Envello
Trust

What belongs on a subprocessor list (most are stale)

Envello Team·2026-07-16·6 min read

A subprocessor list exists to answer one question for a DPO doing due diligence: who else touches this data besides the vendor I'm signing with? A list that's a year out of date, or vague about what each subprocessor actually does, doesn't answer that question, it just checks a box.

What a useful subprocessor list actually contains

  • The specific vendor name, not a category ("a cloud provider" tells a reviewer nothing)
  • What that vendor actually processes (infrastructure hosting vs. payment processing vs. analytics are very different risk profiles)
  • Where that vendor processes data, since this is what determines whether SCCs or another transfer mechanism apply

How this differs from a DPA

A DPA is the contract between you and Envello governing how your data is processed; the subprocessor list is a specific disclosure required within that relationship, naming who else Envello relies on to deliver the service (infrastructure hosting, the sending pipeline through AWS SES, payment processing through Stripe). The two documents are complementary: the DPA sets the terms, the subprocessor list is the concrete answer to "who does this actually involve."

Envello's approach

The current, full subprocessor list is available on request rather than published as a static page, specifically so it can be given directly and stay attached to a specific request rather than drifting out of sync with a page nobody remembers to update. Active customers get 30 days' notice by email before any subprocessor is added or replaced, and any subprocessor operating outside the EEA is bound by the EU Standard Contractual Clauses as an additional safeguard on top of its own GDPR compliance.

The 30-day notice is the part that matters most

A subprocessor list is a snapshot; what actually protects you over time is the notice period before it changes. 30 days is enough time to raise an objection, ask questions, or in the extreme case, plan a migration, before a new subprocessor starts touching your data. A vendor that reserves the right to add subprocessors silently, with no notice period, has effectively made the list decorative.

What happens if you actually object

Most DPAs, including Envello's, give the customer a right to object to a new subprocessor within the notice window. In practice this usually starts as a conversation, understanding why the change is happening and whether it materially affects your risk profile, rather than an automatic contract termination. For most infrastructure-level subprocessor changes (a hosting provider, a monitoring tool), the practical outcome is clarification; for something that meaningfully changes where personal data flows, it's a legitimate basis to reconsider the relationship.

How SCCs work mechanically, briefly

Standard Contractual Clauses are a pre-approved contract template from the European Commission that two parties sign to legitimize a transfer of personal data outside the EEA, without needing case-by-case regulatory approval. If a subprocessor operates outside the EEA, the SCCs are the mechanism, not a substitute, that makes that transfer legally sound alongside the subprocessor's own GDPR compliance. It's worth asking any vendor specifically whether SCCs are actually signed and current, not just referenced as a general policy.

Free tool

Check your own GDPR/DPA gaps before you switch

8 questions covering data residency, retention, and subprocessor documentation, the same things a security questionnaire asks.

Run the free checklist →
Envello

EU-hosted transactional email, done right by default.