![]()
Data protection in subcontracting refers to the set of contractual and technical obligations that apply whenever a service provider processes personal data on behalf of a data controller, acting on the controller's instructions. Under Article 28 of the GDPR, this framework requires a written contract-often called a DPA (Data Processing Agreement)-that formalizes the processor's guarantees before any processing begins. Without this contract, neither the controller nor the processor is compliant, regardless of the technical quality of the service delivered.
Three actions are immediately required of every data controller:
- Qualify the roles: for each service provider, verify whether it acts as a processor or as a joint controller by analyzing who determines the purposes and essential means of processing.
- Formalize the guarantees: require a signed DPA incorporating the mandatory clauses of Article 28.3 of the GDPR before granting any access to data.
- Inventory sub-processors: identify the complete processing chain, including the service providers your processor itself engages.
Table of contents
- Controller, processor, sub-processor: who does what?
- What legal obligations does the GDPR impose on both parties?
- How to draft a subcontracting agreement (DPA) compliant with Article 28?
- What technical and organizational measures should be implemented?
- How to select and monitor a processor over time?
- Who is liable in case of a breach, and what penalties do you face?
- Priority action plan: what to do right now?
- Key points
- Subcontracting compliance is a competitive advantage, not a constraint
- Safe-doc helps you protect your data in subcontracting
- Official sources to consult
Controller, processor, sub-processor: who does what?
The distinction between data controller and processor is not determined by the signed contract, but by the factual reality of the processing. This is the criterion the EDPB reaffirms in its Guidelines 07/2020: the controller decides the "why" (the purposes) and the "essential how" (the determining means); the processor executes on instructions, with no discretion on these two points.
In practice, the boundary is easily blurred. A cloud hosting provider that merely stores encrypted files according to your parameters is clearly a processor. By contrast, an HR service provider that itself determines retention periods, data recipients, or candidate profiling criteria shifts into the role of controller, even if the contract labels it as a "processor." Such reclassification exposes both parties: the service provider assumes obligations it was unaware of, and the controller loses the contractual safeguards it thought it had.
A sub-processor is a service provider that your processor in turn engages to carry out all or part of the processing. It must receive the same data protection obligations as those in your DPA, and its engagement must be authorized-explicitly or by list-by the initial controller.
Before any service begins, document the retained role in your record of processing activities. This determination must be justified by a factual analysis, not merely by the wording of the contract.
What legal obligations does the GDPR impose on both parties?
Obligations do not rest solely on the data controller. The GDPR establishes direct responsibilities for the processor on multiple points, as the CNIL details in its best practices.
What Article 28 requires of the controller
- Choose a processor offering sufficient guarantees-technical and organizational-before entrusting it with data.
- Formalize the relationship by means of a written contract (or equivalent legal instrument) incorporating the clauses of Article 28.3.
- Verify that the processor does not engage a sub-processor without prior authorization.
What the GDPR directly requires of the processor
- Process data only on documented instructions from the controller, except where required by law.
- Ensure the confidentiality of processed data, including vis-à-vis its own employees.
- Implement security measures appropriate to the risk (Art. 32 GDPR).
- Assist the controller in facilitating the exercise of data subject rights (access, rectification, erasure) and in conducting data protection impact assessments (DPIAs).
- Notify without undue delay any data breach to the controller, enabling the controller to meet the 72-hour deadline for notifying the supervisory authority.
- Return or delete the data at the end of the service, according to the controller's instructions.
- Maintain a record of processing activities carried out on behalf of controllers.
GDPR compliance in subcontracting is therefore not a mere contractual exercise: it demands a real internal organization at the processor, operational incident procedures, and the ability to produce evidence on request.
How to draft a subcontracting agreement (DPA) compliant with Article 28?
A valid DPA is not a generic template. The CNIL's processor guide provides model clauses and an operational structure. Here are the mandatory clauses and practical provisions to include.
Mandatory clauses under Article 28.3 of the GDPR
- Subject matter and duration of processing
- Nature and purpose of processing
- Type of personal data processed and categories of data subjects
- Obligations and rights of the controller
Pro tip: Draft the list of data categories with precision-"HR data" is too vague. Specify: social security numbers, health data, bank details, etc. An imprecise list weakens the contract's enforceability in the event of a dispute.
Mapping table: GDPR requirement ↔ contractual clause
| GDPR requirement (Art. 28.3) | Practical contractual clause |
|---|---|
| Processing on instructions only | Documented instructions clause + amendment procedure |
| Staff confidentiality | Confidentiality undertaking signed by authorized personnel |
| Security measures (Art. 32) | Technical annex listing TOMs implemented |
| Engagement of a sub-processor | Authorization clause (list or prior approval) + flow-down obligation |
| Assistance with data subject rights | Contractually defined timeframes and assistance procedures |
| Breach notification | Notification deadline to the controller (recommended: 24-48 hours) |
| Audit and inspection | Controller's audit rights, practical modalities (notice, scope) |
| Return/deletion of data | Deadline, format, and proof of deletion at contract termination |
| Transfers outside the EU | Applicable transfer mechanism (Standard Contractual Clauses, adequacy decision) |
For transfers outside the European Union, systematically verify the applicable mechanism: European Commission adequacy decision, Standard Contractual Clauses (SCCs) adopted by the Commission, or Binding Corporate Rules. The absence of a valid mechanism renders the transfer unlawful, regardless of the quality of the DPA.
What technical and organizational measures should be implemented?
Article 32 of the GDPR requires measures "appropriate to the risk." The CNIL specifies the expected safeguards: encryption, pseudonymization, access management, logging, and regular testing.
Priority technical measures
| Measure | Purpose | Audit evidence indicator |
|---|---|---|
| Encryption in transit (TLS) | Protect data during network exchanges | Server configuration, SSL certificates |
| Encryption at rest (AES) | Protect stored data | Architecture documentation, configuration reports |
| Data pseudonymization | Reduce risk in case of breach | Pseudonymization report, secure mapping export |
| Access management | Limit access to strict need-to-know | Access matrix, access logs |
| Logging and traceability | Detect and prove incidents | Time-stamped logs, automated alerts |
| Stateless mode (zero storage) | Eliminate persistent data at the processor | Documented architecture, audit report |
| Regular testing and audits | Verify effectiveness of measures | Penetration test reports, ISO 27001 certificates |
Pseudonymization deserves special attention. Applied upstream, before a document is transmitted to a processor or third-party tool, it significantly reduces the risk perimeter: if a breach occurs, the exposed data does not permit direct identification of data subjects. Stateless mode takes this logic further by ensuring that no data persists at the provider after processing.

Pro tip: A processor's ISO 27001 or ISO 27701 certification is a signal of maturity, but it does not replace operational evidence. Require recent access logs, dated penetration test reports, and processing architecture documentation-not just a certificate.
Safe-doc illustrates this approach: the platform pseudonymizes sensitive documents in real time, without storing any data, and generates an exportable audit report. For processing sensitive documents without storage, this stateless mode directly simplifies proof of compliance during a CNIL inspection.
How to select and monitor a processor over time?
Choosing a compliant processor is an obligation, not an option. The CNIL recommends requiring documentary evidence before signing and maintaining active oversight throughout the contractual relationship.
Selection criteria before contracting
- Existence of a documented and current security policy
- Relevant certifications (ISO 27001, ISO 27701, SOC 2)-verify their actual scope
- Incident history: has the provider suffered breaches? How were they handled?
- Ability to provide an Article 28-compliant DPA without excessive negotiation
- Data localization and transfer mechanisms if hosted outside the EU
- Incident notification procedure: timelines, contacts, channels
Documentary due diligence procedure
1. Request the security policy and business continuity plan (BCP/DRP).
2. Obtain the list of intended sub-processors and their own guarantees.
3. Verify certifications (issue date, scope, certifying body).
4. Analyze the provider's proposed DPA against the Article 28 checklist.
5. Document findings in your register and retain collected evidence.
Periodic checks during the contract
Initial selection is not enough. Contractually provide for:
- An annual audit or on-demand audit, with rights of access to premises and systems (or recourse to a mandated third-party auditor).
- Security SLA indicators: availability rate, incident notification timeframe, backup frequency.
- A periodic compliance report provided by the processor (test results, certification updates).
- DPA updates with each significant change to processing or technical architecture.
Retain all this evidence in a dedicated compliance file. In the event of a CNIL inspection, it is this file that demonstrates your diligence-not the contract alone.
Who is liable in case of a breach, and what penalties do you face?
Liability in the event of a data breach is shared, but not symmetrical. The controller is primarily accountable to data subjects and the supervisory authority. The processor incurs its own liability if it acted outside instructions or failed to meet its security obligations.
Breach notification obligations
- The processor must notify the controller without undue delay upon becoming aware of a breach-the DPA should set a specific deadline, typically 24-48 hours.
- The controller then has 72 hours to notify the supervisory authority, unless the breach is unlikely to result in a risk to data subjects.
- If the breach poses a high risk to the rights and freedoms of individuals, the controller must also inform them directly.
Penalties and case law
Administrative fines imposed by the CNIL can reach €20 million or 4% of worldwide annual turnover, whichever is higher. Contractual breaches between controller and processor also open the door to civil liability actions.
On the case law front, a judgment of the French Court of Cassation from October 2025 reaffirms the rigor of the regime applicable to processors in contractual matters: the presumption of fault and enhanced causation weigh heavily on the provider that cannot prove it respected its commitments. Although this judgment concerns a contractual context distinct from the GDPR, it illustrates the trend of French courts to tighten evidentiary requirements for processors.
For breaches involving HR data, concrete examples of GDPR violations show that processor failings systematically rebound upon the controller, even when the flaw is technical and outside the controller's direct perimeter.
Priority action plan: what to do right now?
Here are the actions to take without delay, ranked by urgency.
Priorities according to data criticality
For processing involving sensitive data (health, financial data, judicial data, HR data), strengthen controls: mandatory annual audit, end-to-end encryption, systematic pseudonymization before transmission to the processor.
For routine, moderate-risk processing, an annual documentary review and DPA update generally suffice, provided basic TOMs are in place and verifiable.
Documents to retain in your compliance file
- Signed DPA with each processor and its amendments
- Due diligence results (security policies, certifications, questionnaires)
- Audit reports and site visit minutes
- Breach notification evidence (timestamp, content, recipients)
- Updated record of processing activities
Pro tip: Retain these documents for at least 5 years after contract termination. In the event of a CNIL inspection or litigation, the burden of proof rests on you-and a deficient file equates to non-compliance in the eyes of authorities.
Key points
GDPR compliance in subcontracting rests on three inseparable pillars: factual qualification of roles, a complete DPA, and demonstrable technical measures.
| Point | Details |
|---|---|
| Role qualification | Factual reality prevails over the contract: document who determines the purposes and essential means. |
| Mandatory DPA | Article 28.3 of the GDPR requires a written contract with nine minimum clauses before any processing. |
| Technical measures (TOMs) | Encryption, pseudonymization, and logging must be provable by dated reports and logs. |
| Ongoing oversight | Schedule periodic audits and retain evidence in a dedicated compliance file. |
| Safe-doc in practice | Safe-doc pseudonymizes in real time, with no storage, and generates exportable audit reports to facilitate proof of compliance. |
Subcontracting compliance is a competitive advantage, not a constraint
GDPR compliance is often framed as a cost: contracts to draft, audits to finance, procedures to document. This is a narrow reading. For a CIO, a DPO, or a legal director managing sensitive service providers, robust governance of processors delivers concrete competitive effects.
Enterprise clients and public sector contracting authorities now demand proof of compliance before signing. A structured compliance file-with an up-to-date DPA, verified certifications, and recent audit reports-shortens sales cycles and reduces friction during tendering. Conversely, a breach at a poorly supervised processor can block a transaction, trigger a CNIL procedure, and generate costs far exceeding those of a well-run compliance program.
Operational risk reduction also hinges on technical choices. Pseudonymizing data before transmitting it to a processor, or choosing a stateless-mode provider, mechanically reduces the exposure perimeter. Less persistent data at the processor means less attack surface, less data to notify in the event of an incident, and simpler proof of compliance to produce.
My advice: do not treat processor oversight as an annual exercise. Automate what you can-alerts on expired certifications, DPA review reminders, automated collection of security reports-and focus human effort on high-risk providers. That is where vigilance produces the greatest effect.
Safe-doc helps you protect your data in subcontracting
Pseudonymizing your sensitive documents before entrusting them to a processor or an AI tool is precisely what Safe-doc does, without storing a single data point. The platform automatically detects more than 90 types of personal and confidential information (PII, financial data, HR data), replaces them with aliases in real time, and generates an exportable audit report in PDF format.

For CIOs and CISOs, the zero-storage-by-design architecture directly simplifies proof of compliance during a CNIL inspection: no persistent data at the processor, no breach risk to document. For DPOs, the pseudonymization, compliance, and audit page details how Safe-doc audit reports integrate into a GDPR compliance file. Use cases cover M&A data room analysis, HR files, legal documents, and due diligence operations.
Test the platform or request a demo directly at safe-doc.ai to see how Safe-doc integrates into your existing subcontracting chain.

Official sources to consult
These references constitute the documentary foundation of any GDPR compliance file on subcontracting. Keep them accessible for your legal and technical teams.
- Working with a processor | CNIL
- Data controller and processor: 6 best practices for respecting personal data | CNIL
- Security: Managing subcontracting | CNIL
- GDPR: How to properly identify your role | CNIL - Processor guide | CNIL (PDF)
- EDPB Concepts: controller and processor (Guidelines 07/2020)
- Legifrance - CNIL reference (official text)
- Processor's obligation of result - Court of Cassation analysis (Village Justice)
- WP169 - Controller/processor concepts (former Article 29 Working Party)
This article provides general information on the GDPR framework applicable to subcontracting in France. It does not constitute legal advice. For any specific situation, consult a lawyer specializing in data protection or your DPO, and verify the texts in force with the CNIL and on Legifrance.