Why This Is a Different Question Than Cold Email Compliance
It is easy to fold every compliance question a SaaS buyer raises into one bucket. They are not the same bucket. Consent law, CAN-SPAM, GDPR’s legitimate-interest test, state-level TCPA rules, governs whether a message can be sent to a prospect in the first place. Data residency and sub-processor governance is a separate question entirely: once a deal closes and real customer data starts flowing through a vendor’s product, where does it actually live, and who else touches it along the way.
A SaaS company can be fully compliant on the first question and still fail the second one badly enough to lose a regulated deal. This guide is scoped to the second question specifically.
What Article 28 Actually Requires From a Sub-Processor Chain
GDPR Article 28 is specific, not vague, about what a processor owes a controller regarding sub-processors. A processor “shall not engage another processor without prior specific or general written authorisation of the controller.” Where general authorization is used, “the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object.” Every sub-processor must be bound by “the same data protection obligations as set out in the contract... between the controller and the processor.” And where a sub-processor fails to meet those obligations, “the initial processor shall remain fully liable to the controller.”
Read that last clause again from a SaaS vendor’s side of the table: you do not get to point at a sub-processor’s mistake and call it someone else’s problem. You stay liable.
Why “We Use AWS” Isn’t the Full Answer
Naming a primary cloud host answers the top-level version of “where does our infrastructure sit.” It does not answer the question a security team is actually running down: the full, current list of every sub-processor touching customer data, what each one does with it, and where each one operates. Given Article 28’s continuing-liability clause, that list is not a nice-to-have disclosure, it is the exact document a buyer’s legal team needs to understand what they are actually exposed to if any link in that chain fails.
A vendor who cannot produce that list quickly, and cannot explain how the notification-and-objection right under general authorization actually works in their own contract, is answering a compliance question with a marketing one.
The Practical Question Behind “Where Is Our Data”
This is practitioner reasoning, not a separately cited legal rule: in a live sales conversation, “data residency” usually is not a geography trivia question. It is shorthand for “which specific sub-processors touch this data, and in which countries,” asked precisely because Article 28’s objection right only means something if the controller actually knows who is on the list to object to. A buyer who cannot get a straight, current answer to that question cannot meaningfully exercise a right the regulation gives them.
Building a Sub-Processor List Before You’re Asked for One
The practical fix is unglamorous: keep a current, specific, written sub-processor list, what each one does, what data class it touches, and where it operates, ready before a security team asks for it. Some companies publish this list publicly as a standing trust page; others keep it ready to send on request. Either works. What does not work is assembling it for the first time under deadline pressure once a deal is already stalled on the question.
Where This Fits Into a First Conversation
A regulated or EU-facing buyer’s security scrutiny is not a passing phase. Vanta’s State of Trust Report found 72% of security decision-makers say risk for their organization has never been higher, up from 55% in 2024, a 17-point jump in a single year, evidence this exact question is arriving earlier and more often than it used to, not fading out.
Human + AI SDRs can surface the sub-processor question in a first SMS conversation, so a compliance-ready answer is already prepared before a demo gets pitched to a buyer who was always going to ask.
What this means for you
- GDPR Article 28 requires prior controller authorization for any sub-processor, a notification-and-objection right under general authorization, equivalent contractual obligations, and continuing liability for the original processor if a sub-processor fails.
- Naming a primary cloud host answers a different, shallower question than the one a compliance-minded buyer is actually asking, since Article 28’s liability runs through the full sub-processor chain, not just the top-level host.
- Security scrutiny on this exact question is intensifying: 72% of security decision-makers say risk has never been higher, up from 55% in 2024, per Vanta’s State of Trust Report.
Sources
The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
