Sub-processor list

Your sub-processor list, published, and customers told when it changes.

The first thing an enterprise buyer's lawyer asks a small vendor for is the current list of sub-processors and a way to hear about changes. Rowpa generates the page from the vendor register you already keep, gives it a stable URL you can quote in a DPA, and emails subscribers when a sub-processor is added or removed.

Publish yours freeSee a live example

Build and preview it free. Included from Starter with a published Trust Center.

What Article 28(2) actually asks for

A processor must inform the controller of any intended change to the sub-processors it uses, so the controller can object. Every SaaS company meets that with a web page and a subscription form, and every DPA says the current list is at this address. For a small firm the page is the problem: someone has to build it, keep it current, and remember to email the people who asked. Rowpa builds it from the vendors you already record, keeps it current because it is generated, and sends the email for you.

What the page carries

01
Every column a buyer checks
Name and legal entity, what they are used for and which data categories, head office country, where data is processed and on what transfer basis, whether a data processing agreement is in place with a link to it, and the supplier's own sub-processors where you have recorded them.
02
A stable URL, in your language
trust.yourdomain or yourslug.rowpa.app/trust/subprocessors, in English, German, French or Polish, with a last-updated date and a print view for the buyer who wants a PDF on file.
03
Change notifications
A customer enters their email on the page. When you add or remove a supplier, Rowpa emails them the change the next morning, in your language, with an unsubscribe link. The first day only records the list; nobody is told that everything is new.
04
Quoted by your pack
The supplier due diligence pack links the public list in its suppliers section, so the buyer who files the pack has the address that stays current.
05
You see it being read
Views of the list are counted alongside your Trust Center and pack links, without cookies or identifiers, and how many people subscribed shows on your dashboard.

What goes on the page

The same rows as your vendor register, minus anything internal: no risk notes, no negotiation history, no DPA expiry chasing. If a vendor is marked as an independent controller it is left off, because it is not your sub-processor.

Who can see it

Anyone with the link, once your Trust Center is published. Set the Trust Center to private and the list goes with it. Subscribers' addresses are held for you, scoped to your workspace, and never shown on the page.

Pricing

Included from Starter with a published Trust Center; build and preview it free. The pack that quotes it is £39 once or included from Starter.

Start free See all plans

Common questions

Do I have to publish my Trust Center to use this?
Yes. The list is part of the Trust Center and follows its visibility. Unlisted works: the page exists at its address without being linked from the Trust Center's public index.
What counts as a change?
A sub-processor added or removed. A country or DPA status change is shown on the page but does not trigger an email, because Article 28(2) is about which processors you use.
Can I write my own text on the page?
Not yet. The page is generated so it cannot drift from your register. Your accountable person's email is shown for questions.
How does this compare to the template in your blog post?
The template is the same table, built and maintained by hand. This is the table generated from your register, with the notification handled.

Further reading

Publish the list once. Let the register keep it current.

Build your vendor register free, publish your Trust Center, and the list is live.

Publish yours free