Skip to main content
VA Horizon
Book a Call
Data Residency

Data Residency and Sub-Processor Questions Regulated SaaS Buyers Ask Before They’ll Take a Call

Quick answer

GDPR Article 28 sets the legal mechanics behind the question a regulated buyer’s security team actually asks before a first call: no sub-processor may be engaged without the controller’s prior authorization, specific or general, and under general authorization the controller must be told of intended changes and given a chance to object. Every sub-processor must be bound to obligations equivalent to the ones in the original contract, and critically, the original processor, the SaaS vendor, remains fully liable to the controller if a sub-processor fails to meet them.

That liability structure is why a vague answer to “where does our data live” does not satisfy a compliance-minded buyer. This guide covers that infrastructure question specifically, not consent law. Whether a message can legally be sent is a separate question this site’s existing compliance guides already answer; this one is about where the data goes once a deal closes, and who a vendor is contractually answerable for along the way.

Why This Is a Different Question Than Cold Email Compliance

It is easy to fold every compliance question a SaaS buyer raises into one bucket. They are not the same bucket. Consent law, CAN-SPAM, GDPR’s legitimate-interest test, state-level TCPA rules, governs whether a message can be sent to a prospect in the first place. Data residency and sub-processor governance is a separate question entirely: once a deal closes and real customer data starts flowing through a vendor’s product, where does it actually live, and who else touches it along the way.

A SaaS company can be fully compliant on the first question and still fail the second one badly enough to lose a regulated deal. This guide is scoped to the second question specifically.

What Article 28 Actually Requires From a Sub-Processor Chain

GDPR Article 28 is specific, not vague, about what a processor owes a controller regarding sub-processors. A processor “shall not engage another processor without prior specific or general written authorisation of the controller.” Where general authorization is used, “the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object.” Every sub-processor must be bound by “the same data protection obligations as set out in the contract... between the controller and the processor.” And where a sub-processor fails to meet those obligations, “the initial processor shall remain fully liable to the controller.”

Read that last clause again from a SaaS vendor’s side of the table: you do not get to point at a sub-processor’s mistake and call it someone else’s problem. You stay liable.

Want this handled for you?

Pay per booked meeting for your industry. No retainer.

Book a B2B Call

Why “We Use AWS” Isn’t the Full Answer

Naming a primary cloud host answers the top-level version of “where does our infrastructure sit.” It does not answer the question a security team is actually running down: the full, current list of every sub-processor touching customer data, what each one does with it, and where each one operates. Given Article 28’s continuing-liability clause, that list is not a nice-to-have disclosure, it is the exact document a buyer’s legal team needs to understand what they are actually exposed to if any link in that chain fails.

A vendor who cannot produce that list quickly, and cannot explain how the notification-and-objection right under general authorization actually works in their own contract, is answering a compliance question with a marketing one.

The Practical Question Behind “Where Is Our Data”

This is practitioner reasoning, not a separately cited legal rule: in a live sales conversation, “data residency” usually is not a geography trivia question. It is shorthand for “which specific sub-processors touch this data, and in which countries,” asked precisely because Article 28’s objection right only means something if the controller actually knows who is on the list to object to. A buyer who cannot get a straight, current answer to that question cannot meaningfully exercise a right the regulation gives them.

Building a Sub-Processor List Before You’re Asked for One

The practical fix is unglamorous: keep a current, specific, written sub-processor list, what each one does, what data class it touches, and where it operates, ready before a security team asks for it. Some companies publish this list publicly as a standing trust page; others keep it ready to send on request. Either works. What does not work is assembling it for the first time under deadline pressure once a deal is already stalled on the question.

Where This Fits Into a First Conversation

A regulated or EU-facing buyer’s security scrutiny is not a passing phase. Vanta’s State of Trust Report found 72% of security decision-makers say risk for their organization has never been higher, up from 55% in 2024, a 17-point jump in a single year, evidence this exact question is arriving earlier and more often than it used to, not fading out.

Human + AI SDRs can surface the sub-processor question in a first SMS conversation, so a compliance-ready answer is already prepared before a demo gets pitched to a buyer who was always going to ask.

What this means for you

  • GDPR Article 28 requires prior controller authorization for any sub-processor, a notification-and-objection right under general authorization, equivalent contractual obligations, and continuing liability for the original processor if a sub-processor fails.
  • Naming a primary cloud host answers a different, shallower question than the one a compliance-minded buyer is actually asking, since Article 28’s liability runs through the full sub-processor chain, not just the top-level host.
  • Security scrutiny on this exact question is intensifying: 72% of security decision-makers say risk has never been higher, up from 55% in 2024, per Vanta’s State of Trust Report.

Sources

The external data in this guide draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.

FAQ

What does GDPR Article 28 actually require regarding sub-processors?
No sub-processor may be engaged without the controller’s prior authorization, specific or general. Under general authorization, the controller must be told of intended changes and given a chance to object, every sub-processor must be bound to equivalent obligations, and the original processor stays fully liable if a sub-processor fails to meet them.
Is a data residency question the same as a cold email compliance question?
No. Consent law, CAN-SPAM, GDPR legitimate interest, TCPA, governs whether a message can be sent. Data residency and sub-processor governance is a separate question about where customer data lives and who processes it once a deal closes.
Is naming your primary cloud provider enough to answer a buyer’s data residency question?
Usually not on its own. A security team is typically asking for the full, current sub-processor list, what each one touches, and where it operates, since Article 28 makes the original vendor liable for the whole chain, not just the top-level host.
Should a SaaS company have a sub-processor list ready before being asked?
Yes. Some companies publish it as a public trust page; others keep it ready to send on request. Assembling it for the first time under deadline pressure, once a deal is already stalled, is the pattern to avoid.
Is this kind of scrutiny becoming more common?
Yes. Vanta’s State of Trust Report found 72% of security decision-makers say risk has never been higher, up from 55% in 2024, a 17-point jump, evidence buyers are asking earlier and more often, not less.

Have the sub-processor answer ready before it’s asked.

Book a 15-minute call and see how Human + AI SDRs surface the data residency question early, so a regulated buyer gets a real answer instead of a stall.

Book a B2B Call

Pay per booked meeting · No retainer · Free no-show replacement

Recommended next steps