GDPR

How to keep a GDPR sub-processor list that you can actually export

Controllers must know which processors and sub-processors handle personal data. This guide covers what belongs on the list, Article 28 duties, and how to answer customer questionnaires without a week of Slack.

Published 2026-08-24

A GDPR sub-processor list is the customer-facing cut of your vendor register: every processor that handles personal data on your instructions, plus enough detail to show you know what you are doing. Article 28 expects documented instructions, assistance with data-subject rights, and control over onward processors. None of that works if the list lives in last year’s proposal deck.

What belongs on the list

  • Hosting, email, CRM, billing, support, analytics (if personal data is processed), HR/payroll, and AI tools that receive customer or employee content.
  • Purpose of processing in one line (“transactional email”, “error logs”, “model inference”).
  • Location of processing and transfer tool (adequacy, SCCs, DPF) when relevant.
  • Link or date of the DPA / SCC pack.

What to leave off

Hardware retailers, law firms acting as independent controllers, and tools that never receive personal data do not belong on the list you send a customer. Mixing them in makes you look unsophisticated and creates questions you then have to unpick on a call.

Change notice is part of the product

Many customer DPAs require 14–30 days’ notice before you add a sub-processor. That is only possible if someone owns the list and new vendors cannot go live in production without a register row. A chase board for missing DPAs is the operational counterpart: you cannot notify customers about a processor you have not recorded.

Export once, paste many times

Questionnaires ask the same thing in five formats. PrivyLedger keeps one inventory and exports a sub-processor list, SIG-Lite-style answers, CAIQ-style answers, CSV, or JSON. Review the footer: exports are evidence drafts, not legal advice.

PrivyLedger’s own sub-processor list is public at /subprocessors so you can see the standard we hold ourselves to.

Questions

What is a sub-processor under GDPR?

A sub-processor is a processor engaged by your processor to handle personal data. If you are the controller, your vendors are processors; their downstream vendors are sub-processors you still need visibility into when customers ask.

Do I have to publish my sub-processor list?

Not always publicly. You must be able to inform customers (and often must notify them of changes) under your DPAs. Publishing a current list, as PrivyLedger does for itself, reduces back-and-forth.

Is a finance SaaS export enough?

No. Card statements miss free tools, AI copilots, and subprocessors named in a vendor’s own DPA. Finance is a discovery input, not the register.

Related guides