Subprocessor
A vendor engaged to process personal data on another company's behalf, under a data processing agreement — distinct from a vendor a company simply pays for software or infrastructure.
The term was formalized by Article 28 of the EU's GDPR and has since become standard industry vocabulary well beyond companies actually subject to that regulation. Not every paid vendor qualifies — a company that licenses software without ever touching another business's customer data isn't a subprocessor just because an invoice exists.
An operations lead asks a phone-ordering vendor who processes customer data on their behalf. “Handled securely using industry-leading cloud infrastructure” sounds reassuring and names nothing. A real answer looks different: a specific list, naming each vendor, what it's engaged to do, and when it was added.
A common mistake assumes a short or empty subprocessor list means a company is hiding something. It commonly means review just hasn't finished yet — an honest “nothing has cleared review” is a more trustworthy statement than a list padded to look complete.
The subprocessor list is genuinely empty right now — not an oversight, the accurate current state, since no vendor has cleared the review one has to pass before being added, covered on Subprocessors.
BACK TO THE FULL GLOSSARY · OR THE WORKED GUIDES
Open the line.
Tell us about your restaurant. We load your menu, you place a call, and you hear it answered yourself.