How to answer
Will you notify us before adding or changing a sub-processor?
"We will notify you" and "we will notify you thirty days before" are different commitments, and this question is asking for the second.
Yes. Our sub-processors are published at [URL]. We give [30 days'] notice before a new sub-processor begins processing customer data, and you may object during that period; the mechanism and the notice period are set out in our Data Processing Agreement.
Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.
- Answered from
- Your data processing agreement, which should already contain the mechanism and the notice period.
- Evidence to attach
- A link to your published sub-processor list, if you have one. It answers this question and several others without an email.
- Where it is asked
- CAIQ v4.0SIG LiteGDPR · Art. 28(2)
This is one of the few questions on a security questionnaire that is really a contract question, and the good news is that the answer is usually already written down. Article 28(2) of the GDPR requires a processor to have the controller's authorisation for sub-processors, and the standard way to satisfy it is general authorisation with advance notice and a right to object. If your data processing agreement says that, this answer is a sentence and a link.
Give the number. The reviewer is not asking whether you will tell them, they are asking how long they get. Thirty days is the common answer; some agreements say fifteen and some say "reasonable notice", which reads as no commitment at all. Whatever the DPA says, quote it rather than paraphrasing, because this answer will be compared against the document.
A published sub-processor list is worth more than the answer itself. It turns a promise into something the reviewer can verify in the next tab, it removes the need for them to ask who your sub-processors are as a separate question, and it makes the notification mechanism concrete: the list has a change history, and the notice is what happens before the list changes. It is also the single cheapest piece of trust infrastructure a small vendor can build.
Be careful with the word "object". Most agreements give the customer a right to object and, if the objection cannot be resolved, a right to terminate. That is not a veto, and describing it as one creates an expectation you will not meet the first time you change your email provider. Say what you actually offer.
The pitfall that causes real damage here is a stale list. It is a public document making specific factual claims about who processes customer data, and it is trivially checkable: a reviewer can look at your DNS records, your page source, your job postings and your status page and form a view about whether the list is current. A sub-processor list that omits something obvious does more harm than having no list, because it converts a gap in your documentation into a question about your candour.
How this one goes wrong
Specific to this question, not general advice.
- Answering yes without a notice period. "We will notify you" and "we will notify you thirty days before" are different commitments, and the reviewer is asking for the second.
- Promising notification you have no way to deliver. If there is no list of who to tell and no step in the process that triggers it, this becomes a contractual commitment nobody will remember.
- Having a sub-processor list that is out of date. It is a public document making a specific factual claim, and it is the easiest thing on your entire site for a reviewer to check against your DNS records and your job ads.
- Confusing the right to object with a right to veto. Say which one you offer; most agreements give a right to object and a right to terminate, not a veto.