after scope changes, incidents, relocation or material ownership changes.

Do not let incidents stall between companies

A generic requirement to report without delay is often too vague. Define a 24/7 channel for critical events, first-notice time, minimum facts, update frequency and evidence preservation. The subcontractor reports to the prime provider, which reports to the client at agreed thresholds without waiting for a complete root-cause analysis.

An annual scenario exercise reveals more than another questionnaire. Simulate a missing batch, unavailable system or incorrect data transfer and verify that every link knows its contacts, decisions and evidence. Connect the result to the business continuity plan.

Measure the chain, not only the prime provider

The client cares about the end-to-end result. The prime provider can manage partners through hand-over punctuality, discrepancies, incident notification time, evidence completeness, overdue corrective actions and continuity-test success. Detailed supplier data need not flood the client dashboard, but it should explain deviations in the service's KPIs and SLA.

Five warning signs

  • The provider cannot show a current register of partners and locations.
  • The contract permits unrestricted subprocessor changes without advance notice.
  • The provider disclaims responsibility for a partner delivering part of the contracted service.
  • Incidents are reported only after the full investigation ends.
  • There is no tested route for data return, material recovery and continuity at exit.

A 30-day implementation plan

In week one, inventory partners and flows. In week two, classify roles and risks, then close contractual and authorisation gaps. In week three, define reporting, incidents, evidence and owners. In week four, test one hand-over, one incident and one replacement scenario. Record the outcome as dated actions rather than general recommendations.

If you want to organise the delivery chain for business correspondence, printing, inserting or bulk mailing, talk to BackOffice Outsourcing about roles, evidence and reporting. A transparent partner model can increase flexibility while keeping responsibility and the end-to-end result visible.

Sources

Frequently asked questions

Is every subcontractor a subprocessor?

No. A subprocessor processes personal data on the controller's behalf under a further engagement. A partner with no such access may still be an operational subcontractor requiring quality, security and continuity controls.

Can a provider change a subprocessor without client approval?

The GDPR allows specific or general written authorisation. Under a general authorisation, the processor must inform the controller about intended changes and provide an opportunity to object.

Who is responsible for a subcontractor's failure?

The prime provider should remain responsible to the client for the contracted outcome. Under Article 28(4) GDPR, the initial processor remains liable to the controller for the subprocessor's data-protection obligations.

How often should the subcontractor register be updated?

Update it for every change and review it periodically according to risk. Reassess after an incident or a change in location, system, scope or ownership.

Talk to us

Talk to us
← Back to all articles

Let’s talk about what we can do for you and which process to improve

Verify our company

Check BackOffice Outsourcing’s current credentials on the official services.

Quality, security and business continuity

We work in line with recognised ISO standards that structure our processes and information-security practices.

9001:2015Quality management
22301:2020Business continuity
27001:2023Information security
27002:2023Information security controls