Home / Blog / Your sub-processor list

Your Sub-Processor List: The Consent Page Regulators Ask For and Nobody Builds

The page that does not exist

Ask a privacy regulator what they want to see on a company's website and the sub-processor list comes up fast: a public list of the third parties that process personal data on your behalf. Ask most companies where theirs is and you get a blank stare. The cookie policy exists. The privacy policy exists. The sub-processor list, the page that names the actual companies receiving visitor data, usually does not.

This gap matters more than it used to. Enforcement attention has shifted from whether you have a banner to whether your disclosures match reality. A banner that says data goes to named categories, while a dozen unnamed vendors receive it, is a disclosure problem. The sub-processor list is how you close it.

What the list needs to include

Every entry needs four things: the vendor's name, what they do with the data, what data they receive, and where they process it. Name the company, not just the product: the legal entity matters for transfer assessments. Describe the purpose in plain terms: analytics, payment processing, email delivery, fraud prevention. Specify the data categories: identifiers, behavioral data, payment details. And note the processing locations, because cross-border transfers trigger their own obligations.

Group by function so the list is readable: infrastructure, analytics, marketing, payments, support. A list of forty vendors in alphabetical order is technically complete and practically useless. The point is transparency a human can follow, not a data dump.

Include the vendors your visitors never see. The tag manager, the consent platform itself, the CDN, the error-tracking service: these process data too, and they are the entries most lists miss. If a vendor touches personal data, it belongs on the list regardless of whether it has a visible brand.

Keeping it current

The reason nobody builds this page is maintenance. Vendors change constantly: marketing adds a pixel, engineering swaps an analytics tool, support adopts a new chat widget. A list that was accurate in January is fiction by June. The fix is process, not effort.

Tie the list to your vendor onboarding. Every new tool that touches personal data gets a sub-processor entry as part of procurement, before it goes live. Review quarterly against your actual tag inventory and data map: the tags firing on your site are the ground truth, and any tag without a list entry is a finding. Assign one owner, because a list owned by everyone is maintained by no one.

Publish the update cadence on the page itself. A list dated last quarter with a note that it is reviewed quarterly builds more trust than an undated list of unknown age. Regulators notice the difference, and so do the enterprise buyers who check this page during procurement.

Why it is worth building

The sub-processor list does quiet work beyond compliance. It forces vendor hygiene: you cannot publish the list without knowing your vendors, and knowing your vendors is half of privacy governance. It speeds enterprise sales, where security questionnaires ask for exactly this. And it makes your consent story coherent: the banner asks for permission, the cookie policy explains the categories, and the sub-processor list names the names. Build all three and the program finally adds up.

Get a free consent audit of your website

Free consent audit