Discovery queue open Typical turnaround: one working day The register Method Talk to a reviewer
subprocessor.org
Six sources. One reviewed list. Re-checked daily.See how the work flows →
Same engine, different job to be done.Compare the tiers →
We publish observations and dated records, never legal conclusions.Read the method →
Free to read. No account.Open the register →
Sub-processor discovery & upkeep

We'll take it
from here.

Send us your domain and stop maintaining a sub-processor list by hand. We go through your legal pages, your DNS and mail records, your response headers, your consent tooling and any spreadsheet you already keep — then a named reviewer confirms every line before it goes anywhere near your customers.

Rather speak to a person first? Book fifteen minutes with a reviewer

Sign in with Google, nothing to install Nothing published without your approval It stays yours either way
21 found so far
Discovery · northwind.io
opened 09:04 · six sources · 41 minutes elapsed
in progress
✓ Legal pages read/legal/subprocessors · /privacy · DPA §9 12 found
✓ Mail and DNS recordsMX · SPF · CNAME chain 3 found
✓ Response headerscontent-security-policy · connect-src 5 found
✓ Your vendor spreadsheetsent 09:06 · 34 rows read 34 read
◐ Reviewer checking each sourcede-duplicating names, classifying what touches customer data now
3 Your approvalyou see it before anyone else does next
21 sub-processors assembled
3 need a decision from you · nothing published yet
RO
Rachel Okafor
Lead reviewer on your list
22 businesses already in the register Discovery across six sources Checked again every day Dated history from day one
how the work actually flows

Six places we look. One list. Checked again tomorrow.

Nothing here is a guess. Each source is read on its own, everything converges into one candidate pool, a reviewer resolves the overlaps, and then the loop repeats daily for as long as you're with us.

Legal pages & DPA/legal · /privacy · annexMail & DNS recordsMX · SPF · CNAMEResponse headerscontent-security-policyConsent toolingvendor manifestYour spreadsheetor procurement exportContracts you sendDPAs · order forms Reviewed every source cross-checked, duplicates resolved,scope decided RO Your published list 21 entities · 5 countries dated from today RE-CHECKED DAILY
01
We look, not you

Six independent sources, read separately, so one out-of-date page can't hide a vendor.

02
Overlaps resolved

The same company turns up under three names. A reviewer decides which one is real.

03
You approve

Nothing reaches the register or your customers until you have seen it and said yes.

04
Then it repeats

The loop runs every day, and every movement gets a date recorded against it.

why this is landing now

The obligation is old. The expectation isn't.

Article 28 has required notice of sub-processor changes since 2018. What changed recently is how current your list is expected to be, who now has to log the chain beneath it, and how often someone asks to see the record.

MAY 2018
GDPR applies

Notice of sub-processor changes becomes mandatory. The law fixes no deadline — your contract does.

OCTOBER 2024
EDPB raises the bar

Lists are expected to stay current, with detail and time enough to actually object.

JANUARY 2025
DORA applies

Financial entities must log the subcontracting chain, not only the vendor above it.

MARCH 2026
First register cycle

Incomplete subcontractor data ranked among the most-reported difficulties.

TODAY
It's right, or it isn't

Every unchecked day is a day you can't evidence. That's the job we take off you.

GDPR Art. 28(2) · EDPB Opinion 22/2024 · Regulation (EU) 2022/2554 (DORA) · reporting across the first submission window

We don't tell you whether you're compliant — we publish observations and dated records, and you decide what they mean. Every citation is named so your counsel can check us.

Have us do it →
who ends up owning this

Whoever signed the DPAs is the one who gets asked.

Three jobs, the same underlying problem: a list that has to be current, defensible, and produced on demand — usually by someone who has a hundred other things on.

in-house privacy

You signed the DPAs

A hundred vendors, one of you, and an objection window that starts running whether or not anyone noticed.

  • Your Article 28 annex, kept current
  • Windows read from your own contracts
  • Notices to your customers, in your name
grc & security

You answer the auditor

The question is never “do you track sub-processors” — it's “show me the record for the last twelve months.”

  • Dated evidence pack, exported
  • Decision log: accepted, objected, escalated
  • Hash-chained, verifiable after the fact
dpo firms

You carry it for clients

The same work multiplied by every client you advise, and billed as hours you would rather spend on judgement.

  • One workspace per client
  • Cross-client rollups in one view
  • White-labelled exports and a reseller kit
financial services
The DORA register needs the chain, not just the vendor

Subcontracting depth is the part firms most often report as hardest to assemble. Our discovery produces it as a by-product, dated and exportable, ahead of the annual submission window.

Talk about DORA →
what you end up with

A page you can point people at,
and never have to touch.

Published wherever you want it — your own legal page, your trust centre, or the register. Current to the day, with the dated history sitting behind every line.

  • Every entity, with its source

    Name, what it does, where it processes, and which of the six places we read it from.

  • A dated history, not a “last updated”

    Every addition, removal and relocation carries the date we saw it, going back to the day you joined.

  • Your customers told, in your name

    They subscribe to your page. When something changes and you approve it, the notice goes out from you.

  • Exports that fit where you need them

    Your DPA annex, your trust centre, your own site, or straight into an auditor's hands.

northwind.io/legal/sub-processors verified today

Northwind Ltd — sub-processors

21 entities · 5 countries · maintained by subprocessor.org

EntityPurposeCountryRead from
Amazon Web ServicesHosting and storageUnited StatesDPA §9
StripePayment processingUnited Stateslegal page
Twilio SendGridTransactional emailUnited StatesCSP header
IntercomCustomer messagingIrelandCSP header
SnowflakeAnalytics warehouseUnited Statesyour list
Showing 5 of 21 · history from 4 March 2026
▸ sent on your behalf
Northwind Ltd is adding a sub-processor.
Clumio, Inc. — backup and recovery, United States. Effective 16 September 2026.
to 184 subscribed customers · approved by you 17 Aug
after you are live

Your stack moves. Usually without anyone telling you.

A team swaps an email provider, someone turns on an AI feature, a workload moves region. We re-read everything we found during discovery — every day — and bring you only what genuinely changed.

step 01
We spot the difference

Daily re-check of every source. Presentation changes are discarded before anything is compared.

step 02
A reviewer confirms it

Real movement, or a page rebuild dressed up as one? A person decides before you are involved.

step 03
It waits for you

Sits in your queue with the evidence attached. Nothing is public and no customer has been told.

step 04
Published and announced

Your page updates with the date, and the notice goes to your subscribers in your name.

step 05
Recorded for the audit

The change, your decision and who made it land in the evidence pack automatically.

Waiting on you

northwind.io · nothing published while these sit here
3 to decide
17 Aug · 06:12 Clumio, Inc. appearedNew endpoint in your content-security-policy · backup and recovery, United States
11 Aug · 06:04 Intercom moved regionIreland to United States · seen in their own published list
04 Aug · 05:58 Mailgun no longer appearsRemoved from your DPA annex · confirm before we take it off your page
142checks run since you joined 6changes brought to you 0false alarms Everything above is held. We never publish, and never email your customers, before you say so.
for the people who have to wire it in

Everything we hold, available over HTTP.

One JSON API across the public register and your own account. The register is readable without a key, because a register nobody can query isn’t a register. Anything about your business needs one.

  • Versioned and datedEvery path is under /v1. Breaking changes get a new version and twelve months of overlap.
  • Conditional readsSend the ETag back and an unchanged record answers 304 with no body. Those 304s do not count against your rate limit.
  • The same hashes we publishEntity hash, page hash and ledger row come back on every record, so you can verify us rather than trust us.
  • Nothing hidden behind salesThe register endpoints need no key at all. Call them, see the exact shapes, and decide before you talk to anyone.
register lookup — no key200 OK · 61ms
curl https://subprocessor.org/v1/register/atlassian.com

{
  "company": "atlassian.com",
  "verified_at": "2026-09-24T06:03:11Z",
  "entity_hash": "427b2945ef",
  "version": 2,
  "source": "observed",          // read from their own page
  "reviewed": false,
  "shape": "table",
  "count": 29,
  "history_from": "2026-08-19",
  "entities": [
    { "name": "Amazon Web Services",
      "purpose": "Cloud hosting and storage",
      "country": "US",
      "first_seen": "2026-08-19" },
    …
  ],
  "changes_url": "/v1/register/atlassian.com/changes"
}
The registerpublic · no key required
GET/v1/register/companiesPage every business we track, filtered by domainOpen
GET/v1/register/{domain}One business: current list, entity count, countries, verification stampOpen
GET/v1/register/{domain}/changesDated change history: additions, removals, renamesOpen
GET/v1/register/{domain}/history?at=2026-09-01The list exactly as it stood on a past dateOpen
GET/v1/register/{domain}/feed.atomAtom feed of that one business, for your reader or a botOpen
GET/v1/entitiesThe sub-processor index: every named entity and how many name itOpen
GET/v1/entities/{slug}/named-byEvery business naming this entity, with country and purposeOpen
GET/v1/changesGlobal feed of list movements across the registerOpen
GET/v1/ledger/{row}Verify any record against the hash chain, with no accountOpen
Your businessrequires a key · Maintained plan
GET/v1/me/listYour current published list, exactly as your page renders it
GET/v1/me/list.csvThe same list as CSV, shaped for a DPA annex
GET/v1/me/pendingChanges waiting on your decision, with the evidence attached
POST/v1/me/pending/{id}/decisionDecide a queued change. A key can decide; it cannot publish
GET/v1/watchlistEvery vendor you watch, with last read and entity count
GET/v1/windowsOpen objection windows with days remaining and the clause they came from
Not built yetlisted so nobody builds against them
 writes to /v1/watchlist, evidence packs, discovery, AgencyDo these in your account for now. The docs keep the full list current.Soon
A feed for every business

Each business in the register has its own Atom feed. Point a reader, a Slack bot or a cron job at it and hear about a change without writing an integration.

/v1/register/stripe.com/feed.atom
Conditional reads

Poll as often as you like. Send back the ETag and an unchanged list answers 304 with no body, and 304s do not count against your rate limit.

If-None-Match: "427b2945ef"
A ledger you can check without us

Every publication, decision and correction is a row in a hash chain. Anyone can verify a row with no account, including your auditor.

GET /v1/ledger/{row}
Rate limits you can see

Limits come back on every response rather than being discovered by getting cut off: 60 requests a minute without a key, 600 with one.

X-RateLimit-Remaining: 587
Any list, on any date

Ask for a business as it stood on a past date and get the version that was live then, with the hash it was published under.

?at=2026-09-01
Your list, shaped for the annex

Pull your own published list as JSON for your trust centre, or as CSV laid out for a DPA annex, straight from the record.

GET /v1/me/list.csv
financial services
DORA register of information

Subcontracting-chain mapping and register exports, scoped to the annual submission cycle. Priced against the size of your ICT estate rather than a seat count.

Arrange a walkthrough →
before you hand it over

The questions we actually get asked.

Mostly by the person who will be held responsible if any of this is wrong.

A domain. That is genuinely it. If you already keep a vendor spreadsheet, a DPA or a procurement export, send those too and we will read them alongside everything we find ourselves.

Nothing about your business is published, and no customer of yours is contacted, until you have seen the list and approved it.

Possibly, and you decide what happens next. We classify what we find into what plausibly touches customer data inside your product versus what is website or marketing tooling, because those sit under different obligations.

Everything lands in your approval queue with the source attached. You can accept it, exclude it with a reason recorded, or ask the reviewer why they classified it that way.

The crawling is automated. The judgement is not. A named reviewer works through every discovery before it reaches you — merging the same company appearing under three names, deciding what belongs on a sub-processor list, and checking each source resolves.

You get their name on the record, and you can ask them a question directly from any item in your queue.

Yes, and most do. Embed it, pull it through the API, export it into your DPA annex or trust centre, or point your existing legal page at your register entry. It is your list either way.

We say so on the page rather than showing a stale copy, and we keep the last public capture on record with its date. You can also forward that vendor’s notice emails into your account, so the dated record stays complete even when the page is no longer readable.

Encrypted at rest, used only to extract the notification clause, and read by the reviewer assigned to your account. The extracted clause is shown to you for confirmation before it drives any countdown.

Delete the contract and the extracted clause goes with it. We do not need to keep the document to keep the window.

No, and we would be wary of anyone claiming otherwise. Article 28 puts that obligation on your vendor, and a page on a website does not discharge it. We watch what they publish so you can verify they told you — and catch the ones who quietly did not.

Something not answered here?Book fifteen minutes with a reviewer