The situation
A Dutch SaaS company with approximately 45 employees provides a cloud platform to over 80 business clients in the Netherlands and Belgium. The platform processes personal data such as names, email addresses, billing details and in some cases health or HR data of clients' end users.
The company uses several external services:
- Cloud infrastructure: hosting with a European cloud provider, CDN service, DNS provider
- Communication: email delivery service, helpdesk software, video conferencing platform
- Monitoring: error tracking service, log analysis platform, uptime monitoring
- Payments: payment processor, invoicing software
- Internal: HR system, payroll, office productivity suite
Each of these services is a sub-processor. The company must manage all these parties responsibly and inform clients accordingly.
The challenges
Dual role: processor and controller
The tech company is a processor on behalf of its clients, but also a controller for its own employee and business data. This requires two sets of DPAs.
Sub-processor management at scale
With over 15 sub-processors and 80+ clients that must be notified of any changes, manual management becomes unworkable.
International data flows
Some sub-processors are based outside the EEA. The company needs a valid legal basis for each transfer: adequacy decision, SCCs with TIA, or another safeguard per Art. 46.
Client expectations
Larger clients demand ISO 27001 certification, up-to-date sub-processor lists, proof of security measures and annual security questionnaires.
The approach
Step 1: Sub-processor register
The company maps all external services that process personal data, documenting name, country, data types, transfer basis and DPA status.
Step 2: Standardise DPAs
A standard DPA template compliant with Art. 28 is created and used for all clients, with client-specific data, purposes and retention periods filled in.
Step 3: Automate sub-processor notifications
When adding or replacing a sub-processor, all clients are automatically notified with a 30-day objection period. Objections are tracked centrally.
Step 4: Maintain the processing register
The processing register (Art. 30(2)) is automatically generated from client agreements and the sub-processor list, updated with every change.
Step 5: Security certificates and evidence
ISO 27001 certificates, pentest reports and SOC 2 reports are stored centrally with expiry dates. Clients can access them via the platform.
The result
- Complete overview of all 80+ client agreements and 15+ sub-processors
- Sub-processor changes communicated to all clients within a day
- Processing register always current and audit-ready
- Security certificates centrally available for client audits
- Non-EEA transfers documented with SCCs and TIA per sub-processor
- Fewer ad-hoc requests from clients: everything is in the platform
Lessons learned
- Start by mapping all sub-processors — many companies underestimate how many external services process personal data
- Standardise DPAs: a template saves legal costs and prevents inconsistencies
- Automate sub-processor notifications: manually emailing 80+ clients for every tool change is not sustainable
- Actively maintain non-EEA transfer documentation: SCCs and TIAs must stay current
- Invest in transparency: clients value an up-to-date sub-processor list and certificate vault more than a one-time PDF