A subprocessor list is one of the most overlooked pieces of vendor evidence in a security review. Buyers ask for SOC 2 reports and ISO certificates because they are used to asking for them, but a subprocessor list answers a narrower and more useful question: which companies, in which countries, actually touch the personal data you send this vendor, and what happens if that list changes after the contract is signed. This guide sets out what the Standard Contractual Clauses and most data processing agreements require a subprocessor list to contain, how change notice periods actually work under GDPR, and a repeatable way to compare lists across a shortlist of vendors on Compare vendors side by side rather than reading each one in isolation.
What counts as a subprocessor, and what doesn't
A subprocessor is any third party a vendor engages to process personal data on a controller's behalf as part of delivering the service: a cloud hosting provider, an email delivery service, a customer support tool that stores ticket content, a payment processor, an analytics vendor that receives identifiable data. It is not the vendor's own staff, and it is not a supplier who only ever touches encrypted data for which the vendor holds no key, though vendors sometimes stretch that exemption further than it will bear. It also is not every company mentioned on a trust centre. A vendor might list a hundred integrations a customer can optionally connect; only the subset that the vendor itself sends data to as part of running the core service belongs on the subprocessor list proper. A controller stays accountable for the whole chain regardless of how many subprocessors sit behind the vendor, a point covered in more detail in what GDPR asks of your vendors.
What the SCCs and most DPAs require a subprocessor list to contain
Most data processing agreements point at Module 2 or Module 3 of the EU Standard Contractual Clauses for the sub-processing mechanism, and both modules assume the list is more than a name. A usable entry tells the reader what the subprocessor does, where it does it, and how the vendor keeps that subprocessor bound to the same data protection obligations the vendor itself signed up to. A list that only gives a company name and nothing else is not really evidence of anything, it is a marketing page wearing a compliance hat.
- Legal name of the subprocessor, not just a product brand
- The processing activity it performs, for example hosting, email delivery, payment processing or customer support tooling
- Country or region where the processing takes place
- Confirmation that the vendor has a written agreement imposing equivalent data protection obligations on the subprocessor
- The transfer mechanism used if the subprocessor sits outside the customer's region, usually the SCCs again or an adequacy decision
- A last-updated date, without which the list cannot be trusted at all
Change notice periods: what 'advance notice' actually means
The SCCs do not fix a notice period in days. Clause 9 of Module 2 gives the parties a choice: specific prior authorisation, where the vendor must get sign-off before engaging any new subprocessor, or general authorisation, where the vendor may proceed unless the customer objects within a period the contract defines. That period is left blank in the official text for the parties to fill in, which is why it varies so much between vendors. Thirty days before the change takes effect is the figure that appears most often in vendor DPAs in the CertReports index on 2026-09-23, but some vendors specify fourteen days, some specify ten business days, and a few say nothing more precise than 'reasonable notice', which is not really a notice period at all.
| Mechanism | How it works | Who has to act |
|---|---|---|
| General authorisation with an objection right | Vendor publishes the change and starts a clock, commonly thirty days; if the customer does not object in that window the subprocessor is treated as accepted | Customer, and only within the window |
| Specific prior authorisation | Vendor must get written sign-off for each named subprocessor before using it | Vendor, before it can proceed |
| Notice only, no objection right | Vendor tells customers after the change has already happened, with no contractual veto | Neither party has real leverage |
General authorisation, prior authorisation and notice-only mechanisms compared.
The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least [Specify time period] in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s).
Check the annex, not just the page
If a vendor's website subprocessor list and its signed DPA annex ever disagree, the DPA controls. Ask for the current annex directly if the two do not match.
Where vendors actually publish the list
Three places, in practice. Some vendors keep a standalone subprocessor page, usually linked from the footer or from the trust centre, and update it directly. Some fold the list into an appendix or annex of the DPA itself, which means you only see the current version when you pull the signed or template agreement rather than a marketing page. A smaller group publish nothing public at all and will only send a list on request, sometimes only after a contract is signed, which defeats the purpose of comparing vendors before you commit to one. How to read a trust centre in ten minutes covers where else on that page to look once you have found the subprocessor link, including whether it sits next to a real DPA or just a privacy policy.
- 30 days
- Most common notice period stated in vendor DPAs
- in the CertReports index on 2026-09-23
- 6
- Fields a complete subprocessor entry typically carries: name, activity, location, agreement confirmation, transfer mechanism, last-updated date
- SCC Module 2, Clause 9
- 3
- Places a subprocessor list typically lives: a dedicated page, a DPA annex, or nowhere public at all
- in the CertReports index on 2026-09-23
How to compare subprocessor lists across a shortlist
Reading one list at a time misses the point. The value of a shortlist review is comparing lists side by side, because two vendors offering the same core product often route data through a very different set of subprocessors, and that difference is sometimes the deciding factor once you also weigh price and features against everything else. The sequence below works even with a plain spreadsheet.
- 1
Pull the current list, not a cached one
Go to the vendor's own page rather than a copy someone saved to a shared drive last year. Check the last-updated date before you read anything else.
- 2
Map the overlap
List every subprocessor across all vendors on the shortlist in one sheet. The same four or five infrastructure and email providers turn up behind most SaaS products, so your real new exposure is usually a short list, not a long one.
- 3
Check the notice mechanism, not just the notice period
A thirty-day window is only useful if the vendor also commits to telling you when the clock starts. Confirm whether notice comes by email, by a change log, or only by checking the page yourself. - 4
Cross-check against the framework evidence
If a subprocessor handles hosting or storage, see whether it shows up as a subservice organisation in the vendor's SOC 2 report or as part of its FedRAMP boundary. A mismatch between the two documents is worth a direct question. - 5
Set a recheck cadence
Subprocessor lists change more often than certificates renew. A quarterly recheck, or a subscription to the vendor's change notifications where one exists, catches additions between your annual review cycles.
A worked example: reading a real subprocessor list
Notion is a useful case because its subprocessor list sits next to a public DPA rather than being emailed on request, which is the arrangement worth looking for on any vendor's own page. Open both documents together: check whether the DPA's sub-processing clause matches the mechanism described above, then check whether every entity named in the list also carries a stated purpose and location rather than just a name.

Notion · Trust report
Collaboration · Public evidence as of 25 Sep 2026
Framework overview
CertReports state for each framework with public evidence: 11 vendor-stated, 1 expired.
GDPRVendor-statedTrust centre · 25 Sep 2026
HIPAAVendor-statedBadge only, BAA not captured
SOC 2Vendor-statedType II report
PCI DSSVendor-statedTrust centre · 25 Sep 2026
ISO 27001Vendor-statedTrust centre · 25 Sep 2026
ISO 27701Vendor-statedTrust centre · 25 Sep 2026
SOC 3Vendor-statedTrust centre · 25 Sep 2026
ISO 27017Vendor-statedTrust centre · 25 Sep 2026
DPFExpiredListing inactive
3Documents and agreements
Legal and review documents Notion publishes or offers, as of 25 Sep 2026.
- Data processing agreement · Public
- Subprocessor list · Public
- Privacy policy · Public
26Subprocessors
Named on Notion's public subprocessor list, last seen 25 Sep 2026.
Red flags when a list is missing, stale or vague
- No last-updated date anywhere on the page or in the DPA annex
- A single line saying the vendor 'uses trusted third-party providers' with no names
- A list that has not changed in over a year for a vendor that has visibly added product features, which usually means new infrastructure and new subprocessors behind them
- A notice period described only as 'reasonable' or 'as required by law' with no number attached
- Countries named in the list that do not appear in the DPA's international transfer annex
- A sales team that will only share the list after a contract is signed
Building this into a recurring vendor review
A subprocessor check is not a one-off gate at procurement, it is a line item in whatever cadence already governs vendor reviews, alongside the SOC 2 renewal date and the DPF listing status. A 30-minute vendor security review using public evidence sets out the wider checklist this slots into, and if a vendor exposes its evidence through an API rather than a page you have to remember to revisit, Webhooks and the JSON API explains how to pull change events like new subprocessors straight into your own tracker instead. The goal is the same either way: catch the addition during the notice window, not three months after the subprocessor has already been processing data.
People also ask
What is a subprocessor?
A subprocessor is any third party a vendor engages to process personal data on behalf of a customer as part of delivering the service, such as a cloud host, an email delivery provider, a payment processor or a support desk tool that stores ticket content. It does not include the vendor's own staff, and it should not include every optional integration a customer can connect, only the ones the vendor itself sends data to by default.
How much notice must a vendor give before adding a subprocessor?
There is no fixed legal minimum. The Standard Contractual Clauses leave the exact period for the contracting parties to specify, which is why it varies by vendor. Thirty days before the change takes effect is the figure that appears most often in the CertReports index on 2026-09-23, though some vendors specify fourteen days or ten business days, and a few offer no number at all, which is worth challenging before you sign.
Where do vendors publish their subprocessor list?
Most publish it in one of three places: a standalone page usually linked from the trust centre or footer, an annex attached to the data processing agreement, or nowhere public at all, released only on request after a contract is signed. The first two are worth favouring, because you can check them before committing to a vendor rather than discovering the list once you are already a customer.
Is a subprocessor list required by GDPR?
GDPR itself does not name a specific list document, but Article 28 requires a processor to have the controller's authorisation before engaging a subprocessor and to inform the controller of any changes, giving it the chance to object. In practice, vendors meet that obligation with a published list and a notice mechanism defined in the DPA, which is why a vendor's own list and its DPA should always tell the same story.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
The Data Privacy Framework survived the General Court. What buyers should do while the appeal runs
Solomon Amos · 8 Sep 2026 · 9 min read