Greenhouse publicly discloses its subprocessors and states that it executes DPAs with each subprocessor and evaluates their security, privacy, and confidentiality practices before engagement.
This analysis describes what Greenhouse's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision documents Greenhouse's stated sub-processing governance framework, including contractual coverage and pre-engagement evaluation, which is operationally relevant for business customers assessing their GDPR Article 28 and CCPA/CPRA service provider chain obligations.
Interpretive note: The actual subprocessor list, the specific DPA terms imposed on subprocessors, and the scope of the pre-engagement evaluation process are not disclosed in this index document.
This clause establishes that personal data processed by Greenhouse may be shared with disclosed subprocessors, each of which is stated to be covered by a DPA and subject to a pre-engagement security and privacy evaluation by Greenhouse.
Cross-platform context
See how other platforms handle Subprocessor Disclosure and DPA Execution and similar clauses.
Compare across platforms →"The following list discloses the subprocessors assisting Greenhouse in providing services, where Greenhouse itself is acting as a data processor. Greenhouse executes Data Processing Agreements (DPAs) with each of its subprocessors to ensure personal data being processed by those subprocessors is properly protected and secured. Additionally, Greenhouse evaluates the security, privacy, and confidentiality practices of its subprocessors prior to engaging with them.Excerpt from Greenhouse's Terms of Service
1) REGULATORY LANDSCAPE: Subprocessor disclosure and contractual coverage directly engage GDPR Article 28(2) and (4), which require that processors obtain controller authorization for sub-processing and impose equivalent data protection obligations on subprocessors.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision documents Greenhouse's stated sub-processing governance framework, including contractual coverage and pre-engagement evaluation, which is operationally relevant for business customers assessing their GDPR Article 28 and CCPA/CPRA service provider chain obligations.
This clause establishes that personal data processed by Greenhouse may be shared with disclosed subprocessors, each of which is stated to be covered by a DPA and subject to a pre-engagement security and privacy evaluation by Greenhouse.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Greenhouse.