Salta al contenuto principale

Practical guide

Sub-processors: managing the software vendor supply chain

When the management firm entrusts owners' data to management software, that vendor becomes a processor. But the vendor rarely works alone: it relies on cloud hosting services, email platforms, backup and bulk-sending tools. These parties are sub-processors, and the GDPR imposes precise rules for managing them. Ignoring the sub-supplier chain means not really knowing where the data ends up. This guide explains what sub-processors are, what guarantees to ask for and how to keep control, with an operational checklist.

Checklist for governing sub-processors

  1. Verify that the agreement with the vendor governs the use of sub-processors.
  2. Check that the vendor requests authorisation, general or specific, before adding sub-suppliers.
  3. Ask for an up-to-date list of sub-processors and their functions.
  4. Verify where the data centres are located and whether there are transfers outside the European Union.
  5. Ensure the sub-processors are bound by the same protection obligations as the main vendor.
  6. Provide for the right to object to a new sub-processor and the consequences of disagreement.
  7. Keep the documentation in the firm's accountability chain.

Who sub-processors are and why they matter

Article 28 of the GDPR governs the relationship between controller and processor and states that the processor may not engage another processor, the so-called sub-processor, without the controller's prior written authorisation, whether general or specific. In the condominium context the controller is the condominium, the software vendor is the processor, and the services the software relies on are the sub-processors.

The chain is almost always longer than it seems. Cloud-based software does not run on a server at the firm: it uses an infrastructure provider, often a separate backup service, and sometimes third-party platforms to send emails or communications. Each link processes, directly or indirectly, owners' data. Knowing the chain is the premise for being able to govern it.

Authorisation: general or specific

The GDPR allows two approaches. With general authorisation the controller consents in advance to the use of sub-processors, but the processor must inform it of any addition or replacement, giving the controller the chance to object. With specific authorisation each individual sub-processor must be approved before being involved.

In practice most software vendors adopt general authorisation, which is more manageable at scale. What matters is that the mechanism is clear in the agreement: how the vendor communicates changes, with what notice, and what happens if the controller, through the administrator, disagrees with a new sub-supplier. A contract silent on this point leaves the firm without tools.

  • General authorisation with a duty to give prior notice of changes.
  • The controller's right to object to a new sub-processor.
  • Reasonable notice before a sub-supplier is activated.
  • Consequences of disagreement, up to the possibility of terminating.

The guarantees sub-processors must offer

The main vendor must impose on its sub-processors, by contract, the same data protection obligations that apply to it towards the controller. Protection cannot dilute as you go down the chain: the guarantees must be equivalent at every level, and the main processor remains liable to the controller for the conduct of its sub-suppliers.

A point to check carefully is the location of the data. If a sub-processor is located in or stores data outside the European Union, you must ensure the transfer takes place on the basis of adequate safeguards. The administrator has the right to know in which countries owners' data is processed and on what legal bases.

Keeping control over time

The sub-processor chain is not static: vendors change infrastructure, add services, replace partners. That is why the list of sub-suppliers should be requested and kept in an updated version, and included in the firm's accountability file together with the main agreement. In case of a complaint or check, this documentation shows that the firm knows and controls the data supply chain.

Choosing a vendor that is transparent about its sub-processor chain is already a protective measure. Software that clearly states where data resides and which services it uses lets the firm answer owners precisely. AmministraPro's features are described on the /funzioni page and the plans on the /prezzi page.

Frequently asked questions

What is a sub-processor?

It is a party to which the processor, for example the software vendor, in turn entrusts part of the processing, such as cloud hosting, backup or sending communications. Under Article 28 of the GDPR, engaging a sub-processor requires the controller's prior authorisation, general or specific.

Must the condominium authorise the software's sub-suppliers?

Yes, as the controller. In practice authorisation is often general and is contained in the data processing agreement signed with the vendor, with an obligation on the latter to inform the administrator of changes and to recognise the right to object.

How do I find out which sub-processors my vendor uses?

By asking for the up-to-date list of sub-processors, which serious vendors make available or publish. The list should indicate the sub-supplier's name, the function performed and the location of processing. It should be kept in the accountability file and checked periodically.

What happens if data ends up outside the European Union?

Transferring data to third countries is allowed only where adequate safeguards provided by the GDPR are in place, such as an adequacy decision or suitable contractual clauses. The administrator must verify that the vendor and its sub-processors meet these conditions and keep evidence of it.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.