Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The DPA states that Modal will provide 30 days advance notice of subprocessor changes via website update and email notification (if Customer has self-enrolled), but that the only available remedy for a Customer objection to a new subprocessor is termination of the subscription.
This analysis describes what Modal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Customer cannot block a new subprocessor appointment without exiting the service entirely, and that email notification of subprocessor changes requires Customer to affirmatively self-enroll rather than being automatic. The GDPR Article 28(2) framework permits objection rights but does not prescribe the remedy; the termination-only remedy is the contractual implementation of that right.
Under this clause, Customers who object to a new or replacement subprocessor have only one available remedy: terminating their subscription. To receive proactive email notice of subprocessor changes, Customers must self-enroll at https://trust.modal.com/subprocessors; otherwise, notice is provided only through website updates.
Cross-platform context
See how other platforms handle Subprocessor Objection Limited to Termination and similar clauses.
Compare across platforms →Monitoring
Modal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"At least 30 days prior to the addition or replacement of any subcontractor Modal will: (i) update its Subprocessor website at https://trust.modal.com/subprocessors, and (ii) if Customer has self-enrolled to receive email updates, notify Customer of any such intended changes, thereby giving Customer the opportunity to object. Customer's sole recourse if it objects to a Subprocessor will be to terminate its subscription to the Service.Excerpt from Modal's Terms of Service
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 28(2), which requires that processors obtain controller authorization before engaging subprocessors and provide the controller an opportunity to object. The GDPR does not prescribe the remedy for objection, so the termination-only mechanism is a contractual implementation of the objection right rather than a violation of it, though data protection authorities in some EU member states may scrutinize whether this mechanism provides a meaningful opportunity to object. The UK ICO and Swiss FDPIC apply equivalent standards. (2) GOVERNANCE EXPOSURE: Medium. For Customers with operational dependencies on the Modal platform, the termination-only remedy may create a practical situation where objecting to a subprocessor change is not commercially viable, which data protection authorities could view as limiting the effectiveness of the objection mechanism under GDPR. Organizations with strict vendor approval requirements should assess this mechanism against their own data governance policies. (3) JURISDICTION FLAGS: EU and UK Customers operating as data controllers have the most direct exposure under this provision, as GDPR Article 28(2) requires controller authorization of subprocessors. California Customers should assess whether CPRA's service provider requirements impose additional subprocessor management obligations. The emergency replacement provision, which permits immediate subprocessor changes with retrospective notification, creates an additional consideration for time-sensitive objections. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should ensure that relevant personnel self-enroll for subprocessor notifications at https://trust.modal.com/subprocessors, as the agreement does not provide automatic email notice. Contract review workflows should include a process for evaluating new subprocessor appointments within the 30-day window, given that the only contractual remedy after that window is termination. (5) COMPLIANCE CONSIDERATIONS: Data protection officers should document their acceptance of the termination-only objection mechanism as part of their Article 28 controller assessment. The emergency replacement provision should be factored into incident response and subprocessor risk assessment procedures, as it permits changes outside the standard 30-day notice period.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that Customer cannot block a new subprocessor appointment without exiting the service entirely, and that email notification of subprocessor changes requires Customer to affirmatively self-enroll rather than being automatic. The GDPR Article 28(2) framework permits objection rights but does not prescribe the remedy; the termination-only remedy is the contractual implementation of that right.
Under this clause, Customers who object to a new or replacement subprocessor have only one available remedy: terminating their subscription. To receive proactive email notice of subprocessor changes, Customers must self-enroll at https://trust.modal.com/subprocessors; otherwise, notice is provided only through website updates.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Modal.