underdatabehandlere
Underdatabehandler, or sub-data processor, is a term used in data protection law to describe a person or organization that processes personal data on behalf of a data controller and under the instruction of another processor. The sub-processor does not determine the purposes or means of the processing; it acts as an agent in the processing chain to help the main processor fulfill its obligations to the controller.
Legal framework and authorization
Under the GDPR, a processor may engage another processor only with the controller’s written authorization. If
The relationship between controller, processor, and sub-processor must be governed by written data processing agreements. These
Sub-processors must implement appropriate technical and organizational measures to protect personal data. If data are transferred
The processor remains liable to the controller for the acts or omissions of the sub-processor performed on
In practice, underdatabehandlere are common in service delivery, cloud, and outsourcing arrangements, where specialized providers handle