Subprocessor lists are the disclosure of every third party that touches personal data on behalf of your business – payment processors, email delivery services, cloud hosting providers, analytics vendors, customer support platforms – and if your privacy policy doesn’t name them or link to a current list, you likely have a compliance gap. This matters more than most site owners realize, because a subprocessor list isn’t just a nice-to-have transparency gesture. Under GDPR and similar frameworks, it’s often a documented obligation tied directly to your data processing agreements with customers.
What counts as a subprocessor, exactly
A subprocessor is any third party your company brings in to help process personal data that ultimately belongs to your customers or users. If you’re a SaaS company, your customers are the data controllers, you’re the processor, and anyone you outsource pieces of that processing to is a subprocessor.
Common examples include:
– Cloud infrastructure providers (AWS, Google Cloud, Azure)
– Email and SMS delivery services
– Payment gateways
– Customer support and helpdesk tools
– Analytics and error-tracking platforms
– Backup and disaster recovery vendors
Each one of these touches data in some way – storing it, transmitting it, logging it, or analyzing it. That’s enough to trigger disclosure obligations in most cases.
Why a privacy policy without a subprocessor list falls short
A generic privacy policy that says “we may share your data with trusted partners” without naming who those partners are technically fails the transparency principle under GDPR Article 13 and 14. Regulators expect specificity: who processes the data, where they’re located, and what safeguards are in place – particularly for transfers outside the EU/EEA.
Here’s a scenario that plays out often. A mid-sized SaaS company signs a new data processing agreement with an enterprise customer. The DPA includes a clause requiring the vendor to maintain an up-to-date subprocessor list and notify customers before adding a new one. Six months later, the vendor switches email providers without updating the list or notifying anyone. A customer’s security team does a routine vendor review, finds the mismatch between the DPA obligations and the actual privacy policy, and flags it as a contract breach. Now there’s a scramble to publish a corrected list, notify affected customers, and explain the gap – all avoidable with a simple update process.
The myth: “Subprocessor lists are only for enterprise B2B contracts”
A common misconception is that subprocessor disclosure only matters for companies with formal DPAs signed with enterprise clients. In practice, GDPR’s transparency requirements apply regardless of contract size. Even a small e-commerce store using a third-party checkout provider and an email marketing tool is processing personal data through subprocessors, and consumers have the same right to know who handles their information as enterprise customers do. The obligation doesn’t scale down just because the business is small.
How to build and maintain a subprocessor list
1. Inventory every vendor touching personal data. Go beyond the obvious tools – include anything logging IP addresses, storing form submissions, or processing payment details.
2. Document the purpose and location of each subprocessor. Note what data they touch, where they’re headquartered, and whether cross-border transfer safeguards (like SCCs) apply.
3. Publish the list where it’s easy to find. Either embed it directly in the privacy policy or link to a dedicated, regularly updated subprocessor page.
4. Set a notification process for changes. Many DPAs require advance notice – often 15 to 30 days – before adding or replacing a subprocessor. Build this into your vendor onboarding workflow, not as an afterthought.
5. Review the list on a fixed schedule. Quarterly reviews catch drift between what’s actually running on your site and what’s documented.
The step that trips up most teams is the fourth one. Engineering swaps a vendor for cost or performance reasons, and nobody loops back to update the legal documentation. This is exactly the kind of change that website updates can quietly break compliance without anyone noticing.
Where subprocessor lists intersect with your DPA obligations
Your subprocessor list doesn’t live in isolation – it’s usually a contractual requirement documented in the data processing agreements you sign with customers. If you’re unclear on when your site actually needs a formal DPA in the first place, it’s worth reviewing when your site needs a data processing agreement before assuming a simple privacy policy mention is sufficient.
Larger organizations often assign this responsibility to a data protection officer or a designated compliance lead, since keeping subprocessor disclosures synced with vendor contracts and privacy policy language is an ongoing task, not a one-time project. The breakdown of who typically owns this work is covered in more detail in the piece on DPO responsibilities for mid-sized businesses.
Keeping the list accurate over time
The biggest practical challenge isn’t writing the list – it’s keeping it accurate as vendors change. Privacy policies tend to be treated as “set and forget” documents, updated once during a launch or legal review and then left untouched for years. Meanwhile the actual tech stack keeps evolving.
A privacy policy that silently falls out of sync with reality is a quiet liability – nobody notices until an audit, a customer’s security questionnaire, or a regulator’s inquiry surfaces the gap. Ongoing verification that your published policy still matches your current vendor relationships is a core part of avoiding this, something explored further in privacy policy monitoring and preventing costly oversights.
FAQ
Does every website need a public subprocessor list?
Not every website needs a dedicated subprocessor page, but any site processing personal data through third-party tools should disclose those relationships in its privacy policy at minimum. B2B SaaS companies with formal DPAs almost always need a maintained, linkable list, while smaller sites can often meet the requirement with clear category-level disclosures.
How often should a subprocessor list be updated?
It should be updated whenever a subprocessor is added, removed, or replaced – not on a fixed calendar alone. Many contracts require advance notice before changes take effect, so updates need to happen proactively, ideally as part of vendor onboarding rather than during a periodic review.
What happens if a subprocessor list is outdated or missing?
Consequences range from failed customer security audits and breached contract terms to regulatory findings of inadequate transparency under GDPR. The severity depends on context, but the fix – publishing an accurate, current list – is the same regardless of how the gap was discovered.
Summary
A subprocessor list is a small piece of a privacy policy that carries outsized legal weight. It’s the concrete answer to “who else touches my data,” and both regulators and enterprise customers expect it to be accurate, current, and easy to find. The practical fix is straightforward: inventory your vendors, publish the list, build a notification process into vendor changes, and check it regularly against what’s actually running on your site – rather than waiting for an audit to reveal the gap.
