[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-sub-processor::en":3,"gloss-cluster-sub-processor::en":23,"gloss-next-sub-processor::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"sub-processor","security","Sub-processor","A sub-processor is a third-party vendor that processes your customers' personal data on your behalf — the cloud host, email service, analytics tool, or AI API sitting behind your product. Under GDPR and most enterprise contracts, you (the processor) must disclose your sub-processors, bind them with contractual data-protection terms, and often give customers advance notice before adding new ones. This matters twice over for AI SaaS builders: every model provider you call is a sub-processor handling whatever your users send, and enterprise buyers will scrutinize that chain during procurement. A single unlisted vendor can stall a deal or trigger a compliance finding. Practical note: keep a public sub-processor list with names, purposes, and locations; wire up a notification mechanism (a page plus an email list) for changes; and check each vendor's own DPA and data-residency options before you route customer data through them. Fewer, well-documented sub-processors are easier to sell and audit.","Under GDPR you must disclose every sub-processor behind your product, bind each by contract, and notify customers before adding a new one — an auditable duty.",null,[11,14,17,20],{"slug":12,"name":13},"data-residency","Data Residency",{"slug":15,"name":16},"data-retention","Data Retention Policy",{"slug":18,"name":19},"gdpr","GDPR (General Data Protection Regulation)",{"slug":21,"name":22},"pii","Personally Identifiable Information (PII)",[24,28,32,36,39,42,45,48,51,54,57,60],{"slug":25,"category":5,"name":26,"updated_at":27},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":29,"category":5,"name":30,"updated_at":31},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":33,"category":5,"name":34,"updated_at":35},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":37,"category":5,"name":38,"updated_at":35},"bridge-letter","Bridge Letter",{"slug":40,"category":5,"name":41,"updated_at":35},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":43,"category":5,"name":44,"updated_at":27},"byok","Bring Your Own Key (BYOK)",{"slug":46,"category":5,"name":47,"updated_at":35},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":49,"category":5,"name":50,"updated_at":31},"data-classification","Data Classification",{"slug":52,"category":5,"name":53,"updated_at":35},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":55,"category":5,"name":56,"updated_at":35},"data-minimization","Data Minimization",{"slug":58,"category":5,"name":59,"updated_at":35},"data-poisoning","Data Poisoning",{"slug":61,"category":5,"name":62,"updated_at":35},"data-processing-agreement","Data Processing Agreement (DPA)"]