Data processing glossary
Plain-English definitions of the terms that show up when you review a vendor's data processing — DPAs, subprocessors, and the GDPR machinery around them.
What is a subprocessor?
- A subprocessor is a third party your vendor uses to help process your data. If a SaaS tool is your processor, the cloud host, email service or AI provider it relies on behind the scenes are its subprocessors — in scope for your privacy and security reviews even though you never contracted with them directly. Read the full guide →
What is a Data Processing Agreement (DPA)?
- A Data Processing Agreement is the contract that governs how a vendor processes personal data on your behalf: the purposes, security measures, subprocessor terms, and each party's obligations. Under GDPR Article 28 a DPA (or equivalent terms) is required whenever a processor handles a controller's personal data.
What is a data controller?
- A controller is the organisation that decides why and how personal data is processed. You are usually the controller for your customers' data; the vendors you hire to handle it act on your instructions as processors.
What is a data processor?
- A processor is a vendor that processes personal data on a controller's behalf and on its instructions. A processor may, with the controller's authorisation, use subprocessors — which is why the subprocessor list matters.
What is a subprocessor list?
- A subprocessor list is the vendor-published page naming the third parties it uses to process your data. Most DPAs promise to keep this list current and to give notice before adding a new entry — so a change to the list is the signal to review.
What is GDPR Article 28?
- Article 28 of the GDPR sets the rules for using processors: it requires a written DPA, controls the use of subprocessors, and generally gives the controller a right to object to a new subprocessor before it starts handling data. How the objection window works →
What is a subprocessor objection window?
- The objection window is the notice period a DPA gives you to object before a newly added subprocessor starts processing your data. If you object and the vendor can't accommodate you, you may have grounds to terminate. Miss the notice and the window closes on its own — which is why change monitoring matters.
What are Standard Contractual Clauses (SCCs)?
- Standard Contractual Clauses are pre-approved contract terms used to lawfully transfer personal data outside the EEA to a country without an adequacy decision. Vendors often reference SCCs in their DPA to cover international transfers to their subprocessors.
Watch these documents change
DPA Monitor watches your vendors' DPAs and subprocessor lists and emails you when they change.
Watch your vendors — free