Provision record
Greenhouse · Greenhouse Terms of Service · View original document ↗

Subprocessor Disclosure and DPA Execution

Medium severity Medium confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Greenhouse and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

Greenhouse publicly discloses its subprocessors and states that it executes DPAs with each subprocessor and evaluates their security, privacy, and confidentiality practices before engagement.

This analysis describes what Greenhouse's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision documents Greenhouse's stated sub-processing governance framework, including contractual coverage and pre-engagement evaluation, which is operationally relevant for business customers assessing their GDPR Article 28 and CCPA/CPRA service provider chain obligations.

Interpretive note: The actual subprocessor list, the specific DPA terms imposed on subprocessors, and the scope of the pre-engagement evaluation process are not disclosed in this index document.

Consumer impact (what this means for users)

This clause establishes that personal data processed by Greenhouse may be shared with disclosed subprocessors, each of which is stated to be covered by a DPA and subject to a pre-engagement security and privacy evaluation by Greenhouse.

Cross-platform context

See how other platforms handle Subprocessor Disclosure and DPA Execution and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
The following list discloses the subprocessors assisting Greenhouse in providing services, where Greenhouse itself is acting as a data processor. Greenhouse executes Data Processing Agreements (DPAs) with each of its subprocessors to ensure personal data being processed by those subprocessors is properly protected and secured. Additionally, Greenhouse evaluates the security, privacy, and confidentiality practices of its subprocessors prior to engaging with them.

Excerpt from Greenhouse's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Subprocessor disclosure and contractual coverage directly engage GDPR Article 28(2) and (4), which require that processors obtain controller authorization for sub-processing and impose equivalent data protection obligations on subprocessors.

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
Greenhouse Terms of Service
Entity
Greenhouse
Document last updated
July 5, 2026
Tracking information
First tracked
July 6, 2026
Last verified
July 9, 2026
Record ID
CA-P-015518
Document ID
CA-D-00917
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2d08cf7159e02480ba7bc7d2f13373da12c9dfbf555b96e0e61894ec832211d9
Analysis generated
July 6, 2026 15:40 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Greenhouse
Document: Greenhouse Terms of Service
Record ID: CA-P-015518
Captured: 2026-07-06 15:40:41 UTC
SHA-256: 2d08cf7159e02480…
URL: https://conductatlas.com/platform/greenhouse/greenhouse-terms-of-service/provision/CA-P-015518/subprocessor-disclosure-and-dpa-execution/
Accessed: Sept. 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Greenhouse's Subprocessor Disclosure and DPA Execution clause do?

This provision documents Greenhouse's stated sub-processing governance framework, including contractual coverage and pre-engagement evaluation, which is operationally relevant for business customers assessing their GDPR Article 28 and CCPA/CPRA service provider chain obligations.

How does this clause affect you?

This clause establishes that personal data processed by Greenhouse may be shared with disclosed subprocessors, each of which is stated to be covered by a DPA and subject to a pre-engagement security and privacy evaluation by Greenhouse.

Is ConductAtlas affiliated with Greenhouse?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Greenhouse.