Blog

Data protection in subcontracting: GDPR guide

Data protection in subcontracting refers to all the contractual and technical obligations which are imposed as soon as a service provider processes personal data on behalf of a data controller, on the latter's instructions. According to article 28 of the GDPR, this framework requires a written contract - often called a DPA (Data Processing Agreement) - which formalizes the subcontractor's guarantees before any processing. Without this contract, neither the manager nor the subcontractor is in compliance, regardless of the technical quality of the service provided.

Three actions are immediately required of any data controller:

  • Qualify the roles: check, for each service provider, whether it acts as a subcontractor or as a joint controller, by analyzing who decides on the purposes and essential means of processing.
  • Contractualize the guarantees: require a signed DPA including the mandatory information in article 28.3 of the GDPR before any access to the data.
  • Inventory subcontractors: identify the complete processing chain, including the service providers that your subcontractor engages itself.

Table of contents

Responsible, subcontractor, subcontractor: who does what?

The distinction between data controller and subcontractor is not based on the signed contract, but on the factual reality of the processing. This is the criterion that the EDPB recalls in its 07/2020 guidelines: the person responsible decides the “why” (the purposes) and the “essential how” (the determining means); the subcontractor executes on instructions, without latitude on these two points.

In practice, the border slides easily. A cloud host that simply stores files encrypted according to your settings is clearly a subcontractor. On the other hand, an HR service provider who himself decides on the retention periods, the recipients of the data or the candidate profiling criteria switches to the qualification of manager, even if the contract designates him as a “subcontractor”. The reclassification then exposes both parties: the service provider assumes obligations that he was unaware of, and the manager loses the contractual protection that he believed he had.

The subprocessor is the service provider that your subcontractor in turn engages to carry out all or part of the processing. It must receive the same protection obligations as those provided for in your DPA, and its recourse must be authorized - explicitly or by list - by the initial manager.

**Before any service, document the role chosen in your register of processing activities. This decision must be justified by a factual analysis, not just by the drafting of the contract.


What legal obligations does the GDPR impose on both parties?

The obligations do not fall solely on the data controller. The GDPR creates direct responsibility of the subcontractor on several points, which the CNIL details in its best practices.

What Article 28 imposes on the person responsible

  • Choose a subcontractor offering sufficient guarantees - technical and organizational - before entrusting them with data.
  • Formalize the relationship by a written contract (or an equivalent legal act) including the mentions of article 28.3.
  • Verify that the subcontractor does not engage a subcontractor without prior authorization.

What the GDPR imposes directly on the subcontractor

  • Process data only on documented instruction of the person responsible, unless otherwise required by law.
  • Guarantee the confidentiality of the data processed, including with regard to its own employees.
  • Implement security measures adapted to the risk (art. 32 GDPR).
  • Assist the manager in exercising the rights of data subjects (access, rectification, erasure) and in carrying out impact analyzes (AIPD).
  • Notify without delay any data violation to the person responsible, so that he or she can meet the 72-hour deadline for informing the CNIL.
  • Return or destroy the data at the end of the service, according to the instructions of the person responsible.
  • Keep a record of its processing activities carried out on behalf of those responsible.

GDPR compliance in subcontracting is therefore not a simple contractual exercise: it involves a real internal organization at the subcontractor, operational incident procedures and an ability to produce evidence on request.


How to draw up a subcontracting contract (DPA) compliant with article 28?

A valid DPA is not a generic form. The CNIL subcontractor guide provides standard clauses and an operational structure. Here are the mandatory information and practical clauses to include.

Mandatory information according to article 28.3 of the GDPR

  • Purpose and duration of processing
  • Nature and purpose of the processing
  • Type of personal data processed and categories of persons concerned
  • Obligations and rights of the data controller

Pro tip: Write the list of data categories precisely - “HR data” is too vague. Specify: social security numbers, health data, banking data, etc. An imprecise list weakens the scope of the contract in the event of a dispute.

Correspondence table: GDPR requirement ↔ contractual clause

GDPR requirement (art. 28.3)Practical contractual clause
Processing on instruction onlyDocumented instruction clause + modification procedure
Staff ConfidentialityConfidentiality commitment signed by authorized persons
Security measures (art. 32)Technical annex listing the TOMs implemented
Use of a subcontractorAuthorization clause (list or prior agreement) + obligation to pass on
Assistance for people's rightsContractually defined deadlines and assistance procedures
Breach NotificationTime limit for notification to the responsible person (recommended: 24-48 hours)
Audit and controlAudit right of the manager, practical arrangements (notice, scope)
Restitution/destruction of dataDeadline, format and proof of destruction at the end of the contract
Transfers outside the EUApplicable transfer mechanism (standard contractual clauses, adequacy decision)

For transfers outside the European Union, systematically check the applicable mechanism: adequacy decision of the European Commission, standard contractual clauses (SCCs) adopted by the Commission, or binding corporate rules. The absence of a valid mechanism renders the transfer unlawful, regardless of the quality of the DPA.


What technical and organizational measures should be put in place?

Article 32 of the GDPR requires “risk-appropriate” measures. The CNIL specifies the expected guarantees: encryption, pseudonymization, management of authorizations, logging and regular tests.

Priority technical measures

MeasurementObjectiveEvidence indicator for audit
Encryption in transit (TLS)Protect data during network exchangesServer configuration, SSL certificates
Encryption at rest (AES)Protect stored dataArchitecture documentation, configuration reports
Pseudonymization of dataReduce the risk in the event of a leakPseudonymization report, secure mapping export
Management of authorizationsLimit access to what is strictly necessaryRights matrix, access logs
Logging and traceabilityDetect and prove incidentsTime-stamped logs, automatic alerts
Stateless mode (zero storage)Eliminate persistent data at the subcontractorDocumented architecture, audit report
Regular tests and auditsCheck the effectiveness of the measuresPenetration test reports, ISO 27001 certificates

Pseudonymization deserves special attention. Applied upstream, before a document is transmitted to a subcontractor or a third-party tool, it considerably reduces the scope of risk: if a leak occurs, the exposed data does not allow the people concerned to be directly identified. Stateless mode takes this logic further by ensuring that no data persists with the provider after processing.

Hands connect a network cable inside a server rack, ensuring the connection between computer equipment.

Pro Tip: A subcontractor's ISO 27001 or ISO 27701 certification is a signal of maturity, but it does not replace operational proof. Demand recent access logs, dated penetration test reports, and processing architecture documentation - not just a certificate.

Safe-doc illustrates this approach: the platform pseudonymizes sensitive documents in real time, without storing any data, and generates an exportable audit report. For a processing of sensitive acts without storage, this stateless mode directly simplifies the proof of conformity during a CNIL inspection.


How to select and control a subcontractor over time?

Choosing a compliant subcontractor is an obligation, not an option. The CNIL recommends requiring documentary evidence before signing and maintaining active monitoring throughout the contractual relationship.

Selection criteria before contracting

  • Existence of a documented and up-to-date security policy
  • Relevant certifications (ISO 27001, ISO 27701, SOC 2) - to be verified on their actual scope
  • Incident history: has the service provider suffered violations? How did he manage them?
  • Ability to provide a DPA compliant with Article 28 without excessive negotiation
  • Data localization and transfer mechanisms if hosted outside the EU
  • Incident notification procedure: deadlines, contacts, channels

Documentary due diligence procedure

1. Request the security policy and business continuity plan (PCA/PRA).

2. Obtain a list of intended subcontractors and their own guarantees.

3. Check the certifications (date of issue, scope, certifying body).

4. Analyze the DPA proposed by the service provider with regard to the checklist in article 28.

5. Document the results in your log and retain the evidence collected.

Periodic checks during the contract

The initial selection is not enough. Contractually provide:

  • An annual audit or on request, with right of access to premises and systems (or use of a mandated third-party auditor).
  • Security SLA indicators: availability rate, incident notification time, frequency of backups.
  • A periodic compliance report provided by the subcontractor (test results, certification updates).
  • Updating the DPA with each significant change in processing or technical architecture.

Keep all this evidence in a dedicated compliance file. In the event of a CNIL inspection, it is this file which demonstrates your diligence - not the contract alone.


Who is responsible in the event of a violation, and what sanctions do you risk?

Responsibility in the event of a data breach is shared, but not symmetrical. The data controller responds primarily to the persons concerned and the CNIL. The subcontractor incurs his own liability if he acts without instructions or fails to fulfill his safety obligations.

Violation notification obligations

  • The processor must notify the data controller without undue delay as soon as it becomes aware of a violation - the DPA must set a specific deadline, generally 24 to 48 hours.
  • The manager then has 72 hours to notify the CNIL, unless the violation is unlikely to create a risk for the people concerned.
  • If the violation poses a high risk to people's rights and freedoms, the person responsible must also inform them directly.

Sanctions and case law

Administrative sanctions imposed by the CNIL can reach 20 million euros or 4% of global annual turnover, whichever is greater. Contractual breaches between manager and subcontractor also open the way to civil liability actions.

On a jurisprudential level, a judgment of the Court of Cassation of October 2025 recalls the rigor of the regime applicable to the subcontractor in contractual matters: the presumption of fault and reinforced causality weigh heavily on the service provider who cannot prove that he has respected his commitments. Although this judgment concerns a contractual context distinct from the GDPR, it illustrates the tendency of French courts to tighten evidentiary requirements towards subcontractors.

For violations involving HR data, the concrete examples of GDPR violations show that the subcontractor's shortcomings systematically affect the manager, even when the breach is technical and outside its direct scope.


Priority action plan: what to do now?

Here are the actions to take without delay, classified by urgency.

Priorities according to data criticality

For processing involving sensitive data (health, financial data, judicial data, HR data), strengthen controls: mandatory annual audit, end-to-end encryption, systematic pseudonymization before transmission to the subcontractor.

For routine, moderate-risk treatments, an annual literature review and updating of the DPA is generally sufficient, provided that the basic TOMs are in place and verifiable.

Documents to keep in your compliance file

  • DPA signed with each subcontractor and its amendments
  • Results of due diligence (security policies, certifications, questionnaires)
  • Audit reports and visit reports
  • Evidence of notification in the event of a breach (timestamp, content, recipients)
  • Updated processing activity log

Pro Tip: Keep these documents for at least 5 years after the contract ends. In the event of a CNIL inspection or dispute, the burden of proof rests on you - and an incomplete file is equivalent to a lack of compliance in the eyes of the authorities.


Key points

GDPR compliance in subcontracting is based on three inseparable pillars: the factual qualification of roles, a complete DPA and demonstrable technical measures.

PointDetails
Role qualificationFactual reality takes precedence over contract: document who decides on the essential purposes and means.
Mandatory DPA contractArticle 28.3 of the GDPR requires a written contract with nine minimum mentions before any processing.
Technical measures (TOM)Encryption, pseudonymization and logging must be provable by dated reports and logs.
Continuous monitoringSchedule periodic audits and keep evidence in a dedicated compliance file.
Safe-doc in practiceSafe-doc pseudonymizes in real time, without storage, and generates exportable audit reports to facilitate proof of compliance.

Outsourcing compliance is a competitive advantage, not a constraint

GDPR compliance is often presented as a cost: contracts to draft, audits to finance, procedures to document. This reading is short. For a CIO, a DPO or a legal director who manages sensitive service providers, solid governance of subcontractors produces concrete effects on competitiveness.

Major account clients and public ordering parties now require proof of compliance before signing. A structured compliance file, with up-to-date DPA, verified certifications and recent audit reports, shortens sales cycles and reduces friction during calls for tender. Conversely, a breach in a poorly supervised subcontractor can block a transaction, trigger a CNIL procedure and generate costs much higher than those of a well-conducted compliance program.

Reducing operational risk also involves technical choices. Pseudonymizing the data before transmitting it to a subcontractor, or choosing a service provider in stateless mode, mechanically reduces the scope of exposure. Less persistent data at the subcontractor means less attack surface, less data to notify in the event of an incident, and easier proof of compliance to produce.

My advice: don’t treat contractor monitoring as an annual exercise. Automate what you can-alerts on expired certifications, DPA review reminders, automatic collection of security reports-and focus human effort on high-risk providers. This is where vigilance has the greatest effect.


Safe-doc helps you protect your outsourced data

Pseudonymizing your sensitive documents before entrusting them to a subcontractor or an AI tool is exactly what Safe-doc does, without storing a single piece of data. The platform automatically detects more than 90 types of personal and confidential information (PII, financial data, HR data), replaces them with aliases in real time, and generates an exportable audit report in PDF format.

Safe-doc

For IT departments and RSSIs, the zero storage by design architecture directly simplifies the proof of conformity during a CNIL inspection: no persistent data at the subcontractor, no risk of leak to document. For DPOs, page pseudonymization, compliance and audit details how Safe-doc audit reports fit into a GDPR compliance file. Use cases cover M&A data room analysis, HR files, legal documents and due diligence operations.

Test the platform or request a demo directly on safe-doc.ai to see how Safe-doc fits into your existing outsourcing chain.


Safe-doc helps you protect your outsourced data - overview diagram

Official sources to consult

These references constitute the documentary basis of any GDPR compliance file regarding subcontracting. Keep them accessible for your legal and technical teams.

This article provides general information on the GDPR framework applicable to subcontracting in France. It does not constitute legal advice. For any specific situation, consult a lawyer specializing in data protection or your DPO, and check the texts in force with the CNIL and on Legifrance.

Recommendation