RatedWithAI

RatedWithAI

Accessibility scanner

AI Privacy & VendorsSeptember 23, 2026

Your AI Vendor's Vendor Is the One Holding the Data

The data processing agreement you negotiated binds the company on your invoice. In a typical AI feature that company orchestrates; the model host, the capacity broker and the human review workforce do the processing — and each of them is a hop your paper only reaches through a clause most teams never verify was performed.

The shortest version: one signature, four processors. Ask where inference executes, where prompts are logged, and who can read them — as three separate questions, per subprocessor. The answers are usually different, and the gap between them is your actual exposure.

How the Chain Is Actually Shaped

The AI vendor you signed with is rarely the party computing

The company on your invoice typically orchestrates. Inference runs on a foundation-model provider's API or on capacity rented from a cloud or a GPU broker; retrieval runs against a managed vector service; evaluation and abuse review are frequently outsourced to a human workforce in a third country. Four organisations can touch one prompt. Your agreement names one of them.

A subprocessor is defined by function, not by billing

Anything that processes personal data on the vendor's behalf to deliver your service is a subprocessor, whether it is a household-name cloud or a two-person annotation shop. Vendors routinely list the clouds and omit the annotation shops, and the omission is usually not concealment — it is that the security page was written before the AI feature shipped and nobody revised it.

Flow-down is a duty, not a courtesy

The standard processor obligation is that the vendor may not engage a subprocessor without authorisation, and must impose materially the same data-protection terms down the chain by contract. If the vendor cannot show you that downstream paper, the duty was not performed, and the vendor remains fully liable to you for the subprocessor's performance.

Your own obligations do not stop at the first hop

Under the CCPA a service provider may only engage a subcontractor under a written contract carrying the same restrictions, and a business has to exercise reasonable diligence over the chain. Under the GDPR the controller stays accountable for the whole processing operation. Neither framework lets you point at a vendor and call the rest someone else's problem.

The AI layer moved the chain offshore without telling anyone

Capacity is fungible and routed to where it is cheapest and available, which is why 'US region' commitments in an AI product are frequently commitments about your account's storage and not about where a given inference executed. Ask the question about inference, about logging, and about human review separately, because the three answers are often different.

The Five Documents That Have to Line Up

Each one is routinely present in a form that does not do the job it is filed under.

The subprocessor list, with a change-notification term

Named entities, the processing each performs, and the country it performs it in. The useful part is not the list but the term next to it: how many days' notice before a new subprocessor is added, how notice is delivered, and what happens if you object. A list published on a page you must remember to visit is not notice.

The objection right, and what it is actually worth

Most agreements let you object to a new subprocessor and, failing resolution, terminate the affected service. That is a right with a cost attached, so read it as a pricing question: if the answer to an objection is 'terminate and lose the feature', the right exists on paper and will never be used. Negotiate a suspension or an alternative-region option instead where the data is sensitive.

The transfer instrument for every hop that leaves the region

A transfer out of the EEA or the UK needs a lawful mechanism — an adequacy decision, the standard contractual clauses with the right module, the UK addendum, or a derogation that genuinely applies. Module selection is the common error: a processor-to-processor transfer downstream of you is not the module most templates default to, and the wrong module is the kind of defect that is invisible until a regulator reads the annexes.

The transfer impact assessment, dated and specific

The instrument is not sufficient on its own; you are expected to assess whether local law in the destination undermines it, and to document supplementary measures where it does. A one-page assessment that names the destination country, the categories of data, the access-request regime and the encryption and key-custody position is defensible. A template with the country left as a placeholder is not.

The records of processing entry that matches reality

Whatever inventory you keep should record the AI feature, the categories of personal data it receives, the retention at each hop and the recipients including subprocessors. This is the document a supervisory authority asks for first, and the one most likely to describe a product two releases behind the one in production.

Where the Chain Breaks Quietly

'We do not train on your data' answers a different question

Training rights and subprocessing are independent. A vendor can honour a no-training commitment perfectly while routing every prompt through three other companies. Get both answers, in the contract, in separate sentences — and ask specifically about abuse-monitoring retention, which is the standard carve-out that keeps prompt content for a period even under a no-training term.

The zero-retention setting that logs anyway

Zero-retention configurations usually govern the model provider's storage of content, not your vendor's application logs, its error tracker, its analytics or its support tooling. Prompts containing personal data land in all four by default in most stacks. The question to ask is where a prompt can be read ninety seconds after it was sent, not where it is stored ninety days later.

Human review is a subprocessor with a physical location

Safety review, red-teaming, evaluation labelling and support escalation are performed by people, often through a staffing intermediary in a different jurisdiction from the vendor. It is the hop most often missing from the published list and the one with the highest chance of a human reading identifiable customer content.

Agent tooling widens the chain at runtime

An AI feature that calls external tools — search, enrichment, code execution, a browser — sends data to services chosen at inference time by a model, not at procurement time by you. Treat the tool allowlist as part of the subprocessor list, because functionally that is what it is, and require that it be enumerable rather than open-ended.

Acquisition rewrites the chain overnight

AI infrastructure consolidates fast. A subprocessor acquired by a competitor of yours, or relocated to a new parent in a different jurisdiction, changes both your transfer analysis and your commercial exposure without a single line of your contract changing. A change-of-control notice term on the subprocessor list is cheap to ask for at signature and impossible to get afterwards.

Five Things to Put in Place

Draw the data flow from your own request logs, not the vendor's diagram

For one representative feature, write down what leaves your systems, to which endpoint, containing which fields. Teams routinely find that a free-text field reaches a model with far more personal data in it than the design assumed, because users put it there.

Ask three separate location questions

Where does inference execute, where are prompts and outputs logged, and where do humans review them. Ask for each answer per subprocessor. One answer for all three is a sign that the person answering has not checked.

Get the downstream terms confirmed in writing

You are entitled to confirmation that materially equivalent obligations are imposed on each subprocessor. You will rarely get the agreements themselves; a written confirmation naming the instrument and the module is a reasonable settlement and is worth far more than a security page screenshot.

Date the transfer impact assessment and put a review trigger on it

Re-open it when a subprocessor is added, when a destination changes, or when the legal position in a destination changes. An assessment with no review trigger is a document that describes the day it was written.

Keep the subprocessor list under change control with your own copy

Snapshot the vendor's list at signature and on each notice, with dates. When a question arrives about a period in the past, the answer depends on what the chain looked like then, and the vendor's live page will not tell you.

Questions Procurement and Legal Teams Ask

Is a foundation-model API a subprocessor or an independent controller?

In the ordinary enterprise arrangement it is a subprocessor: it processes the content you send on your vendor's behalf, for the purpose of delivering the service, under the vendor's instructions. Model providers publish enterprise terms drafted on exactly that footing. Two things complicate it. First, consumer and self-serve tiers of the same product are often drafted so that the provider processes for its own purposes as well, which is a different relationship with different duties, and teams sometimes build on a self-serve key and inherit those terms without noticing. Second, some providers reserve rights over content for safety and abuse monitoring that look controller-shaped even on enterprise paper. The practical test is not the label in the contract but the answer to two questions: can the provider use the content for any purpose you did not specify, and for how long is it retained when you have asked for zero retention. Get both in writing, because the label follows the answers rather than the other way round.

Our AI vendor will not share its subprocessor agreements. Is that normal?

Declining to hand over the agreements themselves is normal and usually reasonable, since they are third-party commercial documents. Declining to confirm that materially equivalent obligations exist is not, because imposing them is the vendor's own duty under the terms it signed with you. The workable middle is a written confirmation that names each subprocessor, the processing performed, the location, and the instrument relied on for any transfer out of the region — plus a commitment that the vendor remains fully liable for its subprocessors' performance, which is the default position under standard processor terms and should not need negotiating. If a vendor will not confirm even that, the useful conclusion is not that they are hiding something: it is usually that the paperwork does not exist yet, which is itself the finding you needed.

Does the CCPA care about subprocessors the way the GDPR does?

It does, in its own vocabulary. A service provider that engages another entity to help deliver the service must do so under a written contract that imposes the same restrictions applicable to it, and the business is expected to exercise reasonable diligence over the arrangements it relies on. The practical differences from the GDPR are that the California framework attaches most of its force to the purpose limitation — the downstream party may not use the personal information for its own purposes or outside the direct business relationship — and that it does not maintain a separate international-transfer regime, so the cross-border instrument work is driven by European and UK law rather than by California. Where an AI stack serves both populations, the sensible approach is one chain map and one set of terms drafted to satisfy the stricter framework, rather than two parallel programmes that drift.

Do we need a transfer impact assessment for every AI vendor?

You need one for every transfer that relies on the standard contractual clauses or an equivalent instrument rather than on an adequacy decision, which in a typical AI stack means the hops that leave the EEA or the UK for a destination without adequacy. The assessment is proportionate: the categories and sensitivity of the data, the destination's access regime, the likelihood of an access request touching this kind of data, and the technical and organisational measures that would blunt one — encryption in transit and at rest, who holds the keys, whether the vendor publishes a transparency report, and what its policy is on challenging requests. Two things make assessments fail review. One is a placeholder that was never filled in for the specific destination. The other is no review trigger, so it stops describing the chain the moment a subprocessor is added. Date it, name the destination, and re-open it on change.

What is the single most commonly missed hop?

Human review. Every serious AI deployment has a path by which a person can read customer content: abuse and safety review at the model provider, evaluation and labelling for quality work, support escalation when a customer reports a bad output, and debugging when an engineer reproduces a failure from a logged payload. Those four paths are staffed differently, often through intermediaries, frequently in different countries from the vendor's headquarters, and they are the hops least likely to appear on a published subprocessor list. They are also the ones a customer cares most about, because the risk is not abstract processing — it is a named person reading text a user typed. Ask who can read a prompt, under what circumstances, from where, and with what logging of the access itself. The answer tells you more about a vendor's maturity than its certifications do.

The Two-Column Test

Put your vendor's published subprocessor list in one column. In the other, list every company that could see a prompt: the model provider, the capacity it rents, the vector service, the error tracker, the analytics pipeline, the support desk and whoever performs safety review.

If the second column is longer, the difference is not a paperwork gap — it is the set of recipients your own privacy notice does not describe, and the set your customers would name if asked who is holding their data.

Related Reading