GDPR - Processing Under the Authority of the Controller or Processor - Summary
Executive Summary
Only use reliable processors and sub-processors. You are liable if there is a data breach relating to data of which you are the controller.
Article Text
The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.