Agent skill

Sub Processor Management

by mukul975 in mukul975/Privacy-Data-Protection-Skills

GDPR Article 28(2) sub-processor approval workflow management.

Apache-2.0Auto-check passedLegal & Compliance

Install Sub Processor Management

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill sub-processor-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills sub-processor-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/sub-processor-management .claude/skills/sub-processor-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sub-processor-management
GitHub stars
295
Token cost
~2.5k tokens
SKILL.md length
1,080 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

GDPR Article 28(2) sub-processor approval workflow management.

  • Works in 5 steps: Objection grounds: Reasonable data… → Objection period: Minimum 14 calendar… → Objection format: Written notice to… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Authorization Models, Notification Requirements and Objection Mechanism, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Sub Processor Management is an agent skill from mukul975/Privacy-Data-Protection-Skills. GDPR Article 28(2) sub-processor approval workflow management. Covers prior specific and general authorization mechanisms, change notification procedures, objection windows, flow-down obligation enforcement, and sub-processor chain risk monitoring.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Authorization and RBAC. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/sub-processor-management”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Objection grounds: Reasonable data protection concerns (not arbitrary)
  2. Objection period: Minimum 14 calendar days from notification receipt (Summit Cloud Partners standard: 30 days)
  3. Objection format: Written notice to processor's designated privacy contact
  4. Resolution process: Good-faith negotiation within defined timeframe
  5. Escalation: If unresolved, termination right for affected services without penalty

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sub Processor Management loads about 2.5k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 1,080 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,080 words, ~2,483 tokens.

Download SKILL.mdSave it as .claude/skills/sub-processor-management/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
sub-processor-management
description
GDPR Article 28(2) sub-processor approval workflow management. Covers prior specific and general authorization mechanisms, change notification procedures, objection windows, flow-down obligation enforcement, and sub-processor chain risk monitoring.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
vendor-privacy-management
metadata.tags
sub-processor, article-28, flow-down-obligations, vendor-chain, processor-management

Sub-Processor Management

Overview

GDPR Article 28(2) establishes that a processor shall not engage another processor (sub-processor) without prior specific or general written authorisation of the controller. Where general authorisation is granted, the processor must inform the controller of any intended changes concerning the addition or replacement of sub-processors, giving the controller the opportunity to object. This creates an ongoing management obligation that extends through the entire processing chain.

The EDPB Guidelines 07/2020 (paragraph 93) emphasize that the controller's Article 28(1) due diligence obligation extends to oversight of sub-processor arrangements, and that the processor remains fully liable for the sub-processor's compliance.

At Summit Cloud Partners, the Sub-Processor Management Program ensures visibility and control over the entire processing chain for all vendor relationships involving personal data.

Authorization Models

Model A: Prior Specific Authorization

Under this model, the controller individually approves each sub-processor before engagement.

When to Use:

  • High-risk processing (special category data, large-scale processing, cross-border transfers)
  • Processing involving sensitive industries (healthcare, financial services)
  • When the controller requires direct assessment of each sub-processor

Process:

StepActionTimeline
1Processor identifies need for new sub-processor—
2Processor submits sub-processor details to controllerPre-engagement
3Controller conducts due diligence on proposed sub-processor15 business days
4Controller issues written approval or rejection5 business days
5If approved, processor executes sub-processor DPABefore processing begins
6Processor provides controller with confirmation of sub-processor DPA execution5 business days
Model B: General Written Authorization with Notification

Under this model, the controller grants blanket authorization for sub-processing, subject to a notification and objection mechanism.

When to Use:

  • Standard-risk processing
  • SaaS vendors with dynamic infrastructure providers
  • When specific authorization would be operationally impractical

Process:

StepActionTimeline
1Processor notifies controller of intended sub-processor change30 days before engagement
2Notification includes: name, location, function, data access scopeWith notification
3Controller evaluates notification and exercises objection right if neededWithin 14 days
4If no objection, processor may engage sub-processorAfter objection period expires
5If objection raised, parties negotiate resolutionWithin 30 days
6If unresolved, either party may terminate affected servicesPer DPA terms

Notification Requirements

The EDPB has clarified that the notification mechanism must be genuine and effective — a mere listing on a website that the controller must monitor does not satisfy Article 28(2) without an active notification mechanism.

Required Notification Content:

FieldDescriptionExample
Sub-processor legal nameFull legal entity name"Datastream Analytics Inc."
JurisdictionCountry of establishment"United States (Delaware)"
Processing locationWhere personal data will be processed"AWS us-east-1, Virginia, USA"
Processing functionWhat the sub-processor will do"Real-time event processing and aggregation"
Data access scopeWhat personal data the sub-processor accesses"Pseudonymized usage events, IP addresses"
Engagement dateProposed start date"2026-05-01"
Transfer mechanismIf outside EEA, the legal transfer basis"EU-US Data Privacy Framework certification"
Security certificationsRelevant certifications held"SOC 2 Type II, ISO 27001"

Notification Channels:

  • Email notification to designated controller privacy contact
  • Supplement with web-based sub-processor register (not a replacement for active notification)
  • Calendar integration for objection deadline tracking

Objection Mechanism

The controller's right to object must be genuine per EDPB Guidelines 07/2020 (paragraph 115). The DPA must specify:

  1. Objection grounds: Reasonable data protection concerns (not arbitrary)
  2. Objection period: Minimum 14 calendar days from notification receipt (Summit Cloud Partners standard: 30 days)
  3. Objection format: Written notice to processor's designated privacy contact
  4. Resolution process: Good-faith negotiation within defined timeframe
  5. Escalation: If unresolved, termination right for affected services without penalty

Objection Decision Matrix:

ConcernActionEscalation
Sub-processor in jurisdiction with inadequate protection and no valid transfer mechanismObject — require alternative sub-processor or supplementary measuresDPO review
Sub-processor lacks adequate security certificationsObject — request vendor provide evidence of equivalent controlsPrivacy Team review
Sub-processor has history of data breachesObject — require enhanced contractual safeguards or alternativeDPO review
Sub-processor change is administrative (name change, corporate restructure)No objection — acknowledge notificationPrivacy Team acknowledgment
Sub-processor adds processing location within EEAEvaluate — generally no objection if controls equivalentPrivacy Team review
Show full SKILL.md (415 more words)Show less

Flow-Down Obligations

Article 28(4) requires the processor to impose on each sub-processor, by contract, the same data protection obligations as in the controller-processor DPA. The CJEU has not yet directly interpreted the meaning of "same" obligations, but the EDPB position is that they must be materially equivalent.

Flow-Down Checklist:

ObligationController → Processor DPAProcessor → Sub-Processor DPA
Process only on documented instructionsArticle 28(3)(a)Must mirror
Confidentiality obligationsArticle 28(3)(b)Must mirror
Security measures (Art. 32)Article 28(3)(c)Must mirror or exceed
Further sub-processing restrictionsArticle 28(3)(d)Must cascade
DSR assistanceArticle 28(3)(e)Must mirror
Compliance assistance (Art. 32-36)Article 28(3)(f)Must mirror
Deletion/return on terminationArticle 28(3)(g)Must mirror
Audit rightsArticle 28(3)(h)Must provide controller with audit path
Breach notificationArticle 33(2)Must cascade with equivalent or shorter timeframe

Key Consideration — Audit Rights Chain:

The controller must ultimately be able to audit the sub-processor. This can be achieved through:

  1. Direct audit rights over sub-processor (contractually passed through)
  2. Processor audits sub-processor on controller's behalf and shares results
  3. Sub-processor provides independent third-party audit reports (SOC 2, ISO 27001)

Sub-Processor Register

Summit Cloud Partners maintains a centralized sub-processor register for all vendor relationships.

Register Fields:

FieldDescription
Primary processorVendor with direct DPA
Sub-processor nameLegal entity name
Sub-processor locationCountry and specific processing location
Processing functionWhat the sub-processor does
Data access scopeCategories of personal data accessed
Authorization typeSpecific or general authorization
Authorization dateDate of approval
DPA statusSub-processor DPA executed / pending
Transfer mechanismIf applicable — SCC, adequacy, DPF
CertificationsCurrent certifications
Last review dateMost recent assessment
Risk classificationHigh / Standard / Low

Monitoring and Compliance

Ongoing Monitoring Activities
  1. Quarterly sub-processor list reconciliation: Compare processor-provided lists against register
  2. Certification tracking: Monitor sub-processor certification expiry dates
  3. Change notification tracking: Verify all sub-processor changes were properly notified
  4. Annual flow-down verification: Sample sub-processor DPAs to verify equivalent terms
Key Performance Indicators
KPITargetMeasurement
Sub-processor notification compliance100% of changes notified before engagementQuarterly audit
Objection response time100% within 14 calendar daysContinuous
Flow-down DPA coverage100% of sub-processors have executed DPAsQuarterly audit
Sub-processor register accuracy100% match with processor-provided listsQuarterly reconciliation

Key Regulatory References

  • GDPR Article 28(2) — Sub-processor authorization requirements
  • GDPR Article 28(3)(d) — Sub-processor conditions in DPA
  • GDPR Article 28(4) — Flow-down obligations to sub-processors
  • EDPB Guidelines 07/2020 — Controller and processor concepts (paragraphs 93, 115)
  • Commission Implementing Decision (EU) 2021/915 — SCC Clause 7.7 on sub-processing
  • CJEU C-311/18 (Schrems II) — Transfer assessment obligations extending to sub-processor chain

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/sub-processor-management of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Sub Processor Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sub Processor Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sub Processor Management this skillmukul975/Privacy-Data-Protection-Skills295—~2.5kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~4.2kAutomated safety check: PassMIT
Tos Clause Scannerzebbern/claude-code-guide4.6k1 repos~3.3kAutomated safety check: PassMIT
Healthcare Phi Complianceaffaan-m/ECC274k1 repos~1.4kAutomated safety check: PassMIT
Reidentifying Textmaziyarpanahi/openmed5.5k—~1.8kAutomated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2191 repos~3.5kAutomated safety check: PassCustom licence

Similar skills

  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    939 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Tos Clause Scanner

    zebbern/claude-code-guide

    Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.

    4.6k GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    274k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed
  • Reidentifying Text

    maziyarpanahi/openmed

    Reversibly de-identify clinical text with OpenMed and later restore the original PHI from a saved mapping.

    5.5k GitHub stars~1.8k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    219 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Slm Governance

    qualixar/superlocalmemory

    Enterprise compliance and governed workspace behavior for SuperLocalMemory.

    227 GitHub stars~2.1k tokensUpdated yesterday
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Sub Processor Management

What does Sub Processor Management do?

GDPR Article 28(2) sub-processor approval workflow management. Sub Processor Management is an agent skill from mukul975/Privacy-Data-Protection-Skills. GDPR Article 28(2) sub-processor approval workflow management.

When should I use Sub Processor Management?

Sub Processor Management fits situations like: tasks that involve Privacy and GDPR; tasks that involve Authorization and RBAC.

How do I install Sub Processor Management in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill sub-processor-management -a claude-code`. Or copy the skill folder (skills/privacy/sub-processor-management in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/sub-processor-management in your project. Claude Code loads it when a task matches its description.

How do I install Sub Processor Management in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill sub-processor-management -a codex`. Or copy the skill folder (skills/privacy/sub-processor-management in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/sub-processor-management in your project. Codex loads it when a task matches its description.

Can I use Sub Processor Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill sub-processor-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sub-processor-management, .gemini/skills/sub-processor-management, .github/skills/sub-processor-management and .opencode/skills/sub-processor-management in your project.

What does Sub Processor Management need to run?

Going by SKILL.md and its folder, Sub Processor Management needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Sub Processor Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sub Processor Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Sub Processor Management use?

Sub Processor Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sub Processor Management use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Sub Processor Management?

Skills that share tags, products or a category with Sub Processor Management: Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), Tos Clause Scanner (zebbern/claude-code-guide, 4.6k stars), Healthcare Phi Compliance (affaan-m/ECC, 274k stars) and Reidentifying Text (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sub Processor Management?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.