4.5 Third-Party Risk Life Cycle & Sub-Processor Chains

Key Takeaways

  • Indicator III.B.1 covers identifying and assessing the risks of outsourcing processing, including contractual requirements and international transfer rules — assessment is a life cycle, not a pre-signature event.
  • Risk-tiering by data sensitivity, volume, criticality and access model is what makes vendor assessment affordable; tier drives depth, evidence and reassessment frequency.
  • GDPR Article 28(2) and (4) require the controller's prior authorisation for sub-processors and impose the same data protection obligations down the chain — fourth-party risk is the controller's risk.
  • Assurance evidence must be read, not collected: a SOC 2 report's scope, period, carve-outs and exceptions determine whether it means anything for this processing.
  • Offboarding is part of the life cycle — return or deletion of data, certificate of destruction, access revocation, and removal from the sub-processor list.
Last updated: August 2026

Outsourcing Moves the Data, Never the Accountability

Indicator III.B.1 asks the privacy manager to identify and assess risks of outsourcing the processing of personal data (e.g., contractual requirements, rules of international data transfers). The controller remains accountable for processing it has delegated, which is why the CIPM treats vendor management as a continuous life cycle rather than a signature event.

Tier before you assess

An organization with 600 vendors cannot assess all of them deeply, and the credited answer is never "assess everyone the same." Tier on four axes: data sensitivity, volume, business criticality, and access model (does the vendor hold a copy, or query under your control?).

TierProfileDue diligenceReassessment
CriticalSpecial-category or large-scale personal data, or deep systems accessFull assessment, evidence review, security review, possible on-site or live walkthroughAnnual, plus on material change
HighSignificant personal data, limited accessQuestionnaire plus assurance-report reviewAnnual or biennial
ModerateLimited personal dataStandard questionnaireBiennial
LowNo personal data accessContractual attestation onlyOn renewal

Tiering is also the defensible answer when a regulator asks why one vendor got four hours of review and another got forty.

The life cycle

  1. Intake and triage — capture what data, what purpose, which jurisdictions, before procurement negotiates price. Privacy involvement after contract signature has no leverage.
  2. Due diligence — proportionate to tier: security posture, sub-processor chain, transfer mechanism, breach history, retention and deletion capability, rights-request support, insurance.
  3. Contracting — the Article 28 terms below, plus audit rights, notification clocks, and deletion-on-termination.
  4. Onboarding — access provisioned least-privilege, integration documented in the inventory, vendor added to the disclosure log and the transfer register.
  5. Monitoring — periodic reassessment, annual assurance-report refresh, sub-processor change notifications, breach notifications, performance against SLAs.
  6. Offboarding — return or deletion of data with a certificate, access revoked, keys rotated, records updated.

Step six is the one organizations skip, and it is the one that leaves personal data sitting with a vendor nobody has a relationship with any more.

The Article 28 core

A processor contract must bind the processor to: process only on documented instructions, including on transfers; ensure personnel are under a duty of confidentiality; implement Article 32 security measures; observe the sub-processor conditions in Article 28(2) and (4); assist the controller with data-subject rights; assist with security, breach notification and DPIAs; delete or return the data at the end of the service at the controller's choice; and make available information necessary to demonstrate compliance and allow and contribute to audits.

A processor that will not accept audit rights has not merely negotiated a commercial point — it has removed the controller's ability to verify anything it was promised, which is the gap covered by competency IV.C.

Sub-processors and fourth-party risk

Article 28(2) requires the processor not to engage another processor without prior specific or general written authorisation of the controller; under general authorisation the processor must inform the controller of intended changes, giving the controller the opportunity to object. Article 28(4) requires the same data protection obligations to be imposed on the sub-processor, and the original processor remains fully liable to the controller for the sub-processor's performance.

Operationally: maintain the vendor's sub-processor list in your own records, subscribe to change notifications, and define in advance what you will do when you object — because an objection with no exit right is an opinion. A meaningful objection clause is paired with a termination right.

Reading assurance evidence critically

Collecting a SOC 2 report proves nothing. Read four things: the scope (which systems and services — is the one you use inside it?), the type and period (Type I is design at a point in time; Type II is operating effectiveness over a period), the carve-outs (sub-service organizations excluded from testing), and the exceptions and management responses. An ISO/IEC 27001 certificate similarly has a statement of applicability and a scope boundary that may exclude the relevant service. Since October 2025, ISO/IEC 27701 exists as a standalone privacy management system standard, so a vendor can hold a PIMS certification directly.

Worked scenario

A marketing platform notifies its customers that it is adding a new sub-processor in a third country in thirty days. The credited response chain is: check the contract for general or specific authorisation and the objection window; assess whether the new sub-processor changes the transfer position and whether the existing transfer impact assessment still holds; confirm the processor has flowed down equivalent obligations; update the transfer register, disclosure log and privacy notice if recipients are described; and decide, within the window, whether to accept, seek supplementary measures, or exercise the objection and termination right. Doing nothing is a decision to accept — and the exam scores it that way.

Test Your Knowledge

A processor informs its controller customers that a new sub-processor in a third country will be added in 30 days under a general written authorisation. What is the privacy manager's most complete response?

A
B
C
D
Test Your Knowledge

A vendor supplies a SOC 2 Type II report covering its core platform. The service the organization actually uses is a newer module, and the report lists the sub-service organization hosting that module as a carve-out. What should the privacy manager conclude?

A
B
C
D