Subprocessor List Management
Subprocessor list current within 24h of change
Subprocessor lists are a compliance obligation nobody wants to own. DPAs commit us to publishing a current list of subprocessors handling customer data and to notifying customers of additions or changes. In practice: the published list lags reality by 3-6 months, additions happen without customer notice, and one customer's routine audit finds the discrepancy. Trust page shows 47 subprocessors; procurement has 89 vendors with data-processing agreements.
An hour-by-hour walkthrough.
Step by step.
- 01
Nightly reconciliation across sources
Trust page published list + procurement vendor list (data-processing flagged) + production integration inventory. Normalise vendor identities across sources ("Segment" = "Segment.io, Inc." = the segment.com API endpoint).
Trust page · Procurement · Production inventory · Vendor registry - 02
Detect + classify discrepancies
New (add), removed (delete), changed (fourth-party addition). Each has different obligation: new + removed require customer notice + trust page update; changed depends on DPA language.
Reconciliation engine · DPA obligation matrix - 03
Draft actions with customer-notice planning
Trust page update (Git PR or CMS update). Customer notification with the required lead time before the change (30 days typical). DPA-tier-specific notifications: some customers require signed acknowledgement, others just informational.
Git · CMS · Email · Customer notification tier - 04
Weekly legal review + batch approval
Weekly review of the batch: adds, removes, changes with the drafted actions. Legal approves or edits. On approval, changes fire in sequence with the notification lead time respected.
Web UI · Slack · Approval flow - 05
Notify + verify + audit
Customer notifications fire per tier + region. Delivery confirmations tracked. Trust page updates go live at the effective date. Audit record with every notification + acknowledgement for regulatory response.
Email · In-app · Trust page · Audit log
What you connect to make this run.
Trust page · CMS · Static site
read+writePublished subprocessor list. Updates via CMS or Git PR to a source of truth file. Change events time-stamped so customer notice periods can be honoured (announce the change; effective 30 days later).
Coupa · Ramp · Airbase · Vendor management
readVendor list filtered to data-processing-flagged contracts. Vendors added, removed, or reclassified feed the reconciliation.
API integration inventory · Cloud posture
readProduction integration monitoring: which external services are we actually calling with customer data. Catches shadow subprocessors that procurement missed.
Email · Customer notification platform
read+writeCustomer notifications with acknowledgement tracking. Notification tier per customer contract (some require signed ack; some informational). Delivery confirmation retained for audit.
Before and after, honestly.
Playbooks that pair with this one.
DPA Handling
DPA language dictates notification obligations; consulted per subprocessor change.
Vendor Security Review
New subprocessors require security review before DPA sign-off; joint intake.
Privacy Review for New Features
New features adding subprocessors trigger this list update as part of launch approval.
Answers about this playbook.
What if a subprocessor is added mid-notification-window?
Change effective date deferred to end of notification window. If urgent business need to onboard immediately, customer notice fires with the shorter timeline + apology; some customers may formally object per DPA.
How does it handle customer objections to a new subprocessor?
Objection intake. Customer's objection routes to legal + the business owner. Options: contract termination for-cause (rare), agreed workaround (segregate customer's data from that subprocessor), or accept objection is unactionable per contract terms.
What about subprocessors we're removing (going off contract)?
Removal notification + data-return / deletion verification with the subprocessor. Audit record of the removal + the data disposition (returned to us, deleted, escrowed).
Can we differentiate subprocessor lists by product line?
Yes — product-specific subprocessor lists common when the SaaS has multiple product surfaces with different data flows. Customer sees the list relevant to the products they subscribe to.
How does this coordinate with SOC 2 / ISO 27001 subprocessor reviews?
Same list; different consumer. Compliance audits reference the same trust-page list + supporting DPA evidence. Consistency across compliance frameworks + customer-facing disclosures.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.