Why do subprocessors matter for risk?
Subprocessors extend your vendor’s attack surface to their vendors. A breach at a subprocessor is a breach in your vendor’s data pipeline. The 2013 Target breach — accessed through an HVAC vendor — is the canonical example of fourth-party risk. For SaaS vendors, the equivalent is a security incident at the error monitoring or analytics subprocessor that has access to session data or database query logs containing customer data.
What should a subprocessor list contain?
A complete subprocessor list should include: the subprocessor name, the legal entity (not just the brand name), the data processing location, the purpose of processing, the categories of data processed, and a description of safeguards for international transfers. In practice, most vendor subprocessor pages include only name, location, and purpose — missing the legal entity information that is required for standard contractual clause coverage.
How often do subprocessor lists change?
More often than most procurement teams realize. TrustVendor’s analysis of monitored vendors shows that roughly 15–20% of vendors modify their subprocessor list in any given quarter. Changes range from minor (updating a company address) to material (adding a data processing entity in a new jurisdiction). Annual review cycles miss most of these changes. Continuous monitoring surfaces them within hours of the page update.
What should you do when a subprocessor changes?
When you detect a subprocessor change, assess materiality against three criteria: (1) Does the new or modified entity have access to personal data subject to GDPR or other regulation? (2) Is the new entity in a jurisdiction without an adequacy decision or standard contractual clause coverage? (3) Does the new entity’s purpose overlap with the data classes you share with this vendor? Material changes should trigger a formal review and, where GDPR applies, may require updating your record of processing activities.