Ask most startups for a list of their sub-processors and you'll get a vendor list instead. Those aren't the same thing, and the gap between them is where a lot of GDPR exposure quietly sits.
Three words, three different meanings
- Vendor is just business language. Anyone you pay for anything—your accountant, your office cleaning company, AWS.
- Subcontractor is a contract law term. Someone your vendor uses to help deliver their service to you.
- Sub-processor is a GDPR term, and it's narrower than both. It's a subcontractor who actually processes personal data on your behalf. Your vendor's cleaning company is a subcontractor. Your vendor's cleaning company is not a sub-processor, because it never touches your data. The email tool your vendor uses to send you invoices might be a sub-processor, if personal data flows through it.
The distinction matters because GDPR only cares about the third category, and figuring out who's in it requires knowing what a vendor actually does with data—not just that you pay them.
It was never anyone's job to check
Here's where it usually breaks down. Vendor intake at most startups runs through procurement or finance. Privacy isn't in the room. So when a new vendor gets added, someone approves a contract and a price, but nobody asks: does this thing touch personal data, and if so, whose?
Six months later, you have a vendor list with twenty names on it, and genuinely nobody in the company could tell you which of them are sub-processors under GDPR. Not because anyone was careless—because the question was never anyone's job to ask.
Why this actually matters
Regulatory enforcement is obviously a risk. But the more immediate problem tends to show up elsewhere first: due diligence. If you're going for an ISO certification, an auditor will ask for your sub-processor list, and "we don't really have one" is a bad answer in that room.
Same thing happens when you're the vendor: if an enterprise customer or investor asks for your sub-processor list during their due diligence, and you hand them three names when the realistic number is closer to fifteen, that doesn't just look incomplete—it makes you look like you don't actually understand your own data flows. That's a credibility problem, and credibility problems slow down or kill deals.
The DUE test
Run every vendor on your list through three questions—call it the DUE test, since this is exactly what shows up in due diligence:
- D - Data. Do they receive personal data from us, or just invoices and contracts?
- U - Uses. Do they use anyone else to deliver their service to us?
- E - Exposure. If that "anyone else" had a breach, would our customers' data be exposed?
Yes to D and U means you've found a sub-processor, whether it's on your list or not. Run the DUE test across a real vendor list and it's rarely a clean result—most companies find their sub-processor count is higher, and their paperwork thinner, than they assumed going in.
If you want help running this properly across your vendor list, that's something we can do with you.
- Vendor, subcontractor, and sub-processor are three different things, and only the last, a subcontractor that actually processes personal data on your behalf, is what GDPR cares about.
- Most startups' sub-processor lists are really just vendor lists, because vendor intake usually runs through procurement or finance, and nobody was ever specifically tasked with asking whether a vendor touches personal data.
- The immediate risk usually isn't regulatory enforcement but due diligence: an ISO auditor, enterprise customer, or investor asking for a sub-processor list and getting an incomplete one damages credibility and can slow or kill deals.
- The article proposes a 'DUE test' (Data, Uses, Exposure) to check each vendor: do they receive personal data, do they use other parties to deliver their service, and would a breach at that other party expose your customers' data.
- Running the DUE test across a real vendor list typically reveals more sub-processors than a company assumed, and thinner supporting paperwork than expected.
| The core distinction | Vendor is a business term, subcontractor is a contract-law term, and sub-processor is the narrower GDPR term for a subcontractor that actually processes personal data on your behalf. |
|---|---|
| Why lists are wrong | Vendor intake typically runs through procurement or finance, not privacy, so nobody specifically checks whether a new vendor touches personal data. |
| The real risk | It's less about regulatory enforcement and more about due diligence; an incomplete sub-processor list looks bad to auditors, enterprise customers, and investors and can slow deals. |
| The DUE test | Ask of every vendor: Data (do they receive personal data from you?), Uses (do they use another party to deliver their service?), Exposure (would a breach there expose your customers' data?). |
| Practical outcome | A 'yes' to Data and Uses means you've found a sub-processor, whether or not it was already on your list. |
| What typically happens | Running the DUE test across a real vendor list usually surfaces more sub-processors, and less documentation, than the company assumed. |
What's the difference between a vendor, a subcontractor, and a sub-processor?
Vendor is just anyone you pay for anything. Subcontractor is anyone your vendor uses to help deliver its service. Sub-processor is the narrower GDPR term for a subcontractor that actually processes personal data on your behalf.
Why do so many startups have inaccurate sub-processor lists?
Because vendor intake usually runs through procurement or finance rather than privacy, so no one is specifically asked to check whether a new vendor touches personal data.
What is the DUE test?
A three-question check for each vendor: Data (do they receive personal data from you), Uses (do they use another party to deliver their service), and Exposure (would a breach there expose your customers' data).
Why does an inaccurate sub-processor list matter if regulators haven't come knocking?
Because it surfaces first in due diligence. Auditors, enterprise customers, or investors who ask for the list and get an incomplete one see it as a credibility problem, which can slow or kill deals.
What typically happens when a company actually runs the DUE test on its vendor list?
It usually finds more sub-processors than expected, and less supporting documentation than it assumed it had.
- A GDPR-Compliant Vendor Doesn't Automatically Mean Your Data Transfer Is LegalYour vendor says they're GDPR compliant. That doesn't mean your data transfer to the US is legal—those are two separate question
- Global DPA vs. US DPA vs. EU DPA: What Changes When Your Vendor Is International?GDPR’s Article 28 is a fixed checklist. US state law is a patchwork. Here's where a "Global DPA" often fails one side or the other.
