A processor cannot engage another processor without the controller's prior written authorisation, which makes the list the most informative page in the agreement.
Why it matters when the plan changes
The sub-processor list is where a sentence about security becomes a set of named companies in named countries. It is how a controller discovers that assessment text goes to a model provider, that logs go to a monitoring service, or that support staff in another jurisdiction can see a record. Article 44 makes a transfer to a third country lawful only on the regulation's conditions, so location on the list is part of what is authorised, not incidental. None of this is improper; all of it has to be known and authorised.
The tension is between a supplier's need to change infrastructure and a controller's need to know. General authorisation with notification is the usual compromise, and it only works when the notification route is specific and the objection right is real. Article 28 requires prior authorisation, specific or general, before another processor is engaged, setting the floor beneath the compromise. A general authorisation with no notice is a blank cheque the regulation does not permit.
In practice
A controller signs an agreement listing three sub-processors. Over two years the supplier adds a model provider, a new analytics tool and a support platform, and informs nobody. The data protection officer finds out from a security questionnaire. Nothing malicious happened and the controller has been processing without authorisation for eighteen months.
Evidence
A processor may not engage another processor without prior written authorisation from the controller.
Article 28, General Data Protection Regulation (2016)Transfers to a third country are only permitted on the regulation's conditions, so a sub-processor's location is part of what is authorised.
Article 44, General Data Protection Regulation (2016)
What it cannot tell you
A sub-processor list tells a controller who currently handles the data and where, but it says nothing about how well any of them protects it. Authorisation confirms that a party is named and permitted, not that its security practices, retention or breach history meet any particular standard; that assessment sits outside the list entirely.
Questions
Yes, if personal data reaches it. A call sending assessment text to a model endpoint is processing by a third party, and Article 44 of the General Data Protection Regulation (2016) makes the provider's location part of what must be authorised, alongside its own terms.
Specific authorisation means the controller approves each sub-processor by name before it is engaged. General authorisation means the controller approves the category and must be informed of intended changes in time to object. Both are lawful; general only works with a real notification route.
That the same data protection obligations flow down by contract, as required under Article 28 of the General Data Protection Regulation (2016), and the processor remains fully liable to the controller for their performance. A sub-processor's failure is the processor's failure.
Whenever the processor notifies a change, and at least annually as part of the controller's own records of processing. A list read once at procurement and never again is the usual state, and it is how a controller ends up authorising something it has never seen.
Under general authorisation the controller can object to an intended change, and the agreement should say what happens then, which is usually a right to terminate. An objection right with no consequence attached is not an objection right, and a careful data protection officer will ask what it triggers.