FillTrust

How to answer

Do you use sub-processors, and can you provide a current list?

The list is easy. What reviewers actually check is whether the unglamorous ones are on it: the error tracker, the support desk, the AI provider.

A model answerConfirmed in your documents

Yes. Our current sub-processors are published at [url] and the list is kept current. Under our DPA we give [30] days' notice before adding a new sub-processor, during which you may object.

Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.

Answered from
Your published sub-processor list. If you do not have one, this question is the reason to write one.
Evidence to attach
A URL. This is the one question where the best evidence is a public page you maintain rather than a document you send.
Where it is asked
CAIQ v4.0 · DSP-14SIG LiteGDPR · Art. 28(2)

Answering yes is not the hard part. Every SaaS uses sub-processors, and a reviewer who saw "no" would assume you had misunderstood the question.

What they are checking is completeness, and completeness is where almost every list falls short. Teams list the obvious infrastructure, the cloud provider and the managed database, and stop there. A sub-processor is any third party that processes customer personal data on your behalf, which typically also means: your error tracker, if stack traces carry user identifiers; your product analytics; your support desk, where customers paste their own data into tickets; your transactional email provider; your payment processor; and any AI or model provider you send customer content to.

That last one deserves its own sentence, because it is new enough that lists have not caught up. If customer content is sent to a model provider, even transiently and even under terms that exclude it from training, that provider is processing customer data on your behalf, and a reviewer at a company that has thought about AI will look for it specifically. Its absence from an otherwise thorough list reads as either an oversight or an omission, and neither is a good look for the vendor asking for their SOC 2 report.

Two mechanical things make this answer good rather than adequate:

Publish the list at a stable URL and point at it. A list attached as a PDF is out of date the moment your stack changes; a page is right whenever it is read, and a reviewer can check it again at renewal without asking you.

State the notice period. GDPR Art. 28(2) contemplates the controller objecting to a new sub-processor, which is only possible if they hear about it first. Thirty days' notice before a change takes effect is the common commitment. Reviewers ask for the window; having it in the answer is one fewer round trip.

How this one goes wrong

Specific to this question, not general advice.

  • Listing only the infrastructure providers. Your error tracker, analytics, support desk, email sender and any AI provider are sub-processors too if customer data reaches them.
  • Having no notice commitment. GDPR Art. 28 expects the controller to be able to object to a change, which needs advance notice, and reviewers ask for the window.
  • A list in a PDF. It goes stale the day it is sent; a URL stays right.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.