Every subprocessor
behind any company
Search a domain to walk its declared chain – the vendors it uses, the vendors they use, and the countries your data ends up in. Built from public documents.
Your vendors have vendors.
And those vendors
have more vendors
Venpo maps the entire declared chain, so you can see every organization involved in processing your data.
Processor, subprocessor, third party – what each word means
- ProcessorGDPR Art. 4(8)
- A company that handles personal data on your instructions. The vendor you signed the DPA with. (You are the controller.)
- SubprocessorGDPR Art. 28(2)
- A processor your processor engages for the same data. It needs your written authorisation – usually granted in advance through the DPA, with a right to object to additions.
- Third partyGDPR Art. 4(10)
- Any external organisation. Broader than subprocessor: it includes recipients that receive data for their own purposes, which a subprocessor by definition does not.
- Sub-contractorCommercial term
- Not a GDPR one. A sub-contractor is only a subprocessor if it touches personal data. A cleaning company is a sub-contractor; a hosted email provider is a subprocessor.
A subprocessor is your vendor's vendor
You hand data to one company. That company can't run everything itself, so it hands parts of the job to others — and those hand it on again. Every hop is a company holding your data under a contract you never signed.
Every edge has a document behind it
The graph is built from what vendors publish – subprocessor pages, DPAs, terms. Nothing is inferred from traffic, cookies, or page scripts. If an edge is in the chain, there is a public document that declares it, and you can open it.
Read
Venpo monitors each vendor's subprocessor list, DPA and terms. Every fetch is stored as a version, so the page as it existed on any given date is retained.
SendGridnotion.soTwilio SendGridfigma.comsendgrid.comramp.com
Resolve
“SendGrid”, “Twilio SendGrid” and “sendgrid.com” are one company. Every raw name on every list is resolved to a single canonical entity – that is what lets chains connect across levels instead of dead-ending on a spelling.
read Jul 24, 2026
subprocessorsJUL 28 vs JUN 04Version
Every read is dated. Click any node in the graph and you see the source document and the date it was read. When a list changes, the previous version is kept and the diff is recorded.
Where the graph fits in your work
Before you sign
A vendor review that stops at the vendor approves one company. The data goes to the whole set. Walk the declared chain before the signature, not after the incident.
When the list moves
Most DPAs promise notice before a new subprocessor is added and give you a window to object (Art. 28(2)). The window only works if you see the change when it lands on the page – Venpo diffs every list the moment it moves.
Transfer impact assessments
A TIA needs the set of countries the data can reach. The chain gives you that set per vendor, with the document each country claim came from.
Supplier change management
ISO 27001 A.5.22 asks for evidence that supplier changes are monitored and reviewed. Versioned documents and recorded diffs are that evidence, already dated and sourced.
Mix everything you already have.
Get A.5.22 ready
Drop in the contracts you hold, let Venpo monitor the vendors you depend on, and connect the tools where the rest already lives. One memory, three inputs.
Your MSAs, DPAs and policies. Dropped in once, parsed into clauses and linked to the controls they satisfy.
Venpo watches each vendor's public terms, DPA and subprocessor list, and diffs them the moment they change.
Pull from where agreements already live — mail, drive, ticketing and your identity provider — so nothing sits outside the graph.
A.5.19 · A.5.20 · A.5.21 · A.5.23 coming next.
FAQs about subprocessors
Is a public subprocessor list legally required?
GDPR does not mandate a public page. It requires processors to inform controllers of intended subprocessor changes and give them the chance to object (Art. 28(2)). A published list plus a notification mechanism is how most SaaS vendors implement that duty – which is why the list, where it exists, is the public record.
Do subprocessors need my consent?
Written authorisation, yes – general or specific (Art. 28(2)). In practice almost all SaaS DPAs use general authorisation: you approve the current list when you sign and retain a right to object to additions.
What happens if I object to a new subprocessor?
It depends on your DPA. Common terms let the vendor propose a workaround, and if none exists, let you terminate the affected service. The objection window is typically short – which is why seeing the change on time matters more than the objection right itself.
Can I see a vendor's subprocessors without being a customer?
Usually yes – that is what this graph is built from. Where a vendor publishes its list, DPA or terms, the chain is public. Search any domain above to check.
What if a vendor doesn't publish a subprocessor list?
Then the graph shows what does exist for that vendor – its DPA, terms, and any parties declared in them. The absence of a list is itself an input to your vendor review: it means the register your DPA relies on is not public.
How deep does the chain go?
Until the documents stop. Venpo walks each declared party's own declarations until a party publishes nothing further. In the corpus, chains typically end at five levels.
Trace your own chain
Every vendor document read, versioned, diffed and explained – so the reference is there when you need it. Free to start, no credit card required.