---
title: "Free Subprocessor Register Template (2026) — GDPR, Excel"
description: "Subprocessor list template with transfer mechanism, data categories, chain visibility and change-notice tracking columns. Free XLSX, no email gate."
canonical: https://www.orbiqhq.com/templates/gdpr-subprocessor-register
html: https://www.orbiqhq.com/templates/gdpr-subprocessor-register
publisher: Orbiq GmbH
language: en
---
# Free Subprocessor Register Template (2026) — GDPR, Excel

Subprocessor list template with transfer mechanism, data categories, chain visibility and change-notice tracking columns. Free XLSX, no email gate.


**This free subprocessor register template is a downloadable Excel workbook (plus PDF field guide and machine-readable Markdown) holding the subprocessor list GDPR Article 28(2) and [EDPB Opinion 22/2024](https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222024-on-certain-obligations-following-from-the_en) expect a processor to maintain: every subprocessor in the chain with identity, registered address, service, data categories, processing locations, transfer mechanism and security guarantees — plus a change log that tracks each notice, objection deadline and outcome, and a due-diligence log for the ongoing "sufficient guarantees" record. Ungated, with worked example rows.**

Most SaaS companies technically have a subprocessor list. It lives in a PDF annex to the DPA, names first-tier vendors only, and was last updated when someone remembered. Since EDPB Opinion 22/2024, that pattern fails on three counts at once: the list must cover the **whole chain**, must be **current at all times**, and a silent page update discharges nothing unless it is **paired with an active alert** that reaches controllers in time to object. This register is built so those three duties fall out of normal use — the change notice itself is a separate document, covered by our [subprocessor change notice template](/templates/gdpr-subprocessor-change-notice); this register is the source those notices are generated from.

## Key takeaways

1. **One row per subprocessor — including sub-subprocessors.** EDPB Opinion 22/2024 expects controllers to be able to identify every actor in the chain. The register's "Engaged by" and "Chain tier" columns record who engaged whom, so a second-tier data-centre operator is as visible as your cloud provider.
2. **The register is the source; the public page is a projection.** Rows with status *Active* or *Announced — objection window open* are your public subprocessor list; removed subprocessors keep their history. That ordering — update the register, then notify — is what makes the list auditable.
3. **Transfers are a column, not a footnote.** Every row records the mechanism — EEA-only, adequacy decision, or [SCCs under Decision (EU) 2021/914](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj) with a transfer impact assessment date — so a controller can run its own Chapter V analysis from your list alone.
4. **Due diligence is ongoing, not onboarding-only.** The workbook's third sheet logs each assessment — certifications verified, TOMs reviewed, TIA date, whether the subprocessor disclosed its own chain — with a next-review date, matching the EDPB's reading that Article 28(1) guarantees must be verified continuously.
5. **The change log is your Article 28(2) evidence.** Notice reference, send date, channels, objection deadline, objections received, outcome: when a controller (or auditor) asks who was told what and when, this sheet answers.

## What's inside the workbook

| Sheet | What it holds | Why it matters |
|---|---|---|
| **Subprocessor Register** | 18 columns per subprocessor: identity, address, country, contact, service description, data categories, special-category flag, processing locations, transfer mechanism + detail, security guarantees, chain parent, chain tier, flow-down contract date, status, effective date, last verified, notice reference | The EDPB-expected field set plus the operational columns that keep it maintainable |
| **Change Log** | One row per addition, replacement, removal or material change: notice ref, send date, channels, controllers in scope, objection deadline, objections, outcome, effective date | Evidence that the Article 28(2) opportunity to object was real |
| **Due Diligence Log** | Assessment date, assessor, guarantees reviewed, certifications verified, TOMs reference, TIA date, sub-subprocessor disclosure, result, conditions, next review due | The ongoing "sufficient guarantees" record behind each row |

Dropdown validations cover transfer mechanism (six options from *None — EEA only* to *Art 49 derogation*), status (*Active / Announced / Offboarding / Removed*), chain tier, change type, and assessment result. Example rows use a fictional Berlin SaaS company — Aurora Software GmbH — with a Swiss hosting provider, a US email vendor on SCCs, a Dutch support tool mid-objection-window, and a second-tier German data-centre operator, so you can see the chain-visibility model filled in.

The [machine-readable Markdown variant](/downloads/templates/gdpr-subprocessor-register.md) carries the full field definitions and enums, plus agent workflow rules — how to project the public list, the add-a-subprocessor sequence, and register health checks — so internal tooling or an AI agent can maintain the register alongside your [RoPA](/templates/gdpr-ropa-template) and change notices.

## How to use it

1. **Load the current state.** Enter every existing subprocessor — then ask each of them for *their* subprocessor lists and add the material ones as second-tier rows. If a vendor cannot tell you its own chain, that is a due-diligence finding, not a formatting problem.
2. **Complete the transfer columns honestly.** "US vendor, SCCs" is not enough: record the SCC module, the TIA date, and any supplementary measures. For subprocessors relying on the EU–US Data Privacy Framework, note that the General Court dismissed the Latombe challenge in September 2025 but the appeal is pending before the CJEU — SCCs plus a TIA remain the resilient default.
3. **Publish the projection.** Mirror the *Active* and *Announced* rows to your public subprocessor page or Trust Center. The page and the register must never disagree — controllers who click through from a notice should see exactly what they were told.
4. **Run changes through the sequence.** Due diligence → register row with status *Announced* → [change notice](/templates/gdpr-subprocessor-change-notice) sent and logged → status *Active* only after the objection deadline passes with objections resolved. The workbook's status values encode the sequence so it cannot silently be skipped.
5. **Keep the review clock running.** Each due-diligence row carries a next-review date. Re-verify certifications at renewal, re-check the sub-subprocessor disclosure, and refresh TIAs when the legal landscape moves.

## The legal basis behind each column

- **[GDPR Article 28(2)](https://eur-lex.europa.eu/eli/reg/2016/679/oj)** — prior written authorisation, general or specific, for engaging another processor; under general authorisation, the processor informs the controller of intended additions or replacements and gives the opportunity to object. The status and notice-reference columns operationalise this.
- **Article 28(3)(d) and 28(4)** — the contract must respect the paragraph-2 conditions, and the same data-protection obligations flow down the chain, with the initial processor fully liable. The flow-down contract date column records that this actually happened, per subprocessor.
- **Article 30(2)** — the processor's own record of processing feeds from the same facts; the register's service, data-category and transfer columns are written to be reusable there, and in your controllers' Article 30 records.
- **Chapter V (Articles 44–49)** — the transfer mechanism and transfer-detail columns record the adequacy decision or safeguard per subprocessor, so the list carries its own transfer analysis.
- **EDPB Opinion 22/2024** — the field list itself: identity, address, contact, processing description, location, transfer safeguards and security guarantees for every actor in the chain, current at all times, provided proactively.

How these duties fit the broader picture — due diligence, DPA terms, controller expectations — is covered in [Subprocessor Management Under GDPR Article 28](/eu-regulations/subprocessor-management-gdpr-article-28), and the notification workflow in [GDPR Subprocessor Change Notices](/trust-center/gdpr-subprocessor-change-notices).

## UK and Norway/EEA

No structural adaptation is needed. **UK GDPR** retains Article 28 in the same form, supervised by the [ICO](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/), whose contracts guidance expects an explicit objection deadline. **Norway** applies the GDPR through the personopplysningsloven via the EEA Agreement, supervised by [Datatilsynet](https://www.datatilsynet.no/en/). The transfer column is where jurisdictions differ: EEA-to-UK transfers currently ride on the renewed UK adequacy decisions — extended in 2025 with a sunset clause of 27 December 2031 — while EEA-internal processing, including Norway, needs no mechanism at all.

## From spreadsheet to workflow

A register in Excel solves the record-keeping problem. It does not publish itself, notify subscribed controllers, enforce objection windows, or prove who was informed when. That operational layer is what a [Trust Center](/trust-center/what-is-a-trust-center) provides: [Orbiq's trust-update workflow](/platform/trust-updates) keeps the public subprocessor list always current, sends structured change notices to subscribed controllers and DPOs, tracks the objection window, and keeps the audit trail — so this template becomes the data model of a running system rather than another document to remember.

## Sources & References

1. [Regulation (EU) 2016/679 (GDPR)](https://eur-lex.europa.eu/eli/reg/2016/679/oj) — Articles 28(2), 28(3)(d), 28(4), 30(2), Chapter V.
2. [EDPB Opinion 22/2024 on certain obligations following from the reliance on processors and sub-processors](https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222024-on-certain-obligations-following-from-the_en) — adopted 7 October 2024; chain visibility, required information, always-current lists.
3. [Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses for transfers to third countries](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj) — the Article 46(2)(c) mechanism recorded in the transfer columns.
4. [Commission Implementing Decision (EU) 2021/915 — Standard Contractual Clauses between controllers and processors](https://eur-lex.europa.eu/eli/dec_impl/2021/915/oj) — Article 28(7) SCCs, including subprocessor engagement terms.
5. [ICO — Contracts and liabilities between controllers and processors](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/) — UK GDPR position on subprocessor terms and objection deadlines.
6. [Datatilsynet — Norwegian Data Protection Authority](https://www.datatilsynet.no/en/) — GDPR supervision in Norway via the EEA Agreement.

## Related Reading

- [Free Template: GDPR Subprocessor Change Notice (DOCX + email variant)](/templates/gdpr-subprocessor-change-notice) — the notice this register generates
- [GDPR Subprocessor Change Notices: The Article 28 Notification Workflow](/trust-center/gdpr-subprocessor-change-notices)
- [Subprocessor Management Under GDPR Article 28: What Controllers Actually Expect](/eu-regulations/subprocessor-management-gdpr-article-28)
- [Free Template: GDPR Record of Processing Activities (RoPA)](/templates/gdpr-ropa-template) — the Article 30 register this one feeds