A controller signs a processing agreement that gives its processor a general written authorisation to engage sub-processors. The processor later adds two sub-processors deep in its supply chain. The controller's compliance team, mindful of recent EDPB guidance on controller and processor obligations along a processing chain, asks what the controller itself must still do despite having granted the general authorisation. Which obligation continues to rest on the controller?
- ANothing further, because a general written authorisation transfers full responsibility for vetting every sub-processor onto the lead processor alone
- BPersonally negotiate and sign a separate Article 28 contract directly with each sub-processor before that sub-processor may begin work
- CNotify the lead supervisory authority of each new sub-processor and obtain its prior approval before processing may continue
- DVerify that sufficient guarantees are provided throughout the chain and be able to demonstrate it, retaining the means to obtain information about the sub-processors engaged Correct
Why A is wrong: This is the common misreading the guidance warns against; a general authorisation lets the processor add sub-processors without case-by-case sign-off, but it does not extinguish the controller's own accountability for the chain.
Why B is wrong: Article 28(4) requires the back-to-back contractual obligations to be imposed by the processor on its sub-processor, not signed directly by the controller; the controller is not made a party to each sub-processor contract.
Why C is wrong: There is no GDPR requirement to seek supervisory authority approval for adding sub-processors; the control mechanism is the controller's own verification of guarantees and the processor's contractual flow-down, not regulator pre-clearance.
Why D is correct: EDPB Opinion 22/2024 confirms that the controller's duty under Article 28(1) to use only processors offering sufficient guarantees extends across the whole chain; the controller must be able to verify and demonstrate this and should be able to obtain the identities of sub-processors, even under a general authorisation.