
Free Subprocessor Register Template (2026) — GDPR, Excel
Subprocessor list template with transfer mechanism, data categories, chain visibility and change-notice tracking columns. Free XLSX, no email gate.
Download this template
Version 1.0 · Updated Jul 20, 2026 · Free, no email required
Free Subprocessor Register Template (GDPR, Excel)
This free subprocessor register template is a downloadable Excel workbook (plus PDF field guide and machine-readable Markdown) holding the subprocessor list GDPR Article 28(2) and EDPB Opinion 22/2024 expect a processor to maintain: every subprocessor in the chain with identity, registered address, service, data categories, processing locations, transfer mechanism and security guarantees — plus a change log that tracks each notice, objection deadline and outcome, and a due-diligence log for the ongoing "sufficient guarantees" record. Ungated, with worked example rows.
Most SaaS companies technically have a subprocessor list. It lives in a PDF annex to the DPA, names first-tier vendors only, and was last updated when someone remembered. Since EDPB Opinion 22/2024, that pattern fails on three counts at once: the list must cover the whole chain, must be current at all times, and a silent page update discharges nothing unless it is paired with an active alert that reaches controllers in time to object. This register is built so those three duties fall out of normal use — the change notice itself is a separate document, covered by our subprocessor change notice template; this register is the source those notices are generated from.
Key takeaways
- One row per subprocessor — including sub-subprocessors. EDPB Opinion 22/2024 expects controllers to be able to identify every actor in the chain. The register's "Engaged by" and "Chain tier" columns record who engaged whom, so a second-tier data-centre operator is as visible as your cloud provider.
- The register is the source; the public page is a projection. Rows with status Active or Announced — objection window open are your public subprocessor list; removed subprocessors keep their history. That ordering — update the register, then notify — is what makes the list auditable.
- Transfers are a column, not a footnote. Every row records the mechanism — EEA-only, adequacy decision, or SCCs under Decision (EU) 2021/914 with a transfer impact assessment date — so a controller can run its own Chapter V analysis from your list alone.
- Due diligence is ongoing, not onboarding-only. The workbook's third sheet logs each assessment — certifications verified, TOMs reviewed, TIA date, whether the subprocessor disclosed its own chain — with a next-review date, matching the EDPB's reading that Article 28(1) guarantees must be verified continuously.
- The change log is your Article 28(2) evidence. Notice reference, send date, channels, objection deadline, objections received, outcome: when a controller (or auditor) asks who was told what and when, this sheet answers.
What's inside the workbook
| Sheet | What it holds | Why it matters |
|---|---|---|
| Subprocessor Register | 18 columns per subprocessor: identity, address, country, contact, service description, data categories, special-category flag, processing locations, transfer mechanism + detail, security guarantees, chain parent, chain tier, flow-down contract date, status, effective date, last verified, notice reference | The EDPB-expected field set plus the operational columns that keep it maintainable |
| Change Log | One row per addition, replacement, removal or material change: notice ref, send date, channels, controllers in scope, objection deadline, objections, outcome, effective date | Evidence that the Article 28(2) opportunity to object was real |
| Due Diligence Log | Assessment date, assessor, guarantees reviewed, certifications verified, TOMs reference, TIA date, sub-subprocessor disclosure, result, conditions, next review due | The ongoing "sufficient guarantees" record behind each row |
Dropdown validations cover transfer mechanism (six options from None — EEA only to Art 49 derogation), status (Active / Announced / Offboarding / Removed), chain tier, change type, and assessment result. Example rows use a fictional Berlin SaaS company — Aurora Software GmbH — with a Swiss hosting provider, a US email vendor on SCCs, a Dutch support tool mid-objection-window, and a second-tier German data-centre operator, so you can see the chain-visibility model filled in.
The machine-readable Markdown variant carries the full field definitions and enums, plus agent workflow rules — how to project the public list, the add-a-subprocessor sequence, and register health checks — so internal tooling or an AI agent can maintain the register alongside your RoPA and change notices.
How to use it
- Load the current state. Enter every existing subprocessor — then ask each of them for their subprocessor lists and add the material ones as second-tier rows. If a vendor cannot tell you its own chain, that is a due-diligence finding, not a formatting problem.
- Complete the transfer columns honestly. "US vendor, SCCs" is not enough: record the SCC module, the TIA date, and any supplementary measures. For subprocessors relying on the EU–US Data Privacy Framework, note that the General Court dismissed the Latombe challenge in September 2025 but the appeal is pending before the CJEU — SCCs plus a TIA remain the resilient default.
- Publish the projection. Mirror the Active and Announced rows to your public subprocessor page or Trust Center. The page and the register must never disagree — controllers who click through from a notice should see exactly what they were told.
- Run changes through the sequence. Due diligence → register row with status Announced → change notice sent and logged → status Active only after the objection deadline passes with objections resolved. The workbook's status values encode the sequence so it cannot silently be skipped.
- Keep the review clock running. Each due-diligence row carries a next-review date. Re-verify certifications at renewal, re-check the sub-subprocessor disclosure, and refresh TIAs when the legal landscape moves.
The legal basis behind each column
- GDPR Article 28(2) — prior written authorisation, general or specific, for engaging another processor; under general authorisation, the processor informs the controller of intended additions or replacements and gives the opportunity to object. The status and notice-reference columns operationalise this.
- Article 28(3)(d) and 28(4) — the contract must respect the paragraph-2 conditions, and the same data-protection obligations flow down the chain, with the initial processor fully liable. The flow-down contract date column records that this actually happened, per subprocessor.
- Article 30(2) — the processor's own record of processing feeds from the same facts; the register's service, data-category and transfer columns are written to be reusable there, and in your controllers' Article 30 records.
- Chapter V (Articles 44–49) — the transfer mechanism and transfer-detail columns record the adequacy decision or safeguard per subprocessor, so the list carries its own transfer analysis.
- EDPB Opinion 22/2024 — the field list itself: identity, address, contact, processing description, location, transfer safeguards and security guarantees for every actor in the chain, current at all times, provided proactively.
How these duties fit the broader picture — due diligence, DPA terms, controller expectations — is covered in Subprocessor Management Under GDPR Article 28, and the notification workflow in GDPR Subprocessor Change Notices.
UK and Norway/EEA
No structural adaptation is needed. UK GDPR retains Article 28 in the same form, supervised by the ICO, whose contracts guidance expects an explicit objection deadline. Norway applies the GDPR through the personopplysningsloven via the EEA Agreement, supervised by Datatilsynet. The transfer column is where jurisdictions differ: EEA-to-UK transfers currently ride on the renewed UK adequacy decisions — extended in 2025 with a sunset clause of 27 December 2031 — while EEA-internal processing, including Norway, needs no mechanism at all.
From spreadsheet to workflow
A register in Excel solves the record-keeping problem. It does not publish itself, notify subscribed controllers, enforce objection windows, or prove who was informed when. That operational layer is what a Trust Center provides: Orbiq's trust-update workflow keeps the public subprocessor list always current, sends structured change notices to subscribed controllers and DPOs, tracks the objection window, and keeps the audit trail — so this template becomes the data model of a running system rather than another document to remember.
Sources & References
- Regulation (EU) 2016/679 (GDPR) — Articles 28(2), 28(3)(d), 28(4), 30(2), Chapter V.
- EDPB Opinion 22/2024 on certain obligations following from the reliance on processors and sub-processors — adopted 7 October 2024; chain visibility, required information, always-current lists.
- Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses for transfers to third countries — the Article 46(2)(c) mechanism recorded in the transfer columns.
- Commission Implementing Decision (EU) 2021/915 — Standard Contractual Clauses between controllers and processors — Article 28(7) SCCs, including subprocessor engagement terms.
- ICO — Contracts and liabilities between controllers and processors — UK GDPR position on subprocessor terms and objection deadlines.
- Datatilsynet — Norwegian Data Protection Authority — GDPR supervision in Norway via the EEA Agreement.
Related Reading
- Free Template: GDPR Subprocessor Change Notice (DOCX + email variant) — the notice this register generates
- GDPR Subprocessor Change Notices: The Article 28 Notification Workflow
- Subprocessor Management Under GDPR Article 28: What Controllers Actually Expect
- Free Template: GDPR Record of Processing Activities (RoPA) — the Article 30 register this one feeds
Download this template
Version 1.0 · Updated Jul 20, 2026 · Free, no email required
Frequently Asked Questions
What should a GDPR subprocessor register include?
Following EDPB Opinion 22/2024, the register should hold, for every subprocessor in the chain: legal name and registered address, a contact point, the service and processing description, the categories of personal data, the actual processing locations, the transfer mechanism for any non-EEA processing (adequacy decision or SCCs with a transfer impact assessment), and the security guarantees supporting your Article 28(1) assessment. This template adds the operational columns — chain parent, status, effective date, and change-notice reference — that make the list maintainable.
Does the GDPR require a public subprocessor list?
Not in those words — Article 28(2) requires that controllers authorise subprocessors and, under general authorisation, be informed of intended changes with a real opportunity to object. In practice a current, accessible list is how processors discharge that duty at scale, and EDPB Opinion 22/2024 accepts a public page only if it is kept current at all times, carries the required detail, and is paired with an active alert so controllers are actually informed rather than expected to police the page.
What is the difference between a subprocessor register and a Record of Processing Activities?
The RoPA is the Article 30 record each controller and processor keeps of its own processing activities — a regulator-facing document. The subprocessor register is the processor's controller-facing list of the other processors it engages under Article 28. They overlap in content (services, data categories, transfers) but serve different audiences: DPOs use your subprocessor register to keep their own Article 30 records accurate.
How did EDPB Opinion 22/2024 change subprocessor list expectations?
The Opinion, adopted 7 October 2024, confirmed that controllers must be able to identify every actor in the processing chain — including sub-subprocessors — with identity, address and contact details, plus processing descriptions, locations, transfer safeguards and security guarantees, kept up to date at all times and provided proactively. A first-tier-only list, or one updated quarterly, no longer meets the bar.
How long should the objection window be when the register changes?
The GDPR sets no statutory period — the window comes from your DPA. European practice clusters around 15 days as the typical window, with 30–60 days commonly negotiated by enterprise and regulated controllers and 90 days increasingly rare. The EDPB's test is not the number but whether the window allows a meaningful, informed objection before the change takes effect.
Does the same register work for UK and Norwegian customers?
Yes. UK GDPR carries Article 28 in the same form, supervised by the ICO, and Norway applies the GDPR through the personopplysningsloven via the EEA Agreement, supervised by Datatilsynet. The only column that changes across jurisdictions is the transfer mechanism: EEA-to-UK transfers ride on the renewed UK adequacy decisions (extended in 2025, with a sunset of 27 December 2031), while EEA-internal processing, including Norway, needs none.