What is a subprocessor? (And why your vendors keep changing theirs)
Updated September 24, 2026
A subprocessor is a company that a vendor (the processor) uses to process personal data on behalf of its customers (the controllers). If you use a SaaS product and that product runs on Amazon Web Services, sends email through Twilio and answers support tickets in Zendesk, then Amazon, Twilio and Zendesk are subprocessors of your data.
Where the term comes from
Under the GDPR, a processor may only engage another processor with the controller’s authorisation (Article 28(2)). Almost every SaaS contract handles this with a general authorisation: the vendor may use subprocessors, provided it keeps a current list, tells customers before adding one, and gives them a window to object. The same mechanics appear in the UK GDPR, in most data processing agreements (DPAs), and increasingly in US state privacy laws.
That contractual promise is why vendors publish a subprocessor list — and why the list is the one page on a vendor’s site that is supposed to change.
What a subprocessor list contains
A typical entry has three parts:
| Field | Example |
|---|---|
| Entity | Amazon Web Services, Inc. |
| Purpose | Cloud hosting and storage |
| Location | United States, Ireland |
Some vendors add the categories of personal data involved, the vendor’s own affiliates, or a separate list per product or region. Some publish it as an HTML table, some as a PDF annex to the DPA, and a few only inside a login wall.
Why the lists change
Vendors change subprocessors for ordinary reasons: a new CDN, a support tool migration, a data centre in a new region. Lately the most common addition is an AI provider — OpenAI, Anthropic, Google’s Gemini, Azure OpenAI or Amazon Bedrock — as vendors add AI features. For a compliance team, that single line can change a vendor’s risk profile: customer content is now leaving the vendor for a model provider.
What you are expected to do about it
If you are the controller, your own obligations run through your vendors’ subprocessors: your records of processing, your transfer impact assessments and your own customers’ DPAs all depend on knowing who is on the list today. In practice that means:
- Knowing where each vendor publishes its list (and its DPA and privacy policy).
- Checking the list on a schedule, or being told when it changes.
- Reviewing each change — is the new entity acceptable, is the location acceptable, does an existing contract need updating — and keeping a record of the review.
Most vendors promise an email before a change. Many send one; not all do, and the emails are easy to lose. Reading the list itself is the reliable source.
How this directory helps
The ClauseTrail vendor directory tracks the published subprocessor lists of the vendors compliance teams ask about most, in a structured form: who is on the list, what they do, where they are, and how the list has changed over time. Each vendor page shows the current list and when it was last checked, and ClauseTrail turns that into alerts for the vendors you actually use.