Founding offer — 50% off for life, with concierge migration. We set everything up for you.
subprocessor.io
← All resources
Template · 3 min read

Free GDPR subprocessor list template

26 May 2026

Every B2B company that processes personal data on behalf of its customers needs an accurate, current list of its subprocessors. Under GDPR Article 28 you must be able to show controllers who is in your processing chain, what they do, and when the list last changed. This template gives you the columns a subprocessor list needs to be audit-ready — copy them into a spreadsheet, or use them as the schema for a live list.

The columns your list needs. At a minimum, capture the following for every subprocessor:

Subprocessor name — the legal or commonly-used name of the vendor (for example, 'Amazon Web Services, Inc.'). Link to the vendor's site, or to its own subprocessor page, where you can.

Processing purpose — what the vendor does for you, in plain language: cloud hosting, email delivery, error monitoring, payment processing, customer support, analytics. This is the single most useful column for a reviewer trying to understand your chain.

Categories of personal data — the types of personal data the vendor can access: account data, contact details, usage and log data, content and uploads, payment data, support conversations. Be specific enough to be meaningful, but not so granular that the list becomes unmaintainable.

Location / region — where the vendor processes the data (country or region, and the relevant data-centre region if it matters). Reviewers use this to assess international-transfer exposure at a glance.

Transfer mechanism — if data leaves the EEA, the safeguard that covers the transfer: EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, an adequacy decision, or a Data Privacy Framework certification. Leave blank for purely in-region vendors.

Date added (and date removed) — when the subprocessor entered your chain, and when it left if applicable. This is what turns a snapshot into a record: it lets you, and an auditor, reconstruct what your list looked like at any point in time.

Optional but useful columns. Depending on your needs you may also track: the sub-processing relationship (does this vendor use its own subprocessors?), a link to the vendor's DPA, the internal owner responsible for the relationship, and whether the vendor is currently active or retired.

How to use it. Fill it in for every vendor with regular access to personal data — not just the headline ones. Publish it where customers can find it (a dedicated subprocessor page is better than burying it in a privacy policy), and notify affected customers before you add or replace an entry, as Article 28(2) requires. When manual updates start to slip — when 'who updates this?' stops having a clear answer — that is the signal to move from a static spreadsheet to a live list that maintains its own history and handles notifications for you.

Related resources

Turn the template into a live list

subprocessor.io keeps these columns for you — with per-customer scoping, a visible change history, and notifications handled when an entry changes.

See the subprocessor list