Menu

Subprocessor lists

A subprocessor list per client, current on the day you send it

The list your client's customers ask for, built from the vendors that client actually uses, with the entity and transfer mechanism of each one taken from a registry we check ourselves.

Free · No sign-up · Up to ten websites

What is a subprocessor list?

A subprocessor list names the other companies a processor uses to deliver its service. Article 28 of the GDPR lets a processor engage another processor only with the controller's authorisation, and the controller has to be told about changes in time to object — which is why the list is usually published alongside the data processing agreement.

The awkward part is that it goes stale quietly. A vendor moves its EU contracting entity, replaces a transfer mechanism or adds a sub-processor of its own, and every list that named it is wrong until somebody notices.

What it has to cover

  • Each sub-processor's legal entity and country of registration
  • What it is used for, and which personal data it sees
  • The transfer mechanism for anything leaving the EEA
  • A link to that vendor's own data processing agreement
  • How and when the controller is told about a change

What changes when it is not done by hand

From a registry

The facts come from one verified place

Each vendor is one record: entity, country, transfer mechanism, DPA link and the date it was verified. Every client's list reads the same record, so two clients can never disagree about the same vendor.

Matched, not typed

Client vendor names resolve to registry records

The names a client gives in the interview, or that appear in their existing documents, are matched to registry records instead of being retyped per client.

Changes tracked

You hear about a change before the client does

Vendor pages are checked daily. A change is reviewed by a person before it reaches you, and then shows which of your clients it affects and which documents to regenerate.

What you get

Every vendor fact comes from our own registry: 157 vendors with the date each entry was checked.

A registry we verify ourselves

Vendors with their legal entity, country, transfer mechanism, DPA and sub-processor links, each with the date it was last checked.

Table built by code

The list is assembled from the client's vendors and the registry, so it never contains a vendor or a URL that is not in the data.

Publishable on a trust page

Publish the list on the client's trust page, under your brand, and keep the document version for their DPA.

Out-of-date marking

When a vendor's entity or terms change, the documents naming it are marked out of date per client.

Import what already exists

Read the client's current list from a DOCX or PDF, keeping only facts that appear in the document, each with its quote.

Registry download

Take the whole registry as a CSV when you want to work outside the workspace.

Get started in three steps

  1. 1

    Collect the client's vendors

    From the interview, from a document you import, or from a scan of their website. Each name resolves to one registry record.

  2. 2

    Generate the list and the DPA

    The table is built from those records with your firm's wording around it, and the same facts feed the record of processing.

  3. 3

    Publish it and keep it watched

    Publish on the client's trust page or export it, then get told when a vendor changes so you can regenerate before anyone asks.

Questions

Where do the vendor facts come from?
From our own registry. Each record is verified against the vendor's published documents and carries the date it was checked; the page for a vendor shows that date.
What if a client uses a vendor you do not have?
You can add it for that client. It becomes a candidate for the registry, and until it is verified it is shown as unverified rather than as a checked record.
Do you tell my clients about vendor changes?
No. We tell you, with the list of your clients affected. What the client hears, and when, stays with you.
Is a sub-processor the same as a processor?
A sub-processor is a processor engaged by another processor. Whether a given vendor is one for a given client is a judgement you make; we supply the facts about the vendor.
Can the list live on our own domain?
Yes. A trust page can be served from your own domain, with your branding and without any mention of us.

See what changed since your clients' policies were written

Enter up to ten client websites. Free, no sign-up, the first report in about a minute.