Privacy obligations travel down the processing chain. Your customer — the controller — signs a DPA with you; you in turn engage the infrastructure and tooling that actually touches their users’ data: hosting, email delivery, error monitoring, the support desk where tickets carry personal details. Each of those is your subprocessor, and the protections you promised upstream have to flow down to them by contract. Contractually, their failure is your failure.
Because controllers must know who touches their data, processors publish a subprocessor list — typically a page on the website or trust center naming each vendor, its function, and where it processes — and commit to notifying customers before adding or replacing one, with a window to object. Keeping that list truthful is an operations task: it drifts every time an engineer adopts a new tool, which is how companies end up disclosing last year’s stack.
A subprocessor list is also an implicit claim that you assessed everyone on it. Customers increasingly test that claim in security reviews, asking how you evaluate a vendor’s security before data flows and on what cadence you re-check. A working vendor security review process — tiered by data access, evidenced, repeatable — is what makes the answer credible.