Guide

How to Audit Your Vendors' Subprocessors

When you sign a contract with a SaaS vendor, you are also implicitly accepting relationships with every other company that vendor uses to deliver its service. These subprocessors — cloud hosting providers, payment processors, email delivery services, analytics tools — may handle your data, sometimes including sensitive data classes like PHI or PII. GDPR Article 28 requires that data processors only use sub-processors with your prior authorization, and that you are notified of material changes.

Why do subprocessors matter for risk?

Subprocessors extend your vendor’s attack surface to their vendors. A breach at a subprocessor is a breach in your vendor’s data pipeline. The 2013 Target breach — accessed through an HVAC vendor — is the canonical example of fourth-party risk. For SaaS vendors, the equivalent is a security incident at the error monitoring or analytics subprocessor that has access to session data or database query logs containing customer data.

What should a subprocessor list contain?

A complete subprocessor list should include: the subprocessor name, the legal entity (not just the brand name), the data processing location, the purpose of processing, the categories of data processed, and a description of safeguards for international transfers. In practice, most vendor subprocessor pages include only name, location, and purpose — missing the legal entity information that is required for standard contractual clause coverage.

How often do subprocessor lists change?

More often than most procurement teams realize. TrustVendor’s analysis of monitored vendors shows that roughly 15–20% of vendors modify their subprocessor list in any given quarter. Changes range from minor (updating a company address) to material (adding a data processing entity in a new jurisdiction). Annual review cycles miss most of these changes. Continuous monitoring surfaces them within hours of the page update.

What should you do when a subprocessor changes?

When you detect a subprocessor change, assess materiality against three criteria: (1) Does the new or modified entity have access to personal data subject to GDPR or other regulation? (2) Is the new entity in a jurisdiction without an adequacy decision or standard contractual clause coverage? (3) Does the new entity’s purpose overlap with the data classes you share with this vendor? Material changes should trigger a formal review and, where GDPR applies, may require updating your record of processing activities.

Common questions

Under GDPR, can a vendor change subprocessors without notifying me?
No. GDPR Article 28(2) requires that processors inform controllers of any intended changes concerning the addition or replacement of sub-processors, giving the controller the opportunity to object. Many DPAs implement this as a rolling 30-day notice window.
How do I track subprocessors for a large vendor portfolio?
Manual tracking is not feasible beyond a handful of critical vendors. TrustVendor monitors subprocessor pages continuously and alerts you when entities are added, removed, or modified — with a before-and-after diff showing exactly what changed.
What is fourth-party risk?
Fourth-party risk is the risk from your vendors' vendors — the subprocessors of your subprocessors. TrustVendor's subprocessor concentration analysis shows where multiple vendors in your portfolio share the same underlying infrastructure provider, creating correlated risk.

Related guides

What Is Third-Party Risk Management (TPRM)?Residual Risk in Third-Party Risk ManagementEvidence Decay: Why Freshness Is a First-Class Risk Concept

Put evidence behind every vendor claim.

TrustVendor automates the evidence collection this guide describes.

Book a demo