Independent DPDP educationSWARN is in development · educational, not legal adviceSource status: 30 Aug 2026
P05Govern

ARCHITECTURE PATTERN · SYNTHETIC REFERENCE

Processor and sub-processor register

Link approved providers to instructions, data flows, locations, assurance and exit work.

Engineering control

Engineering pattern
not a legal template

WHEN TO USE

Use when third parties process personal data or introduce downstream providers.

Start only after the relevant facts, source status and system boundary are understood.

SOURCE / STATUS BOUNDARY

Verify the legal status before implementation.

Engineering controlPattern verification pointers

These IDs are verification pointers to the primary-source ledger. They are not provision mappings, applicability findings or legal conclusions.

SEQUENCE DIAGRAM

Four accountable hand-offs.

  1. 01Vendor owner

    describes service, systems and instructions

    ARTEFACT · register entry
  2. 02Reviewers

    assess contract, security and locations

    ARTEFACT · approval decision
  3. 03Change monitor

    records sub-processor or location changes

    ARTEFACT · change task
  4. 04Exit owner

    closes access and confirms return or deletion

    ARTEFACT · exit evidence

TYPED JSON FIXTURE

Synthetic by design.

This example contains no real person, provider, incident or system data. It demonstrates record boundaries, not a production schema.

{
  "fixture": true,
  "schemaVersion": "1.0-demo",
  "pattern": "processor-and-sub-processor-register",
  "subjectRef": "synthetic-only",
  "payload": {
    "processorRef": "processor_demo_03",
    "region": "synthetic-region",
    "exitState": "review_required"
  }
}

EVIDENCE OUTPUTS

  • Service and instruction record
  • Sub-processor list
  • Location map
  • Exit acknowledgement

THREAT CONSIDERATIONS

  • Unauthorised vendor access
  • Hidden sub-processors
  • Sensitive contract details exposed too widely

FAILURE MODES

  • The contract folder is treated as the register
  • Material changes have no review trigger
  • Offboarding ends before data and access are closed

RESEARCH / RADAR CONNECTION

Keep implementation context attached.

Implementation teams benefit from separating legal interpretation from the engineering artefacts used to execute and test a decision.

Read From obligation to evidence: the DPDP implementation stack
Adopt · R-05

Software and data-flow inventories

Link services, stores, flows and owners to a controlled change process.

Foundational practice · Review 2026-12-20Open radar rationale

LOCAL WORKSPACE NOTE

Give this work a next owner.

This browser only

Nothing is sent anywhere. Avoid names, personal data or confidential incident details.

No local note loaded.
NextReturn to pattern discovery