Sub-processor changes

What is a sub-processor?

A sub-processor is a company your vendor brings in to process personal data you handed to the vendor. When you use an AI vendor, its cloud host, its model provider and its support tools can each be sub-processors of your customers’ data. The law is quoted below from the official text, and every vendor clause from an agreement we read on the date shown.

What the GDPR says

The GDPR does not use the word. It calls a sub-processor “another processor”, and sets two rules: the vendor needs your authorization, and the sub-processor takes on the same obligations.

The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.

GDPR Article 28(2) — official text · read September 30, 2026

Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law

GDPR Article 28(4) — official text · read September 30, 2026

Specific or general authorization

The standard contractual clauses, the EU’s template for sending personal data outside the EU, spell out the two ways a customer can authorize sub-processors. Under the first, the vendor asks each time. Under the second, the vendor works from an agreed list and tells you before it changes.

OPTION 1: SPECIFIC PRIOR AUTHORISATION The data importer shall not sub-contract any of its processing activities performed on behalf of the data exporter under these Clauses to a sub-processor without the data exporter’s prior specific written authorisation. The data importer shall submit the request for specific authorisation at least [Specify time period] prior to the engagement of the sub-processor, together with the information necessary to enable the data exporter to decide on the authorisation.

Standard contractual clauses, Clause 9(a), Module Two, Option 1 — official text · read September 30, 2026

OPTION 2: GENERAL WRITTEN AUTHORISATION The data importer has the data exporter’s general authorisation for the engagement of sub-processor(s) from an agreed list. The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of sub-processors at least [Specify time period] in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the sub-processor(s).

Standard contractual clauses, Clause 9(a), Module Two, Option 2 — official text · read September 30, 2026

The period is left blank in the template, for the parties to fill in. Vendors fill it in their own DPAs. The standard contractual clauses have their own page.

Where the data importer engages a sub-processor to carry out specific processing activities (on behalf of the data exporter), it shall do so by way of a written contract that provides for, in substance, the same data protection obligations as those binding the data importer under these Clauses, including in terms of third-party beneficiary rights for data subjects.

Standard contractual clauses, Clause 9(b), Module Two — official text · read September 30, 2026

Sub-processor lists, and how notice is given

Under general authorization, the agreed list is often a page on the vendor’s own site; we read 100 of them. Some agreements treat an edit to that page as the notice itself:

At least ten (10) days before enabling any third party other than existing Authorized Subprocessors to access or participate in the processing of Personal Data, AssemblyAI will add such third party to the List and notify Customer via the email address subscribed to receive notifications of New Subprocessors as described herein. Customer may object to such an engagement by informing AssemblyAI within ten (10) days of receipt of the aforementioned notice to Customer, provided such objection is in writing and based on reasonable grounds relating to data protection.

AssemblyAI — https://assemblyai.com/legal/data-processing-addendum · read September 30, 2026 · snapshot fbdd5e9283b3

Where notice is a page rather than an email, nothing arrives in anyone’s inbox. The page changes and the objection period starts. What the notice clause obliges you to do covers this in detail.

How long you have to object

We quote the objection period from 70AI vendors’ agreements. The shortest is 5 business days. Business days and calendar days both appear, and they are not the same clock:

Customer may object to the Processing of Customer’s Personal Data by the New Sub-Processor, for reasonable and explained grounds, by providing a written objection to [email protected] within 5 business days following Gong’s written notice to Customer of the intended engagement with the New Sub-Processor.

Gong — https://gong.io/legal/data-processing-addendum · read August 31, 2026 · snapshot cab59af09f81

Every window we hold is listed with the vendor’s own sentence, its source and the date we read it.

How often the lists move

We read 100 sub-processor lists for 186 AI vendors. Since the archive began, 88vendors’ lists have differed from our previous copy, and we have recorded 83 names added and 57 removed. Each change is published on what changed 30 days after we record it; subscribers are told the morning we read it.

The free stack scan reads your own sub-processor page and shows the notice window each listed vendor gives you.

Common questions

What is a sub-processor?
A company that a processor (your vendor) engages to carry out processing of personal data on behalf of the controller (you). The GDPR describes it in Article 28(2) and 28(4) as "another processor"; the standard contractual clauses call it a sub-processor.
Does a vendor need permission to add a sub-processor?
Under GDPR Article 28(2), a processor may not engage another processor without the controller's prior specific or general written authorization. Under general authorization it must inform the controller of intended additions or replacements, giving the controller the opportunity to object.
What is a sub-processor list?
The list of sub-processors a vendor uses. AI vendors publish these lists as pages on their own sites, and Xither reads them for the vendors it watches. Under general authorization, a change to that list is what the controller is told about and can object to.
How long do I have to object to a new sub-processor?
It depends on the vendor's DPA. The standard contractual clauses leave the period blank for the parties to fill in ("at least [Specify time period]"). Xither quotes the period from each AI vendor agreement it holds on its notice windows page.
What is the difference between a processor and a sub-processor?
The processor is the vendor you contracted with. A sub-processor is a company that vendor engages. GDPR Article 28(4) requires the same data protection obligations to be imposed on the sub-processor by contract.

What this page is not

It is not legal advice. It quotes the law and published agreements on the dates shown; a negotiated contract may say something else, and it governs.

Xither Staff Writer · reviewed September 30, 2026. Vendor clauses and counts are generated from the record when the page is served.