Free tool

Subprocessor change alerts: get an email when a vendor's subprocessor list changes

Enter the address of a vendor's subprocessor list, privacy policy or DPA page. We read it once a day and email you a short summary when the text changes, so a new subprocessor does not slip past your objection period.

Published 7 October 2026 · Sources checked 7 October 2026

The vendor's subprocessor list, privacy policy or DPA, for example https://vendor.com/legal/subprocessors

Shown in your alert emails, for example "Survey tool subprocessors".

We use this address only to send you a confirmation email and, once you confirm, an email when the page changes, with a short AI-written summary of what changed. Nothing is sent until you click the confirmation link. Every alert has an unsubscribe link, unconfirmed requests are deleted after 7 days, and you can follow up to 10 pages per address. See our privacy policy.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

On this page
  1. Why subprocessor changes matter
  2. How much notice vendors give
  3. How to find a vendor's subprocessor list
  4. What to do when an alert arrives
  5. How the alerts work
  6. Sources
  7. About this page

Why subprocessor changes matter

When a university uses a cloud service to handle personal data, the vendor is usually a processor and the university the controller. Article 28(2) GDPR says the processor may not engage another processor (a subprocessor) without the controller's prior specific or general written authorisation. Most vendor contracts use general authorisation: you approve the current list, and the vendor must inform you of intended additions or replacements, "thereby giving the controller the opportunity to object" [1].

The EDPB explains why that notice matters. Under a general authorisation, the controller's failure to object within the agreed timeframe can be interpreted as authorisation [2]. In other words, a notice that nobody reads becomes a yes.

A new subprocessor can change your risk picture in several ways:

How much notice vendors give

The GDPR itself sets no number of days. The EDPB says the contract should state the timeframe for approval or objection, that it should be reasonable given the processing, and what happens after an objection [2]. The European Commission's standard contractual clauses for controllers and processors leave the period as a blank: the processor informs the controller of changes "at least [SPECIFY TIME PERIOD] in advance" [3].

Two published vendor DPAs, read on 7 October 2026, show how this is filled in in practice:

Validemic's analysis

Two practical points follow. First, an objection right often means ending the service, so the earlier you know, the more options you have, for example negotiating, changing configuration or planning an exit. Second, where notices go only to subscribed addresses, the right person at the university has to be subscribed, and stay subscribed when staff change. An independent alert does not replace the vendor's notice, but it is a cheap second line.

How to find a vendor's subprocessor list

  1. Read the DPA. It usually links to the list or includes it as an annex. If the list is only in an annex of a signed PDF, ask the vendor where changes are published.
  2. Look in the footer. Legal, Privacy, Trust or Security pages often link to "Subprocessors" or "Sub-processors". Atlassian and Google Cloud, for example, publish theirs as public web pages [5] [6].
  3. Search the vendor's site for "subprocessors", "sub-processors" or "third parties", and check the trust centre if the vendor has one.
  4. Ask the vendor. If nothing is published, ask for the list and for the notification method in writing. That answer belongs in your vendor assessment.

If the vendor offers its own notification sign-up, use it as well. Then paste the list's address into the form above.

What to do when an alert arrives

  1. Open the page and confirm the change. The summary is written by AI and can miss nuance, so read the added and removed entries yourself.
  2. Check your contract. Find the notice and objection period in your DPA and note the deadline. If you never received the vendor's own notice, ask why.
  3. Assess the new company. Note its role, where it processes data, and whether a transfer outside the EU/EEA is involved. Ask the vendor for the safeguards in place.
  4. Decide and record. Accept, ask questions or object in writing before the deadline, and update your records of processing and any DPIA that names the vendor.

How the alerts work

Validemic workspaces include the same change monitoring for all of a university's vendors and regulation texts, with the full text difference for each change and an in-app change feed.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28 and 44 to 46. EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng. Retrieved 7 October 2026.
  2. European Data Protection Board, Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1, paragraphs 155 to 160. edpb.europa.eu. Retrieved 7 October 2026.
  3. Commission Implementing Decision (EU) 2021/915 on standard contractual clauses between controllers and processors, Clause 7.7(a). EUR-Lex: eur-lex.europa.eu/eli/dec_impl/2021/915/oj/eng. Retrieved 7 October 2026.
  4. Google Cloud, Cloud Data Processing Addendum (Customers), section on subprocessors. cloud.google.com/terms/data-processing-addendum. Retrieved 7 October 2026.
  5. Atlassian, Data Processing Addendum, and List of Data Subprocessors. atlassian.com/legal/data-processing-addendum, atlassian.com/legal/sub-processors. Retrieved 7 October 2026.
  6. Google Cloud, Google Cloud Platform Subprocessors. cloud.google.com/terms/subprocessors. Retrieved 7 October 2026.

About this page

Legal text and vendor terms checked on 7 October 2026. Vendor examples show what those documents state on that date and apply to the named services only; other plans and products may have different terms. If you spot an error, please contact us and we will correct it.

Frequently asked questions

What is a subprocessor?

A subprocessor is another company your vendor (the processor) engages to process personal data on your behalf, such as a cloud host, an email service or an AI model provider. Article 28(2) GDPR requires your prior written authorisation for them.

How much notice do vendors give before adding a subprocessor?

It depends on the contract. The GDPR does not set a number of days, and the European Commission's standard clauses leave the period blank for the parties to fill in. Google Cloud's and Atlassian's DPAs, for example, both state at least 30 days.

Why use alerts if the vendor already notifies customers?

Vendor notices often go to whoever signed up for the vendor's mailing list, which may be a former colleague or a shared inbox nobody reads. An independent alert to the person responsible for the vendor relationship is a simple safety net.

Can the alert read any page?

It reads ordinary web pages, plain text and PDF files. Pages that only show their text after running scripts, or that sit behind a login, cannot be read; the form tells you if that is the case. Try the vendor's printable or PDF version instead.

How do I stop the alerts?

Every email has an unsubscribe link that stops alerts for that page straight away. Requests you never confirm are deleted after 7 days.