Third-Party Data Processors: Managing GDPR Risk in Your Supply Chain

Manage GDPR risks across your supply chain when working with third-party data processors.Learn how to strengthen processor contracts, conduct supplier due diligence and manage sub-processors effectively. Understand Article 28 requirements, ongoing supplier monitoring and practical steps for UK GDPR compliance.
J
Julian Mercer
Aug 08, 2026
11 min read
Third-party data processors GDPR compliance banner showing processor agreements, due diligence and supply chain risk management.

Managing third-party data processors GDPR UK compliance is an essential part of modern data protection governance. Most organisations rely on external suppliers for services such as cloud hosting, payroll, CRM systems, IT support, email marketing, analytics and software platforms. When those suppliers process personal data on your behalf, outsourcing the work does not mean outsourcing your GDPR responsibilities.

Under the UK GDPR, controllers must choose processors that provide sufficient guarantees that appropriate technical and organisational measures are in place. They must also establish suitable contracts, monitor compliance and understand how personal data moves through the wider supplier chain.

For DPOs, procurement professionals and IT managers, effective supplier governance therefore requires more than signing a standard contract. It means assessing risk before onboarding, controlling sub-processors, monitoring suppliers throughout the relationship and having a clear response plan when something goes wrong.

Controller vs Processor — Why the Distinction Matters

The controller determines the purposes and essential means of processing personal data. A processor processes that information on the controller's behalf and normally acts according to the controller's documented instructions.

For example, a company may decide why and how employee payroll information is processed, making it the controller. If it appoints an external payroll provider to process that information according to its instructions, the payroll provider will usually act as a processor for that activity.

However, labels in a contract are not enough. The actual roles depend on what each organisation does. If a supposed processor starts determining its own purposes and essential means for a particular processing activity, it may become a controller for that processing.

This distinction matters because controllers and processors have different obligations and liabilities. Processors now have direct UK GDPR responsibilities of their own, but controllers remain responsible for choosing appropriate processors and demonstrating accountability for processing carried out on their behalf.

In practical terms, shared accountability across the relationship means both parties need to understand:

  • what personal data is being processed;
  • why the processing is taking place;
  • who makes key decisions;
  • which security measures are required;
  • whether other suppliers are involved;
  • where the information is processed;
  • how individual rights will be supported; and
  • what happens when the contract ends.

For organisations reviewing these responsibilities more widely, our DPO role explained guide looks at how Data Protection Officers support accountability, monitoring and organisational compliance.

What Article 28 UK GDPR Requires From Processor Contracts

A written contract or other legally binding arrangement is required whenever a controller appoints a processor to process personal data on its behalf. Article 28(3) sets out the minimum contractual requirements.

A compliant processor agreement GDPR UK arrangement must first describe:

  • the subject matter of the processing;
  • how long the processing will continue;
  • the nature and purpose of the processing;
  • the types of personal data involved;
  • the categories of data subjects; and
  • the controller's rights and obligations.

It must also include provisions requiring the processor to act only on documented instructions, ensure confidentiality, implement appropriate security measures and comply with agreed controls for appointing sub-processors.

The contract must require the processor to help the controller respond to data subject rights requests where appropriate. It must also require assistance with relevant security, breach-management and DPIA obligations and allow the controller to obtain information needed to demonstrate Article 28 compliance.

At the end of the relationship, the processor must, according to the controller's choice, return or delete relevant personal data and delete existing copies unless applicable law requires retention. Audit and inspection provisions must also be included.

This is why Article 28 GDPR explained properly is more than inserting a generic privacy clause into a supplier contract. The agreement must reflect the actual processing relationship.

Due Diligence Before Appointing a Processor

Article 28 requires controllers to use processors providing sufficient guarantees that appropriate technical and organisational measures will protect personal data and support UK GDPR compliance. Supplier assessment should therefore happen before personal data is handed over, not after an incident.

Effective supplier due diligence GDPR reviews should be proportionate to the sensitivity, scale and risk of the proposed processing.

Useful questions include:

  • What personal data will the supplier access?
    Identify whether the service involves basic contact information, financial records, employee data, children's information or special category data.
  • Where will the data be stored and accessed?
    Establish hosting locations and whether restricted international transfers may occur.
  • What security measures are in place?
    Consider encryption, access management, backups, resilience, vulnerability management and incident-response arrangements.
  • Who can access the information?
    Check staff access controls, confidentiality obligations and training.
  • Which sub-processors are involved?
    A supplier using several cloud or infrastructure providers can create a much longer processing chain than the primary contract suggests.
  • How are data subject rights supported?
    The supplier should be able to help with access, deletion, rectification and other relevant requests.
  • How quickly will breaches be reported?
    Internal contractual deadlines should give the controller enough time to assess its own regulatory obligations.
  • Can the supplier demonstrate compliance?
    Relevant policies, independent assurance, audit reports, recognised standards and security documentation may help provide evidence.

ICO audit guidance specifically recommends building risk-proportionate due diligence into procurement and considering measures such as security checks, audit requests, testing and, where appropriate, site visits.

Due diligence should therefore produce evidence, not simply a completed questionnaire.

Key Clauses Every Data Processing Agreement Should Have

A data processing agreement template can provide a useful starting point, but it should not become a substitute for understanding the processing arrangement. The clauses need to match the service, risk and supplier relationship.

Core provisions should cover:

  • Documented instructions: the processor only processes data according to the controller's documented instructions, unless otherwise required by applicable law.
  • Confidentiality: authorised personnel handling the information must be subject to appropriate confidentiality duties.
  • Security: the supplier must maintain appropriate technical and organisational measures consistent with Article 32.
  • Sub-processing: new sub-processors require the controller's specific or general written authorisation.
  • Individual rights: the processor must assist the controller in responding to applicable rights requests.
  • Breach assistance: responsibilities for detecting, investigating and communicating personal data breaches must be clear.
  • DPIA assistance: the processor should provide information and support where the controller needs to undertake a DPIA.
  • Deletion or return: personal data must be returned or securely deleted when services end, subject to applicable legal retention requirements.
  • Audit rights: the controller must be able to obtain information demonstrating compliance and conduct or commission appropriate audits and inspections.

Commercial agreements may go further by defining incident-notification times, evidence requirements, security schedules, remediation processes and allocation of contractual liability.

DPOs responsible for reviewing these arrangements need both legal awareness and practical governance skills. Our GDPR training for Data Protection Officers provides a structured next step for professionals responsible for processor governance, accountability and organisational compliance.

Sub-Processors and Onward Transfers

Modern supply chains rarely stop with one supplier. A SaaS provider may rely on a cloud hosting provider, communications platform, support service or analytics provider, each of which may handle personal data as a sub-processor.

Under Article 28, a processor must not appoint a sub-processor without the controller's prior specific or general written authorisation. Where general authorisation applies, the controller must be informed of intended additions or replacements so it has an opportunity to object.

The processor must also impose equivalent Article 28 data protection obligations on its sub-processor through a binding arrangement. Importantly, the original processor remains liable to the controller for the sub-processor's compliance with those obligations.

Organisations managing GDPR supply chain risk should therefore maintain visibility beyond their direct supplier.

Consider recording:

  • every authorised sub-processor;
  • its role and service;
  • categories of data involved;
  • processing and hosting locations;
  • international transfer mechanisms where relevant;
  • date approved;
  • changes notified by the primary processor; and
  • any risk conditions attached to approval.

International transfers require additional attention. If personal information is transferred to a processor or sub-processor outside the UK in circumstances amounting to a restricted transfer, the organisation must consider the UK GDPR's international transfer requirements alongside Article 28.

Ongoing Supplier Oversight

Due diligence is not a one-time onboarding exercise. ICO guidance states that controllers should monitor processor compliance on an ongoing basis as part of accountability, with the method and frequency depending on the circumstances and risk of the processing.

A practical supplier-monitoring programme may include:

  • annual or risk-based compliance reviews;
  • refreshed security questionnaires;
  • review of audit or assurance reports;
  • checks on major security-control changes;
  • monitoring changes to processing locations;
  • sub-processor change notifications;
  • contract renewal reviews;
  • incident and breach history;
  • outstanding remediation actions; and
  • evidence that deletion obligations are followed when services end.

The ICO's accountability audit framework also recommends keeping processor contracts current and conducting regular compliance checks to test whether suppliers are meeting contractual commitments.

Not every supplier needs the same level of scrutiny. A provider processing limited business contact information may justify lighter oversight than a cloud platform holding large volumes of customer records or special category data.

Risk tiering can help procurement, IT and privacy teams focus resources accordingly.

For technology teams managing cloud services, SaaS platforms and infrastructure vendors, our IT Compliance & GDPR for Tech Teams course can help reinforce the link between technical controls and data protection obligations. You can also explore our wider IT compliance guide for additional operational guidance.

What Happens If a Processor Has a Breach?

A supplier breach does not automatically remove the controller's responsibilities.

A processor that becomes aware of a personal data breach must notify the controller without undue delay. The processor contract should set out how this communication and assistance will work.

The controller must then assess the breach and determine whether notification to the ICO is required. Where a breach is likely to result in a risk to individuals' rights and freedoms, the controller must notify the ICO without undue delay and, where feasible, no later than 72 hours after becoming aware of it. Higher-risk breaches can also trigger obligations to communicate with affected individuals.

Controllers should therefore require processors to provide information quickly about:

  • what happened;
  • when the incident started and was discovered;
  • systems involved;
  • categories of people affected;
  • types of personal data involved;
  • approximate scale where known;
  • likely consequences;
  • containment measures; and
  • ongoing investigation and remediation.

Liability depends on the facts. A controller remains responsible for its own compliance and may face consequences where its selection, instructions, security controls or oversight were inadequate. Processors also have direct responsibilities and can be liable where they breach processor-specific duties or act contrary to lawful instructions.

This makes documented due diligence and ongoing oversight important evidence of accountability.

Training Procurement and IT Teams

Many supplier risks begin before the DPO sees a contract. Procurement may select a platform based primarily on price and functionality, while an IT team may enable a new SaaS integration without recognising that customer or employee data will be transferred to another processor.

Training should help these teams recognise GDPR issues during vendor selection rather than treating privacy as a final approval step.

Procurement and IT staff should know when to escalate questions about:

  • new processing of personal data;
  • special category or high-risk information;
  • overseas hosting;
  • unclear supplier roles;
  • extensive sub-processor chains;
  • weak security documentation;
  • missing deletion arrangements;
  • unrestricted reuse of customer data;
  • poor incident-notification terms; and
  • suppliers unwilling to support audits or compliance enquiries.

They should also understand that a signed processor agreement GDPR UK contract does not prove that a supplier is safe. Contractual commitments need to be supported by appropriate due diligence and ongoing assurance.

For organisations building stronger cross-functional knowledge, Data Protection & GDPR Compliance training can help procurement, operations and technical teams recognise their responsibilities when handling personal data.

FAQs

What is the difference between a data controller and a processor?

A controller determines the purposes and essential means of processing personal data, while a processor handles personal data on the controller's behalf and according to its documented instructions. The real activities of each organisation determine the role, not simply the label written in a contract.

What must a data processing agreement include under UK GDPR?

Article 28 requires details of the processing plus mandatory provisions covering documented instructions, confidentiality, security, sub-processors, individual rights, assistance to the controller, deletion or return of data, and audits and inspections. A generic data processing agreement template should therefore be adapted to the actual processing relationship.

Am I liable if my supplier has a data breach?

Potentially, but liability depends on the circumstances and each party's responsibility for the infringement or resulting damage. Controllers remain responsible for their own UK GDPR compliance and processor selection, while processors can also have direct liability for breaches of their own obligations or unlawful departures from controller instructions.

Do I need to approve a processor's sub-processors?

Yes. A processor needs the controller's prior specific or general written authorisation before appointing a sub-processor. Under general authorisation, the processor must notify the controller of intended changes so the controller has an opportunity to object.

How often should I review third-party suppliers for GDPR compliance?

The UK GDPR does not prescribe one universal review interval for every processor. Monitoring should be proportionate to the nature, scale and risk of the processing, with higher-risk suppliers normally receiving closer and more frequent oversight.

Strengthen your supply chain compliance. Build the knowledge needed to assess processors, review contracts and manage supplier risk confidently — explore our GDPR Training for Data Protection Officers course.

Article by:

Professional portrait of a privacy operations and third-party risk writer.

Julian Mercer

Julian Mercer is a privacy operations and third-party risk writer focused on practical compliance. He covers incident response, supplier oversight and operational controls that help organisations manage privacy risks effectively.

Start Building Your Data Protection Skills Today

Explore flexible online courses designed to help you learn, apply, and strengthen data protection knowledge at your own pace.

Browse Courses