Magrios / Knowledge / enterprise / What is a subprocessor list? A practical definit

What is a subprocessor list? A practical definition

Glossary · enterprise · 4 min read · last verified 2026-07-21

Reviewed before publication Editorial board Independent commercial review
In shortA subprocessor list documents the third parties a vendor (processor) engages to help process customer (controller) data. Under GDPR Article 28, the processor needs authorization and remains liable for subprocessor performance.

The short definition

A subprocessor list is a published record of the third-party vendors a company engages to help process personal data on behalf of its customers — common examples include cloud infrastructure providers (AWS, GCP, Azure), email and communications tools (Twilio, SendGrid), analytics platforms, customer support tooling, and increasingly, AI or LLM providers used to power product features. If your SaaS product touches your customers' personal data and you rely on other companies to help deliver the service, those companies are your subprocessors, and enterprise buyers will expect a documented, current list of them.

Getting the roles right — this is where people get it backwards

Under the EU GDPR framework (and similar structures in UK GDPR and various other data protection regimes), there are two core roles:

The obligation runs in a specific direction: the processor (you, the vendor) needs authorization from the controller (your customer) before engaging a subprocessor — not the other way around. This direction is easy to invert when writing about it casually, but it's the whole basis of why subprocessor lists exist and why customers care about them.

What GDPR Article 28 actually requires

Article 28 of the GDPR governs the processor relationship, and it specifically addresses subprocessors:

This is why a maintained, accessible subprocessor list matters operationally, not just as a compliance formality: it's how a vendor fulfills the "keep the controller informed" obligation at scale, instead of negotiating individual notices with every customer for every vendor change.

What a usable subprocessor list looks like

A subprocessor list that actually helps a customer's security or legal team review it typically includes:

The notice period, and why it's negotiated

GDPR doesn't mandate a specific number of days of advance notice for subprocessor changes — it requires that the controller get a genuine opportunity to object before the change takes effect. In practice, vendor data processing agreements commonly specify a notice window, and 30 days shows up frequently as a negotiated or offered standard, though shorter and longer periods both appear depending on the vendor and the customer's leverage. Buyers with strict internal review requirements should confirm the actual notice period in the DPA rather than assume a default.

Why this has gotten more scrutiny lately

Two trends have pushed subprocessor lists from a compliance checkbox to an active review item in enterprise deals:

What buyers should actually check

This is general information about how subprocessor obligations commonly work under GDPR-style frameworks, not legal advice — specific obligations depend on your data flows, roles, and applicable law, so confirm details with counsel and the vendor's actual DPA.

Frequently asked questions

What is a subprocessor in GDPR terms?

A subprocessor is a third party that a processor (typically the SaaS vendor) engages to help process personal data on behalf of the controller (typically the vendor's customer). Examples include cloud hosting, email delivery, and AI model providers.

Who needs to authorize a new subprocessor — the vendor or the customer?

The processor (vendor) needs authorization from the controller (customer) before engaging a subprocessor, either specific or general. This direction is easy to get backwards but is the core of Article 28's subprocessor rules.

Is the vendor still liable if a subprocessor causes a data breach?

Yes. Under GDPR Article 28, the original processor remains fully liable to the controller for the subprocessor's performance of its data protection obligations — engaging a subprocessor doesn't transfer that accountability away.

How much notice does a vendor have to give before adding a subprocessor?

GDPR requires a genuine opportunity to object before the change takes effect, but doesn't mandate a specific number of days. Many vendor DPAs specify a notice window, commonly around 30 days, though this varies — check the actual DPA.

Should AI or LLM providers be listed as subprocessors?

If customer personal data is routed through a third-party AI model to power a product feature, that model provider is functioning as a subprocessor and should be disclosed, ideally along with whether the data is used for model training.

Further reading — chosen for this article
Entities in this research
subprocessor listGDPR Article 28controllerprocessorsubprocessordata processing agreementgeneral authorizationspecific authorization
Related knowledge

What is a vendor risk tier? A practical definition · linked

What are data residency requirements? A practical definition · shared entities

What Is a Paper Process? A Practical Definition · shared entities

What is an SBOM? A practical definition · linked

What is a change advisory board? A practical definition · linked

Recently updated

Magrios vs Athena · 2026-07-21

Magrios vs Writesonic · 2026-07-21

Magrios vs Semrush · 2026-07-21

Magrios vs peec · 2026-07-21

Where does your brand stand?
Check your AI visibility free — real evidence, not a score.
Check my visibility or run the full analysis →