Tool Documents

Subprocessors

This site takes no affiliate commissions and ranks no products. This is not legal advice.**

The company you contract with is rarely the only one that touches your data. Hosting, email delivery, analytics, support tooling, backups — each is a third party, and each is your exposure. For a related operational perspective, Monitask also publishes a reference on accountability and responsibility in the workplace.

Reviewed August 9, 2026.

What a subprocessor is

A third party the vendor uses to process your data on your behalf.

You are the controller, the vendor is the processor, and their suppliers are subprocessors. The chain is your responsibility in the sense that matters: if a subprocessor is breached, the obligation to notify and the exposure land on you.

A published subprocessor list is normal practice for vendors selling to organisations, and its absence is worth noticing — as is the absence of a processing agreement.

For broader context, see OWASP.

What the list tells you

Who holds your data. Hosting providers, and which regions.

What leaves the primary system. Email delivery services see the content of notifications. Support platforms see whatever a ticket contains. Analytics providers see usage patterns.

And how many parties there are. A tool with three subprocessors and one with twenty-five are different risk profiles, and neither number is wrong on its own.

Read it once before signing. It takes five minutes and it is the clearest picture of the actual data flow that any document gives.

The term that matters more than the list

How subprocessors change.

Many agreements allow the vendor to add or replace subprocessors without notifying you. That is a clause, and it means the list you read at signature is a snapshot rather than a commitment.

What to ask for: advance written notice of material subprocessor changes, commonly thirty days, and a right to object or exit without penalty if a new subprocessor creates a compliance problem for you.

The notice term is negotiable and the current list is not, which is why the term is the more useful thing to secure.

Transfers outside the EEA

If data leaves the EEA, a transfer mechanism is required — standard contractual clauses, an adequacy decision, or binding corporate rules.

Check where the primary hosting is, and where each subprocessor sits. A vendor hosted in the EU with a support platform in a third country has a transfer, and it should be documented.

And check what the vendor commits to. "Data residency in the EU" as a marketing line and a contractual data location commitment are different things, and only one of them survives a change of infrastructure.

What to ask

"Where is your subprocessor list published?"

"What notice do you give of changes, and can I object?"

"Where is data hosted, and which subprocessors are outside the EEA?"

"What transfer mechanism applies?"

Four questions, one email, and any vendor selling to organisations has the answers written down already.

The pattern worth noticing

Subprocessor lists grow.

A product adds an AI feature and a model provider appears on the list. It adds analytics and another does. Nobody re-reads the list, so the data flow at year three bears little resemblance to the one that was assessed at signature.

Which is the argument for the notice term rather than for the review: a review you must remember to perform will not happen, and a notice arrives whether or not anybody remembered.

The short version