What is a subprocessor? A plain-English guide (with real examples)
A subprocessor is a company your vendor hires to help process your data. If you use a SaaS tool, that tool is your processor; the cloud host, email service, analytics provider, or AI model it relies on behind the scenes are its subprocessors. When your data flows to any of them, they're in scope for your privacy and security reviews — even though you never signed a contract with them directly.
That's the whole idea in one paragraph. The rest of this guide explains why the subprocessor list is the page compliance teams watch most closely, shows you real examples, and walks through how to find and read any vendor's list.
Processor vs. subprocessor, quickly
Under GDPR the roles are simple, even if the words aren't. You (the company deciding why and how data is used) are the controller. The vendor you hire to handle that data is the processor. Anyone the processor brings in to help is a subprocessor. The chain can be several links long — a support tool might use a cloud provider, which uses a content-delivery network — but from your seat, what matters is the list of names your vendor publishes.
- Controller: you decide what happens to the data.
- Processor: your vendor, acting on your instructions.
- Subprocessor: the third parties your vendor uses to deliver its service.
Why a change to the list matters
Most data processing agreements promise to keep an up-to-date list of subprocessors and to give you notice before adding a new one. That notice period exists for a reason: GDPR Article 28 generally gives you a window to object before a new subprocessor starts handling your data. If you object and the vendor can't accommodate you, you may have grounds to terminate. Miss the change, and the window closes on its own — you're simply relying on a new data flow you never reviewed.
This is also the moment auditors care about. A SOC 2 or ISO 27001 reviewer will ask how you keep track of the vendors in your stack and when you last reviewed them. "We check the subprocessor pages" is a fine answer — if you can show it actually happens.
Real examples you can look at right now
The best way to understand a subprocessor list is to read a few. Here are current, public examples from vendors many teams already use. Each of these pages names the third parties involved, usually with the purpose and location of processing:
Read two or three and a pattern emerges. There's usually a table: the subprocessor's name, what it's used for (hosting, email delivery, analytics, customer support, increasingly AI features), and where it operates. The AI rows are the newest and the fastest-moving — a vendor adding a model provider to power a new feature is exactly the kind of change worth catching early.
How to find any vendor's subprocessor list
There's no universal URL, but there's a reliable method. Try these in order:
- Search the vendor's name plus "subprocessors" or "sub-processors" — the spelling varies.
- Look for a "Trust", "Legal", or "Privacy" section in the site footer; the list usually lives there.
- Check the vendor's DPA itself — it often links to the current subprocessor list or an appendix.
- Confirm you're on the vendor's own domain, not a third-party summary. Only the official page is authoritative.
Once you've found it, the hard part isn't reading it once — it's noticing when it changes. Pages update quietly. A row appears, a date moves, and unless you had the old version memorized, you'd never know. That's the job most teams can't reasonably do by hand across a dozen vendors.
The manual way, and the lazy way
The manual way is a calendar reminder, a spreadsheet of URLs, and a quarterly afternoon spent diffing pages in your head. It works right up until it doesn't — someone leaves, the reminder gets snoozed, and six months later you find a subprocessor you can't explain.
The lazy way is to let something watch the pages for you. That's what we built DPA Monitor to do: pick your vendors, and we snapshot their subprocessor lists and DPAs, check them on a schedule, and email you a plain-English summary when one changes — with a link straight to the official source. We report the change; we don't interpret its legal meaning, and nothing here is legal advice.
Frequently asked questions
Is a subprocessor the same as a third party?
It's a specific kind of third party — one your vendor (the processor) uses to help process your data. Not every third party a vendor works with is a subprocessor; the label applies when they touch personal data on your behalf.
Do I have to approve every subprocessor?
It depends on your agreement. Many DPAs use a "general authorization" model: you accept the current list and the vendor notifies you of additions, giving you a window to object. Others require specific approval. Check your DPA's subprocessor clause.
How often do subprocessor lists change?
There's no fixed cadence — it varies by vendor and by how quickly they ship features. Rather than guess a number, the practical answer is to watch the page so you catch changes whenever they happen.
DPA Monitor watches your vendors' subprocessor lists and DPAs and emails you when they change. Set it up in two minutes.
Watch my vendors — free