Discovery queue open Typical turnaround: one working day The register Method Talk to a reviewer
subprocessor.org
Six sources. One reviewed list. Re-checked daily.See how the work flows →
Same engine, different job to be done.Compare the tiers →
We publish observations and dated records, never legal conclusions.Read the method →
Free to read. No account.Open the register →

The register › If you are listed

Found your company here?

Then either you published this yourself, or someone did the work of assembling it from what you publish. Either way, this page is about handing you control of it.

01 Claim your page

what claiming does

It puts the page under your control: you approve every future change, and nothing is published without you.

Verify the domain, and the page becomes yours. From then on discovery runs against your stack, a reviewer checks it, and you approve each version before it appears.

Claiming does not delete the history that already exists — that would defeat the purpose of a dated record — but from the moment you claim it, you decide what is added.

02 Suggest a correction

If something here is wrong, tell us and we will fix it. Two commitments about how:

  • Every correction is logged. We record that you told us, what you said, and what we changed — a register that silently rewrites itself is worth nothing.
  • We record your position even where we disagree. If we think the evidence supports what is published, we will say so and note your objection alongside it rather than simply refusing.

03 Keeping a list worth reading

from reading a lot of these

Most published sub-processor lists fail on the same four things, and none of them are hard.

  1. Publish it as a table. Roughly seven in ten do, and those are the ones anyone can actually parse. Prose buried in a privacy policy is technically compliant and practically useless.
  2. State the country. Without it a reader cannot answer a transfer question, which is often the reason they came.
  3. Date the changes, not the page. A "last updated" stamp says nothing about what changed. A dated entry per addition and removal answers the question people are actually asking.
  4. Email the notice. Updating a page is not informing anyone. Article 28 puts the duty on you to tell your customers, and a page they have to remember to check does not discharge it.

None of this requires our product. If you do these four things on your own site, you are ahead of most of the register.

04 Asking us to remove it

You can ask, and we will listen. What we will not do is pretend a page you publish publicly is private, or delete a dated record because it is inconvenient — that would make every other entry untrustworthy.

What we will do: correct anything inaccurate, mark a page as no longer maintained rather than letting it go stale, remove anything that was never public, and record that you asked.

If a page contains something genuinely confidential that we read in error, tell us and it comes down while we look at it. That is a different question from disliking the record.