How to monitor your vendors' subprocessor lists (before the objection window closes)
Vendors change subprocessor lists quietly, and their notification mechanisms are opt-in at best. A practical guide to watching subprocessor pages, DPAs, and trust centers — with GDPR Article 28 mechanics explained.
Somewhere in your vendor stack, a subprocessor list changed this month. A new analytics provider was added, a hosting region quietly expanded outside the EU, a notice period in a DPA shrank from 30 days to 14. If you're responsible for GDPR compliance, vendor risk, or a SOC 2 program, you were supposed to know — and there's a decent chance nobody told you.
This guide covers why that happens, what the law actually gives you, and how to set up monitoring that catches changes while your objection window is still open.
Why you're supposed to know
Under GDPR Article 28(2), a processor can't engage another processor without your authorization. In practice nearly every SaaS DPA uses general written authorization: you pre-approve the current subprocessor list, and in exchange the vendor commits to inform you of intended additions or replacements and give you the opportunity to object.
That objection right is the whole game, and it's time-boxed. Typical DPA language gives you 14 to 30 days from notification to object; stay silent and you've consented. Miss the window and your remaining option is usually "terminate the service," which is no option at all mid-contract.
The same page matters beyond GDPR: SOC 2 vendor-management controls expect you to track material changes at subservice organizations, DORA pushes financial firms toward continuous third-party monitoring, and every security questionnaire you fill out asks whether you know where your data flows.
Why the vendor's notification mechanism fails
Vendors technically comply with the "inform" duty in ways that are easy to miss:
- The bell icon. Many trust pages offer a subscribe button… that you have to find, click, and confirm — per vendor. Nobody has done this for all 40 vendors in their stack.
- The email you didn't get. Notifications often go to the account owner who signed the contract — a founder, a procurement inbox, someone who left — not to the privacy or security team.
- The silent edit. Some vendors update the page and consider the page itself the notice. The DPA says "we will inform you via our website." Legally arguable; practically invisible.
- The changelog nobody reads. A "last updated" date changes at the bottom of a legal page. That's it. That's the notification.
The result: the customer side has to self-serve. The subprocessor page is public; the burden of watching it is yours.
What to actually monitor
For each critical vendor, there are up to three URLs worth watching:
- The subprocessor list itself — usually
/legal/subprocessors,/subprocessors, or a section of the trust center. This is the primary target. - The DPA page — watch for changes to the notice mechanics: notice periods, objection windows, how they define "inform."
- The trust center / security page — hosting regions, certifications, and infrastructure claims often change here first.
Prioritize vendors by data sensitivity, not by contract size. The tiny transcription tool processing customer call audio matters more than the big CRM whose subprocessor list has been stable for five years.
Setting up the monitor
Subprocessor pages are ideal monitoring targets because they're quiet: no A/B tests, no rotating banners. When they change, someone meant it. That shapes the setup:
For the subprocessor list: start with exact diff. On a quiet legal page, every text change is signal, and a byte-for-byte diff catches a single added vendor name with zero AI involvement. The alert shows exactly which lines changed.
For conditional questions: use a semantic prompt. Sometimes any change isn't the question — a specific change is:
Watch this subprocessor list and alert me if any subprocessor is added, removed, or if any processing location moves outside the EU/EEA.
Watch this DPA and tell me if the subprocessor notice period or objection window changes.
A diff can't answer "did a location leave the EU?" — a model reading the page can, and with modsignal the alert comes back as one sentence with the before, the after, and a confidence score:
Vendor added Anthropic (US) as a subprocessor for AI-assisted support features. New since July 18.
That sentence, with its evidence, is forwardable directly to your DPO or into the vendor-risk ticket — no re-reading the page to confirm.
Check daily. Subprocessor lists don't change hourly, and your objection window is measured in weeks. Daily checks — which modsignal's free tier includes — leave you the full window to act.
When the alert fires
A change alert starts a clock, so have the next steps ready:
- Classify. New subprocessor, removed one, changed location, or changed DPA terms? Removals are usually good news; additions and location changes need review.
- Assess. What data category does the new subprocessor touch? What's its location and transfer mechanism (SCCs, adequacy)? Does it change your own records of processing — or your own subprocessor list, if you're a processor too?
- Object or accept — on the record. If it's a problem, object in writing within the window, citing the DPA clause. If it's fine, note the review in your vendor file; auditors love a documented non-event.
- Cascade. If you're a processor yourself, your customers may now need their Article 28 notice from you. Your modsignal alert is upstream of your own notification duty.
The stack-wide version
One vendor is a monitor. A compliance program is a list: every critical vendor's subprocessor page, each with the same prompt, each with its own alert history — which becomes your evidence that monitoring happened, reviewable at audit time.
modsignal's subprocessor watch pack ships with these prompts ready to edit. The free tier covers your three most sensitive vendors at daily checks; the Pro plan covers a 25-vendor stack for $19/month. Either way, the setup is the same sentence, repeated: tell me when this changes — and prove it.