What is a sub-processor?
A sub-processor is a third-party data processor engaged by Include Security Experts in AppSec. The sub-processor has or potentially will get access to personal data that Include Security Experts in AppSec processes on behalf of its customers.
Why and how should I assess this?
If you choose to use Include Security Experts in AppSec as a processor, the sub-processors listed will have access to personal data processed on your behalf. When you assess the sub-processors of your vendors, you need to ensure the following:
A signed data processing agreement
You need to have a signed contract in place that commits Include Security Experts in AppSec to only use sub-processors with your permission.
Transfers of data out of Europe
If Include Security Experts in AppSec uses a sub-processor located outside Europe, there must be a legal basis for the transfer.