Sub-Processor
A sub-processor is a third party engaged by a data processor to process personal data on behalf of the data controller. Under GDPR, processors must obtain prior written authorization from the controller before engaging sub-processors, and must ensure sub-processors meet the same data protection obligations.
Why It Matters
In AI agent architectures, sub-processor chains can emerge unexpectedly. If an agent governance platform (processor) routes traffic through a cloud provider (sub-processor), and that traffic contains personal data, the cloud provider becomes a sub-processor with GDPR obligations.
For EU buyers, sub-processor management is a procurement blocker. Security teams evaluate the entire chain of entities that handle personal data and require DPAs at each link. A gateway that routes PII through multiple third-party services creates a long sub-processor chain that complicates compliance.
Self-hosting the gateway component and keeping personal data within the customer's infrastructure shortens the sub-processor chain to its minimum, which is often the decisive factor for regulated EU buyers.