Customer Asked for Your Subprocessor List and Data Residency. What Should a Small SaaS Vendor Share?
Published August 2026 by Solarc Labs
The buyer is asking about the real service chain, not just your company address
A SaaS vendor may operate the customer-facing application while relying on hosting, email, support, observability, authentication or other service providers underneath it. The procurement question is therefore about which separate organisations can process customer personal information, what role they perform and where the relevant processing takes place. NCSC cloud guidance says a provider should be able to explain where customer data is processed and stored and where providers handling that data are legally based. Start with the services actually used by the product and the customer plan in scope. Do not copy every vendor your company has ever purchased into the list, and do not omit an in-scope processor because it sits behind another platform.
For UK GDPR processor relationships, subprocessor authorisation is a contract control
ICO guidance says a processor wishing to use another processor must have the controller’s prior specific or general written authorisation. Where general authorisation applies, the processor must inform the controller about intended changes and give the controller an opportunity to object. The processor also needs an appropriate contract with the subprocessor. Your customer-facing answer should therefore match the DPA or other governing terms that actually apply. Do not promise a notification period, objection right or approval workflow that is not in the signed terms or operational process.
“Where is my data?” needs more than one country label
Separate the locations that matter: primary application data, backups, operational logs and any other material processing performed by providers. If the product offers regional configuration, state the region available to the customer and the conditions that apply. If some support or subprocessors can access data from another location, do not describe the whole service as “UK-only” merely because the primary database is in the UK. NCSC guidance specifically asks SaaS buyers to consider whether data is stored and processed in appropriate locations and legal jurisdictions. A useful answer names the relevant service, purpose and location rather than using a vague “hosted in Europe” statement.
Data-centre geography alone does not decide whether a UK restricted transfer exists
ICO’s 2026 international-transfer guidance makes an important distinction: geographic server location is not the only question. The legal entities involved and whether personal information is made available to a separate organisation outside the UK also matter. A UK service provider using servers abroad is not automatically the same legal transfer scenario as a UK processor contracting with a separate non-UK subprocessor. That is why a questionnaire answer should describe the actual processing chain and route transfer-law questions to the responsible privacy or legal owner. Do not infer a transfer mechanism solely from a cloud region name.
Keep one reviewed record that can answer the next buyer without becoming stale
For each in-scope subprocessor, record the legal or trading name needed for customer identification, service purpose, material data category, processing/storage location where relevant, evidence source, contract or DPA owner and last review date. Keep proposed or historical providers separate from currently used providers. If the service chain changes, trigger review of the public list, DPA commitments and approved questionnaire answer. Reusing an answer from last year without checking the current architecture can create a false procurement statement even when the old answer was correct at the time.
VendorOS can organise the evidence; it cannot decide the legal position for you
VendorOS Security Questionnaire Rescue can map a buyer’s subprocessor or data-residency question to reviewed wording, source evidence, owners, review dates and explicit gaps. It does not determine whether a supplier is legally a subprocessor, amend a DPA, approve an international transfer, guarantee UK GDPR compliance or prove that every data path stays inside a stated region. If the buyer asks for a contractual commitment that the service does not currently support, preserve that as a real deal constraint and escalate it rather than turning it into polished but unsupported sales copy.
Primary sources
Sources used for this article
Continue the job