← Back to blog
Typographic composition of the term Sub-processors

AI Vocabulary

Sub-processors: how many hands touch your matters?

A sub-processor is a supplier your provider itself calls on to perform its service. You have no contract with it, and your data passes through its systems all the same. The chain typically has 3–4 links, of which you know one.

What the chain looks like

You contract with a software publisher. It hosts its service with an infrastructure provider. It calls a laboratory for the model. It may use a third party for technical monitoring, another for file storage.

Each of those links is a sub-processor. European data protection law requires them to be identified, the same obligations imposed on them by contract, and you to be informed of any change.

What the mechanism organises, and does not reduce

It organises liability in cascade: each link undertakes to the previous one, and the publisher remains answerable to you for its own suppliers' failures.

It does not, however, reduce the number of places through which information passes. That distinction is one the law does not draw and professional secrecy requires: the number of links counts as much as their strength.

Why the question arises more here than elsewhere

You accept sub-processing chains without a second thought in other areas: your email, your practice management system, your website host all have theirs.

Two differences justify particular attention here. The first is the content: what passes through is not an invoice or an appointment, it is material covered by professional secrecy. The second is the newness of the chain: model providers appeared recently, their practices change fast, and relationships between actors recombine at a pace no other area of computing has seen.

The three questions to ask

What is the complete, up-to-date list, with each party's role? It should be supplied, not merely available on request.

Where is each established, and under which jurisdiction? A link outside the European Union brings the matter within the transfer regime, with the corresponding formalities.

How will you be told of a change? A provider may change host while meeting every obligation; you still need to learn of it, and to be able to object or terminate.

A note on how to frame the request. Asking a salesperson for the list of sub-processors often produces an awkward silence; asking who hosts the service and which model is called gets an immediate answer, because those are facts everyone internally knows. The formal list follows, from the provider's legal team.

What it does not solve

Liability in cascade presupposes discovering the breach in order to invoke it. A leak at the third link of a chain you do not know is hard to detect, and the 2026 incident at a legal research provider was a reminder that such events are discovered through their consequences.

And informing data subjects falls to you, not to the sub-processor. If a link you had not identified suffers an incident, you are the one explaining it to your clients.

Why it matters to a lawyer

Because you are asking your clients to trust a chain whose length you do not know. That is an uncomfortable position, and it becomes untenable the day a client asks the question in writing.

Obtaining the list before signing costs an email. Obtaining it after an incident costs a great deal more.

← Back to blog