We'll take it
from here.
Send us your domain and stop maintaining a sub-processor list by hand. We go through your legal pages, your DNS and mail records, your response headers, your consent tooling and any spreadsheet you already keep — then a named reviewer confirms every line before it goes anywhere near your customers.
Rather speak to a person first? Book fifteen minutes with a reviewer
Six places we look. One list. Checked again tomorrow.
Nothing here is a guess. Each source is read on its own, everything converges into one candidate pool, a reviewer resolves the overlaps, and then the loop repeats daily for as long as you're with us.
Six independent sources, read separately, so one out-of-date page can't hide a vendor.
The same company turns up under three names. A reviewer decides which one is real.
Nothing reaches the register or your customers until you have seen it and said yes.
The loop runs every day, and every movement gets a date recorded against it.
The obligation is old. The expectation isn't.
Article 28 has required notice of sub-processor changes since 2018. What changed recently is how current your list is expected to be, who now has to log the chain beneath it, and how often someone asks to see the record.
Notice of sub-processor changes becomes mandatory. The law fixes no deadline — your contract does.
Lists are expected to stay current, with detail and time enough to actually object.
Financial entities must log the subcontracting chain, not only the vendor above it.
Incomplete subcontractor data ranked among the most-reported difficulties.
Every unchecked day is a day you can't evidence. That's the job we take off you.
GDPR Art. 28(2) · EDPB Opinion 22/2024 · Regulation (EU) 2022/2554 (DORA) · reporting across the first submission window
Whoever signed the DPAs is the one who gets asked.
Three jobs, the same underlying problem: a list that has to be current, defensible, and produced on demand — usually by someone who has a hundred other things on.
You signed the DPAs
A hundred vendors, one of you, and an objection window that starts running whether or not anyone noticed.
- Your Article 28 annex, kept current
- Windows read from your own contracts
- Notices to your customers, in your name
You answer the auditor
The question is never “do you track sub-processors” — it's “show me the record for the last twelve months.”
- Dated evidence pack, exported
- Decision log: accepted, objected, escalated
- Hash-chained, verifiable after the fact
You carry it for clients
The same work multiplied by every client you advise, and billed as hours you would rather spend on judgement.
- One workspace per client
- Cross-client rollups in one view
- White-labelled exports and a reseller kit
Subcontracting depth is the part firms most often report as hardest to assemble. Our discovery produces it as a by-product, dated and exportable, ahead of the annual submission window.
A page you can point people at,
and never have to touch.
Published wherever you want it — your own legal page, your trust centre, or the register. Current to the day, with the dated history sitting behind every line.
- Every entity, with its source
Name, what it does, where it processes, and which of the six places we read it from.
- A dated history, not a “last updated”
Every addition, removal and relocation carries the date we saw it, going back to the day you joined.
- Your customers told, in your name
They subscribe to your page. When something changes and you approve it, the notice goes out from you.
- Exports that fit where you need them
Your DPA annex, your trust centre, your own site, or straight into an auditor's hands.
Northwind Ltd — sub-processors
21 entities · 5 countries · maintained by subprocessor.org
| Entity | Purpose | Country | Read from |
|---|---|---|---|
| Amazon Web Services | Hosting and storage | United States | DPA §9 |
| Stripe | Payment processing | United States | legal page |
| Twilio SendGrid | Transactional email | United States | CSP header |
| Intercom | Customer messaging | Ireland | CSP header |
| Snowflake | Analytics warehouse | United States | your list |
Clumio, Inc. — backup and recovery, United States. Effective 16 September 2026.
Your stack moves. Usually without anyone telling you.
A team swaps an email provider, someone turns on an AI feature, a workload moves region. We re-read everything we found during discovery — every day — and bring you only what genuinely changed.
Daily re-check of every source. Presentation changes are discarded before anything is compared.
Real movement, or a page rebuild dressed up as one? A person decides before you are involved.
Sits in your queue with the evidence attached. Nothing is public and no customer has been told.
Your page updates with the date, and the notice goes to your subscribers in your name.
The change, your decision and who made it land in the evidence pack automatically.
Waiting on you
Everything we hold, available over HTTP.
One JSON API across the public register and your own account. The register is readable without a key, because a register nobody can query isn’t a register. Anything about your business needs one.
- Versioned and datedEvery path is under
/v1. Breaking changes get a new version and twelve months of overlap. - Conditional readsSend the ETag back and an unchanged record answers 304 with no body. Those 304s do not count against your rate limit.
- The same hashes we publishEntity hash, page hash and ledger row come back on every record, so you can verify us rather than trust us.
- Nothing hidden behind salesThe register endpoints need no key at all. Call them, see the exact shapes, and decide before you talk to anyone.
curl https://subprocessor.org/v1/register/atlassian.com { "company": "atlassian.com", "verified_at": "2026-09-24T06:03:11Z", "entity_hash": "427b2945ef", "version": 2, "source": "observed", // read from their own page "reviewed": false, "shape": "table", "count": 29, "history_from": "2026-08-19", "entities": [ { "name": "Amazon Web Services", "purpose": "Cloud hosting and storage", "country": "US", "first_seen": "2026-08-19" }, … ], "changes_url": "/v1/register/atlassian.com/changes" }
/v1/register/companiesPage every business we track, filtered by domainOpen/v1/register/{domain}One business: current list, entity count, countries, verification stampOpen/v1/register/{domain}/changesDated change history: additions, removals, renamesOpen/v1/register/{domain}/history?at=2026-09-01The list exactly as it stood on a past dateOpen/v1/register/{domain}/feed.atomAtom feed of that one business, for your reader or a botOpen/v1/entitiesThe sub-processor index: every named entity and how many name itOpen/v1/entities/{slug}/named-byEvery business naming this entity, with country and purposeOpen/v1/changesGlobal feed of list movements across the registerOpen/v1/ledger/{row}Verify any record against the hash chain, with no accountOpen/v1/me/listYour current published list, exactly as your page renders itMaintained/v1/me/list.csvThe same list as CSV, shaped for a DPA annexMaintained/v1/me/pendingChanges waiting on your decision, with the evidence attachedMaintained/v1/me/pending/{id}/decisionDecide a queued change. A key can decide; it cannot publishMaintained/v1/watchlistEvery vendor you watch, with last read and entity countMaintained/v1/windowsOpen objection windows with days remaining and the clause they came fromMaintainedwrites to /v1/watchlist, evidence packs, discovery, AgencyDo these in your account for now. The docs keep the full list current.SoonEach business in the register has its own Atom feed. Point a reader, a Slack bot or a cron job at it and hear about a change without writing an integration.
/v1/register/stripe.com/feed.atomPoll as often as you like. Send back the ETag and an unchanged list answers 304 with no body, and 304s do not count against your rate limit.
If-None-Match: "427b2945ef"Every publication, decision and correction is a row in a hash chain. Anyone can verify a row with no account, including your auditor.
GET /v1/ledger/{row}Limits come back on every response rather than being discovered by getting cut off: 60 requests a minute without a key, 600 with one.
X-RateLimit-Remaining: 587Ask for a business as it stood on a past date and get the version that was live then, with the hash it was published under.
?at=2026-09-01Pull your own published list as JSON for your trust centre, or as CSV laid out for a DPA annex, straight from the record.
GET /v1/me/list.csvSubcontracting-chain mapping and register exports, scoped to the annual submission cycle. Priced against the size of your ICT estate rather than a seat count.
The questions we actually get asked.
Mostly by the person who will be held responsible if any of this is wrong.
A domain. That is genuinely it. If you already keep a vendor spreadsheet, a DPA or a procurement export, send those too and we will read them alongside everything we find ourselves.
Nothing about your business is published, and no customer of yours is contacted, until you have seen the list and approved it.
Possibly, and you decide what happens next. We classify what we find into what plausibly touches customer data inside your product versus what is website or marketing tooling, because those sit under different obligations.
Everything lands in your approval queue with the source attached. You can accept it, exclude it with a reason recorded, or ask the reviewer why they classified it that way.
The crawling is automated. The judgement is not. A named reviewer works through every discovery before it reaches you — merging the same company appearing under three names, deciding what belongs on a sub-processor list, and checking each source resolves.
You get their name on the record, and you can ask them a question directly from any item in your queue.
Yes, and most do. Embed it, pull it through the API, export it into your DPA annex or trust centre, or point your existing legal page at your register entry. It is your list either way.
We say so on the page rather than showing a stale copy, and we keep the last public capture on record with its date. You can also forward that vendor’s notice emails into your account, so the dated record stays complete even when the page is no longer readable.
Encrypted at rest, used only to extract the notification clause, and read by the reviewer assigned to your account. The extracted clause is shown to you for confirmation before it drives any countdown.
Delete the contract and the extracted clause goes with it. We do not need to keep the document to keep the window.
No, and we would be wary of anyone claiming otherwise. Article 28 puts that obligation on your vendor, and a page on a website does not discharge it. We watch what they publish so you can verify they told you — and catch the ones who quietly did not.