A single misconfigured cloud bucket at a subcontractor can cascade into a €5M fine for your organisation—even if your own systems remain untouched. CNIL’s latest breach decisions reveal a troubling pattern: controllers are being held liable for processor failures they neither detected nor controlled. With GDPR’s joint-controller and processor liability provisions now routinely enforced, CTOs and CISOs must move beyond passive contractual protections to active technical and operational oversight
A single misconfigured cloud bucket at a subcontractor can cascade into a €5M fine for your organisation—even if your own systems remain untouched. CNIL’s latest breach decisions reveal a troubling pattern: controllers are being held liable for processor failures they neither detected nor controlled. With GDPR’s joint-controller and processor liability provisions now routinely enforced, CTOs and CISOs must move beyond passive contractual protections to active technical and operational oversight of their entire supply chain.
The Subcontractor Liability Gap: Why Controllers Remain Exposed
GDPR’s liability framework creates a deceptive sense of security. While Article 28(1) requires controllers to use only processors providing "sufficient guarantees," the regulation’s joint liability provisions (Article 82) and supervisory authority powers (Article 58) mean controllers cannot outsource accountability. Three structural gaps explain why controllers remain exposed:
- 1The "Black Box" Problem: Most controllers lack visibility into their processors’ subcontracting arrangements. A 2023 ENISA report found that 68% of organisations could not identify all sub-processors in their supply chain beyond the first tier.
- 1Contractual vs. Operational Reality: Standard Data Protection Agreements (DPAs) often include audit rights, but these are rarely exercised. CNIL’s 2025 guidance notes that fewer than 15% of controllers conduct annual processor audits, despite Article 28(3)(h) requiring "regular verification" of compliance.
- 1Technical Debt in Monitoring: Legacy monitoring systems focus on internal controls, not external processor environments. When a processor’s subcontractor suffers a breach, controllers typically learn about it through media reports or regulatory notices—long after the 72-hour notification window has closed.
The liability chain extends beyond direct processors. Article 28(4) requires processors to obtain the controller’s written authorisation before engaging sub-processors, but this provision is frequently circumvented through "general authorisations" buried in DPAs. When a sub-processor fails, both the primary processor and the controller face enforcement action.
CNIL's May 2026 Breach Pattern: What Controllers Missed
CNIL’s May 2026 decision against a French e-commerce platform (Decision SAN-2026-005) reveals a now-familiar breach pattern that controllers continue to overlook. The incident involved a third-tier subcontractor (a payment gateway’s cloud hosting provider) that exposed 450,000 customer records through an unpatched vulnerability. Key findings from the decision highlight critical oversights:
The "Russian Doll" Subcontracting Problem
The breach originated with a fourth-party service provider (the hosting provider’s CDN subcontractor). CNIL found that:
- The controller’s DPA with its primary processor included a general authorisation for subcontracting, violating Article 28(2)’s requirement for specific written consent.
- No contractual provisions required the primary processor to cascade GDPR obligations to all sub-processors, contrary to Article 28(4).
- The controller had no inventory of sub-processors beyond the first tier, despite Article 30(1)’s record-keeping requirements.
Technical Control Failures
CNIL’s technical investigation revealed systemic gaps in processor oversight:
- Lack of Encryption at Rest: The exposed data was stored in plaintext, violating Article 32(1)(a)’s requirement for "appropriate technical measures."
- No Processor-Specific Monitoring: The controller’s SIEM did not ingest logs from processor environments, despite Article 32(1)(d)’s mandate for "continuous monitoring."
- Default Credentials: The subcontractor’s cloud bucket used default credentials, which CNIL deemed a clear violation of Article 32’s security requirements.
Notification and Cooperation Breakdowns
The incident response exposed critical failures in the liability chain:
- The subcontractor notified its direct customer (the third-tier processor) 48 hours after discovery, but this notification was not escalated to the controller for another 7 days—well beyond GDPR’s 72-hour window.
- The controller’s DPA lacked specific provisions for sub-processor breach notification, despite Article 28(3)(f)’s requirement for processors to "assist the controller" in breach response.
- CNIL found that the controller’s internal incident response plan did not account for processor or sub-processor breaches, violating Article 33(5)’s requirement for "documented procedures."
The decision imposed a €5.2M fine on the controller, with CNIL noting that "the controller’s failure to exercise due diligence in selecting and monitoring its processor chain constituted a negligent violation of Article 24(1)." The primary processor received a separate €3.1M fine for its role in the breach.
Article 28 Enforcement: Auditing Your Processor's Supply Chain
Article 28’s requirements extend far beyond standard DPA clauses. Supervisory authorities are increasingly scrutinising the operational reality of processor relationships, not just the contractual framework. Three enforcement trends demand attention:
1. The "Cascade Clause" Requirement
Article 28(4) requires processors to impose "the same data protection obligations" on sub-processors as those binding the processor to the controller. This creates a contractual cascade that must be:
- Explicit: General authorisations for subcontracting are insufficient. CNIL’s 2025 guidance requires controllers to approve each sub-processor individually or establish a pre-approved list with strict criteria.
- Enforceable: The cascade clause must include audit rights, breach notification requirements, and liability provisions that mirror the controller-processor DPA.
- Documented: Controllers must maintain records of all sub-processors (Article 30(1)) and their approval status.
2. The Rise of "Processor Audits"
Article 28(3)(h) requires processors to "make available to the controller all information necessary to demonstrate compliance" and "allow for and contribute to audits." Supervisory authorities are interpreting this as:
- Annual Audits: The EDPB’s 2024 guidelines recommend annual audits for high-risk processing activities, with ad-hoc audits following material changes to the processor’s environment.
- Sub-Processor Audits: Controllers must either audit sub-processors directly or require their primary processors to conduct and document such audits.
- Technical Evidence: Audits must include technical evidence (e.g., configuration snapshots, access logs) to verify compliance with Article 32’s security requirements.
3. The "Right to Object" to Subcontractors
Article 28(2) prohibits processors from engaging sub-processors without the controller’s "prior specific or general written authorisation." CNIL’s 2026 decisions clarify that:
- General Authorisations Must Be Specific: A blanket clause allowing subcontracting "as necessary" is insufficient. Controllers must define criteria for sub-processor approval (e.g., location, security certifications).
- Controllers Must Exercise Oversight: Simply including a general authorisation does not absolve controllers of liability. They must actively monitor sub-processor changes and object to those that pose risks.
- Change Notifications Are Mandatory: Processors must notify controllers of any intended changes to sub-processors, and controllers must have a documented process for reviewing and approving such changes.
Contractual Teeth: Beyond Standard DPA Clauses
Standard DPAs often fail to address the operational realities of subcontractor breaches. Controllers must enhance their contractual frameworks with provisions that create enforceable accountability:
1. Sub-Processor Inventory and Approval
- Dynamic Inventory Clauses: Require processors to maintain an up-to-date, machine-readable inventory of all sub-processors, updated in real-time via API.
- Automated Approval Workflows: Implement contractual requirements for processors to use automated tools (e.g., workflow systems) to route sub-processor change requests to the controller for approval.
- Risk-Based Approval Criteria: Define clear criteria for sub-processor approval, such as: - Geographic location (e.g., no sub-processors in jurisdictions without adequacy decisions). - Security certifications (e.g., ISO 27001, SOC 2 Type II). - Data residency requirements.
2. Liability Allocation and Indemnification
- Joint and Several Liability: Explicitly state that the processor and all sub-processors are jointly and severally liable for breaches, with no caps on liability for negligence or wilful misconduct.
- Indemnification for Regulatory Fines: Include indemnification clauses covering GDPR fines imposed on the controller due to processor or sub-processor failures.
- Cost of Remediation: Require processors to cover the costs of breach remediation, including customer notifications, credit monitoring, and regulatory filings.
3. Audit and Monitoring Rights
- Unannounced Audit Rights: Reserve the right to conduct unannounced audits of processors and sub-processors, with contractual penalties for non-cooperation.
- Continuous Monitoring Requirements: Require processors to integrate their security monitoring tools with the controller’s SIEM or provide API access to logs.
- Third-Party Audit Reports: Mandate that processors provide annual third-party audit reports (e.g., ISO 27001, SOC 2) for themselves and all sub-processors.
4. Breach Notification and Response
- Tiered Notification Requirements: Define specific notification timelines for breaches at different tiers of the supply chain (e.g., 24 hours for the primary processor, 48 hours for sub-processors).
- Incident Response Collaboration: Require processors to participate in the controller’s incident response plan, including joint tabletop exercises.
- Forensic Evidence Preservation: Mandate that processors and sub-processors preserve forensic evidence for regulatory investigations, with contractual penalties for spoliation.
Technical Controls: Monitoring & Access Restrictions for Subcontractors
Contractual protections are insufficient without technical controls to enforce them. Controllers must implement technical measures to monitor and restrict subcontractor access to personal data:
1. Data Mapping and Inventory
- Automated Data Discovery: Use tools