GDPR
How to keep a GDPR sub-processor list that you can actually export
Controllers must know which processors and sub-processors handle personal data. This guide covers what belongs on the list, Article 28 duties, and how to answer customer questionnaires without a week of Slack.
Published 2026-08-24
A GDPR sub-processor list is the customer-facing cut of your vendor register: every processor that handles personal data on your instructions, plus enough detail to show you know what you are doing. Article 28 expects documented instructions, assistance with data-subject rights, and control over onward processors. None of that works if the list lives in last year’s proposal deck.
What belongs on the list
- Hosting, email, CRM, billing, support, analytics (if personal data is processed), HR/payroll, and AI tools that receive customer or employee content.
- Purpose of processing in one line (“transactional email”, “error logs”, “model inference”).
- Location of processing and transfer tool (adequacy, SCCs, DPF) when relevant.
- Link or date of the DPA / SCC pack.
What to leave off
Hardware retailers, law firms acting as independent controllers, and tools that never receive personal data do not belong on the list you send a customer. Mixing them in makes you look unsophisticated and creates questions you then have to unpick on a call.
Change notice is part of the product
Many customer DPAs require 14–30 days’ notice before you add a sub-processor. That is only possible if someone owns the list and new vendors cannot go live in production without a register row. A chase board for missing DPAs is the operational counterpart: you cannot notify customers about a processor you have not recorded.
Export once, paste many times
Questionnaires ask the same thing in five formats. PrivyLedger keeps one inventory and exports a sub-processor list, SIG-Lite-style answers, CAIQ-style answers, CSV, or JSON. Review the footer: exports are evidence drafts, not legal advice.
PrivyLedger’s own sub-processor list is public at /subprocessors so you can see the standard we hold ourselves to.
Questions
What is a sub-processor under GDPR?
A sub-processor is a processor engaged by your processor to handle personal data. If you are the controller, your vendors are processors; their downstream vendors are sub-processors you still need visibility into when customers ask.
Do I have to publish my sub-processor list?
Not always publicly. You must be able to inform customers (and often must notify them of changes) under your DPAs. Publishing a current list, as PrivyLedger does for itself, reduces back-and-forth.
Is a finance SaaS export enough?
No. Card statements miss free tools, AI copilots, and subprocessors named in a vendor’s own DPA. Finance is a discovery input, not the register.