Subprocessor change notification email template
4 May 2026
A good subprocessor change notification does one job well: it tells the controller exactly what is changing, when it takes effect, and how to object — without burying any of it. Use the template below as a starting point and adapt the wording to your own DPA terms and brand voice.
Subject: Notice of a change to our subprocessor list — action may be required by [objection deadline]
Hello [Contact name],
We are writing to notify you of an upcoming change to the subprocessors we use to provide [Product / Service name], in line with Article 28(2) of the GDPR and the terms of our Data Processing Agreement with [Customer organisation].
What is changing: We are [adding / replacing] [Subprocessor name] ([website]), which will process [data categories — e.g. customer account and usage data] for the purpose of [processing purpose — e.g. cloud hosting / email delivery / analytics]. The data will be processed in [location / region], under [transfer mechanism, if outside the EEA — e.g. EU Standard Contractual Clauses].
When it takes effect: This change is scheduled to take effect on [effective date].
Your right to object: If you have reasonable grounds to object to this change, please reply to this email by [objection deadline — the effective date minus your contractual notice period]. We will work with you to address your concerns before the change takes effect. If we do not hear from you by that date, the change will proceed as described.
Your current subprocessor list: You can view our complete, up-to-date subprocessor list at any time at [link to your trust page / subprocessor list].
If you have any questions, just reply to this email and it will reach our team directly.
Kind regards, [Sender name], [Company name]
A few notes on using it. Fill every bracket — vague notices ('we may use additional vendors') do not satisfy Article 28(2), which requires you to inform controllers of the specific addition or replacement. Set the objection deadline from each customer's own contractual notice period, not a one-size-fits-all date; notice periods commonly vary between 10, 14, and 30 days. Send to the named privacy or DPO contact in the DPA rather than a general account address, and record the send — recipient, timestamp, and delivery status — so you can later evidence that notice was given.
Finally, only send each controller the changes that actually affect them. A blanket 'notify everyone' send creates noise for customers whose scope is unchanged and makes it harder to prove that the right people were told about the right change.
Related resources
Stop filling in brackets by hand
subprocessor.io fills the change details, effective date, and each customer's objection deadline automatically — and records every send as evidence.
See automated notifications