Skip to main content

How-to

How to Check a Vendor's Subprocessor List

What a subprocessor list must include under the SCCs and most DPAs, how notice periods work, and how to compare lists across a shortlist.

Solomon AmosPublished 23 Sep 20268 min read

A subprocessor list is one of the most overlooked pieces of vendor evidence in a security review. Buyers ask for SOC 2 reports and ISO certificates because they are used to asking for them, but a subprocessor list answers a narrower and more useful question: which companies, in which countries, actually touch the personal data you send this vendor, and what happens if that list changes after the contract is signed. This guide sets out what the Standard Contractual Clauses and most data processing agreements require a subprocessor list to contain, how change notice periods actually work under GDPR, and a repeatable way to compare lists across a shortlist of vendors on Compare vendors side by side rather than reading each one in isolation.

What counts as a subprocessor, and what doesn't

A subprocessor is any third party a vendor engages to process personal data on a controller's behalf as part of delivering the service: a cloud hosting provider, an email delivery service, a customer support tool that stores ticket content, a payment processor, an analytics vendor that receives identifiable data. It is not the vendor's own staff, and it is not a supplier who only ever touches encrypted data for which the vendor holds no key, though vendors sometimes stretch that exemption further than it will bear. It also is not every company mentioned on a trust centre. A vendor might list a hundred integrations a customer can optionally connect; only the subset that the vendor itself sends data to as part of running the core service belongs on the subprocessor list proper. A controller stays accountable for the whole chain regardless of how many subprocessors sit behind the vendor, a point covered in more detail in what GDPR asks of your vendors.

What the SCCs and most DPAs require a subprocessor list to contain

Most data processing agreements point at Module 2 or Module 3 of the EU Standard Contractual Clauses for the sub-processing mechanism, and both modules assume the list is more than a name. A usable entry tells the reader what the subprocessor does, where it does it, and how the vendor keeps that subprocessor bound to the same data protection obligations the vendor itself signed up to. A list that only gives a company name and nothing else is not really evidence of anything, it is a marketing page wearing a compliance hat.

  • Legal name of the subprocessor, not just a product brand
  • The processing activity it performs, for example hosting, email delivery, payment processing or customer support tooling
  • Country or region where the processing takes place
  • Confirmation that the vendor has a written agreement imposing equivalent data protection obligations on the subprocessor
  • The transfer mechanism used if the subprocessor sits outside the customer's region, usually the SCCs again or an adequacy decision
  • A last-updated date, without which the list cannot be trusted at all

Change notice periods: what 'advance notice' actually means

The SCCs do not fix a notice period in days. Clause 9 of Module 2 gives the parties a choice: specific prior authorisation, where the vendor must get sign-off before engaging any new subprocessor, or general authorisation, where the vendor may proceed unless the customer objects within a period the contract defines. That period is left blank in the official text for the parties to fill in, which is why it varies so much between vendors. Thirty days before the change takes effect is the figure that appears most often in vendor DPAs in the CertReports index on 2026-09-23, but some vendors specify fourteen days, some specify ten business days, and a few say nothing more precise than 'reasonable notice', which is not really a notice period at all.

MechanismHow it worksWho has to act
General authorisation with an objection rightVendor publishes the change and starts a clock, commonly thirty days; if the customer does not object in that window the subprocessor is treated as acceptedCustomer, and only within the window
Specific prior authorisationVendor must get written sign-off for each named subprocessor before using itVendor, before it can proceed
Notice only, no objection rightVendor tells customers after the change has already happened, with no contractual vetoNeither party has real leverage

General authorisation, prior authorisation and notice-only mechanisms compared.

The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least [Specify time period] in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s).

Check the annex, not just the page

If a vendor's website subprocessor list and its signed DPA annex ever disagree, the DPA controls. Ask for the current annex directly if the two do not match.

Where vendors actually publish the list

Three places, in practice. Some vendors keep a standalone subprocessor page, usually linked from the footer or from the trust centre, and update it directly. Some fold the list into an appendix or annex of the DPA itself, which means you only see the current version when you pull the signed or template agreement rather than a marketing page. A smaller group publish nothing public at all and will only send a list on request, sometimes only after a contract is signed, which defeats the purpose of comparing vendors before you commit to one. How to read a trust centre in ten minutes covers where else on that page to look once you have found the subprocessor link, including whether it sits next to a real DPA or just a privacy policy.

Diagram of the fields a usable subprocessor list entry should contain: name, activity, location, agreement and last-updated date
A complete subprocessor entry, not just a company name.
30 days
Most common notice period stated in vendor DPAs
in the CertReports index on 2026-09-23
6
Fields a complete subprocessor entry typically carries: name, activity, location, agreement confirmation, transfer mechanism, last-updated date
SCC Module 2, Clause 9
3
Places a subprocessor list typically lives: a dedicated page, a DPA annex, or nowhere public at all
in the CertReports index on 2026-09-23

How to compare subprocessor lists across a shortlist

Reading one list at a time misses the point. The value of a shortlist review is comparing lists side by side, because two vendors offering the same core product often route data through a very different set of subprocessors, and that difference is sometimes the deciding factor once you also weigh price and features against everything else. The sequence below works even with a plain spreadsheet.

  1. 1

    Pull the current list, not a cached one

    Go to the vendor's own page rather than a copy someone saved to a shared drive last year. Check the last-updated date before you read anything else.

  2. 2

    Map the overlap

    List every subprocessor across all vendors on the shortlist in one sheet. The same four or five infrastructure and email providers turn up behind most SaaS products, so your real new exposure is usually a short list, not a long one.

  3. 3

    Check the notice mechanism, not just the notice period

    A thirty-day window is only useful if the vendor also commits to telling you when the clock starts. Confirm whether notice comes by email, by a change log, or only by checking the page yourself.
  4. 4

    Cross-check against the framework evidence

    If a subprocessor handles hosting or storage, see whether it shows up as a subservice organisation in the vendor's SOC 2 report or as part of its FedRAMP boundary. A mismatch between the two documents is worth a direct question.
  5. 5

    Set a recheck cadence

    Subprocessor lists change more often than certificates renew. A quarterly recheck, or a subscription to the vendor's change notifications where one exists, catches additions between your annual review cycles.

A worked example: reading a real subprocessor list

Notion is a useful case because its subprocessor list sits next to a public DPA rather than being emailed on request, which is the arrangement worth looking for on any vendor's own page. Open both documents together: check whether the DPA's sub-processing clause matches the mechanism described above, then check whether every entity named in the list also carries a stated purpose and location rather than just a name.

Notion logo

Notion · Trust report

Collaboration · Public evidence as of 25 Sep 2026

3Documents and agreements

Legal and review documents Notion publishes or offers, as of 25 Sep 2026.

26Subprocessors

Named on Notion's public subprocessor list, last seen 25 Sep 2026.

Notion's DPA and subprocessor list, checked against its current framework evidence. Every line is a dated public record from Notion's trust centre and the Data Privacy Framework list. A framework not shown means no public evidence was found, not that Notion lacks it.CertReports

Red flags when a list is missing, stale or vague

  • No last-updated date anywhere on the page or in the DPA annex
  • A single line saying the vendor 'uses trusted third-party providers' with no names
  • A list that has not changed in over a year for a vendor that has visibly added product features, which usually means new infrastructure and new subprocessors behind them
  • A notice period described only as 'reasonable' or 'as required by law' with no number attached
  • Countries named in the list that do not appear in the DPA's international transfer annex
  • A sales team that will only share the list after a contract is signed
Timeline showing a vendor publishing a new subprocessor, the notice window opening, and a customer's objection deadline before the subprocessor goes live
A general authorisation notice window, from publication to deadline.

Building this into a recurring vendor review

A subprocessor check is not a one-off gate at procurement, it is a line item in whatever cadence already governs vendor reviews, alongside the SOC 2 renewal date and the DPF listing status. A 30-minute vendor security review using public evidence sets out the wider checklist this slots into, and if a vendor exposes its evidence through an API rather than a page you have to remember to revisit, Webhooks and the JSON API explains how to pull change events like new subprocessors straight into your own tracker instead. The goal is the same either way: catch the addition during the notice window, not three months after the subprocessor has already been processing data.

People also ask

What is a subprocessor?

A subprocessor is any third party a vendor engages to process personal data on behalf of a customer as part of delivering the service, such as a cloud host, an email delivery provider, a payment processor or a support desk tool that stores ticket content. It does not include the vendor's own staff, and it should not include every optional integration a customer can connect, only the ones the vendor itself sends data to by default.

How much notice must a vendor give before adding a subprocessor?

There is no fixed legal minimum. The Standard Contractual Clauses leave the exact period for the contracting parties to specify, which is why it varies by vendor. Thirty days before the change takes effect is the figure that appears most often in the CertReports index on 2026-09-23, though some vendors specify fourteen days or ten business days, and a few offer no number at all, which is worth challenging before you sign.

Where do vendors publish their subprocessor list?

Most publish it in one of three places: a standalone page usually linked from the trust centre or footer, an annex attached to the data processing agreement, or nowhere public at all, released only on request after a contract is signed. The first two are worth favouring, because you can check them before committing to a vendor rather than discovering the list once you are already a customer.

Is a subprocessor list required by GDPR?

GDPR itself does not name a specific list document, but Article 28 requires a processor to have the controller's authorisation before engaging a subprocessor and to inform the controller of any changes, giving it the chance to object. In practice, vendors meet that obligation with a published list and a notice mechanism defined in the DPA, which is why a vendor's own list and its DPA should always tell the same story.

subprocessorsDPASCCsGDPRvendor review
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

Read next on CertReports

You might also like