Subprocessor list
The public list in which a vendor names the subprocessors that handle its customers' personal data, usually with each one's purpose and location.
Vendors publish the list so customers can see who else handles their data and use the right to object that their data processing agreement gives them. A typical entry names the company, what it does for the vendor (hosting, support, email delivery, analytics, AI features) and where it processes data.
Lists change without much ceremony: a row is added, a country appears, a purpose is reworded. Because the objection window is usually short, the list only helps if someone notices the change in time.
Source: GDPR Art. 28(2) ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.