Discovery queue open Typical turnaround: one working day The register Method Talk to a reviewer
subprocessor.org
Six sources. One reviewed list. Re-checked daily.See how the work flows →
Same engine, different job to be done.Compare the tiers →
We publish observations and dated records, never legal conclusions.Read the method →
Free to read. No account.Open the register →
who this is for

Same evidence. Different reason for needing it.

Four roles and five situations. The underlying work is identical — who is in your chain, where they process, what changed on which date — but what you are being asked for differs.

by role

In-house privacy

You signed the DPAs and you get asked about them.

Read more →
by role

GRC & security

You answer the auditor, and screenshots are not evidence.

Read more →
by role

DPO firms

You carry it for a book of clients rather than one company.

Read more →

01 Selling into the EU

what triggers it

A European customer's procurement team asks for your sub-processor list, and you realise you have never written one.

Article 28 expects a controller to know who is in the chain and to be told before it changes. In practice the first request lands mid-deal, from a customer who will not sign without it, and the spreadsheet you assemble under pressure becomes the thing you are held to for years.

Discovery gives you the list in a day, a reviewer checks it, and it publishes at your own address so the next buyer gets a URL rather than an email thread.

02 Financial services and DORA

The register of information wants the subcontracting chain beneath each ICT provider, not just the provider. That depth is the part firms consistently report as hardest to assemble, and it is precisely what a sub-processor list contains.

03 A hundred vendors and no way to watch them

the arithmetic

A hundred vendors checked quarterly is four hundred page reads a year, done by hand, by someone with a real job.

So it does not happen. It gets done once at onboarding, then at renewal, and the eighteen months in between are covered by hoping the vendor's notice email arrives and reaches a monitored inbox.

Watching reads every vendor's published page daily, once per vendor no matter how many of our customers depend on them, and tells you what moved. Where you have supplied the contract, the countdown is the one you actually agreed.

04 Your first DPA annex

The one nobody warns you about: whatever you write first becomes the baseline. Miss an entity now and adding it later reads like a change rather than a correction.

Discovery is free precisely so the first version is assembled from evidence rather than memory. A reviewer works through it, you approve it, and the dated history starts from a list that was right.

05 A privacy team outgrowing the spreadsheet

The spreadsheet worked when one person maintained it. It stops working when three people edit it, when the auditor asks what it said in March, and when nobody can say where a row came from.

What replaces it has to answer three questions the spreadsheet cannot: where did this entity come from, when did it appear, and who decided it belonged. All three are recorded here as a by-product of the work rather than as extra admin.

06 A multi-client practice

The same work multiplied by every client, billed as hours you cannot mark up. One workspace per client, one rollup across all of them, exports under your name, and a vendor nine clients share read once rather than nine times.

If a client takes it in-house, the workspace transfers with its full history. That makes you easier to hire, not harder to leave.