Desk notes · US commercial contracts · Position of the week
Position of the week: sub-processor notice, thirty days
US customers with EU data ask for prior approval of every sub-processor. Vendors offer a list and a promise to update it. The workable middle is a notice period with a right to object, and the number we hold is thirty days.
Every SaaS product runs on other people’s services: cloud infrastructure, email, analytics, support tools. Each is a sub-processor under the GDPR, and the regulation requires the customer’s authorisation before one is engaged. Specific approval of each addition is what customers ask for. It is also unworkable: a vendor with two hundred customers cannot seek two hundred consents to change its logging provider.
The position
General authorisation for the sub-processors on a published list. Thirty days’ written notice — an email to a nominated address, or a subscription to the list page — before any addition. A right to object on reasonable, data-protection-related grounds. If the objection cannot be resolved, the customer may terminate the affected services without penalty.
Why thirty
Fourteen days is what vendors open with; it is not enough for a customer’s privacy team to assess a new provider. Sixty is what customers open with; it means a vendor cannot respond to an outage by switching providers for two months. Thirty is long enough to evaluate and short enough to operate, and it is where the large majority of negotiated DPAs land.
Where we move
For regulated customers, a longer period for sub-processors that will hold special-category data, and sometimes a short list of named providers that require specific approval. Never to specific approval for everything. That is a promise the vendor will break in the first quarter.
Next step
Seen something like this on your own paper?
Send it over. Twenty minutes, marked up, explained.