What DPA Monitor watches — and why a subprocessor change matters
Your company relies on dozens of SaaS vendors, and each one quietly processes your customers' data under a set of documents most people never read twice: a data processing agreement, a subprocessor list, a privacy policy. Those documents change. When they do, the change usually lands with no announcement — a new row in a table, a revised paragraph, a fresh "last updated" date. DPA Monitor exists to notice those changes so you don't have to.
The documents we track
For each vendor we watch the pages that matter to a data protection or security review:
- Subprocessor lists — the third parties a vendor uses to process your data.
- Data processing agreements (DPAs) — the contract terms governing that processing.
- Privacy policies — how the vendor collects, uses, and shares personal information.
- Terms of service and security pages, where a vendor publishes them.
Why subprocessors are the page to watch
Under GDPR Article 28, when a vendor adds or replaces a subprocessor, you typically have a window to object before the change takes effect. That window opens whether or not anyone on your team is looking. If you find out months later, the window has closed — and you've been relying on a data flow you never reviewed. An "added subprocessor" alert is the single most useful signal a vendor-monitoring tool can give you.
How we report a change
We take a snapshot of each document, and on the next check we compare it to the last one. When something meaningful changes, we summarize what moved in plain English and link you straight to the official page so you can confirm it yourself. We detect and report changes — we don't interpret their legal meaning, and nothing here is legal advice.
Set it up once, and the boring-but-important pages get watched for you. That's the whole idea.
DPA Monitor watches your vendors' subprocessor lists and DPAs and emails you when they change. Set it up in two minutes.
Watch my vendors — free