48 Total
8 High severity
13 Medium severity
27 Low severity
Summary

This is Twilio's official sub-processor disclosure list for the Segment Customer Data Platform and related Twilio services, identifying every third-party company authorized to process customer personal data as of April 2026. The document discloses that AWS processes personal data across all Twilio services as the primary infrastructure provider, with data location dependent on whether customers have selected Regional Twilio (Ireland or Australia); however, the document states that fraud and abuse investigations may result in processing in the United States regardless of region selection. Multiple AI vendors including OpenAI, Anthropic, Amazon Bedrock, and Microsoft Azure are listed as sub-processors for personal data contained in customer-defined workflows, applicable across all AI products.

Technical / Legal Breakdown

This document is Segment's (published under Twilio) sub-processor list, last updated April 2026, which discloses the third-party companies engaged to process personal data on behalf of Twilio customers pursuant to applicable data protection laws including GDPR and related frameworks. The document states that Twilio imposes contractual obligations on each sub-processor to implement appropriate technical and organizational measures, has performed Transfer Impact Assessments where cross-border data transfers occur, and maintains written contracts with all listed sub-processors. The list spans over 35 named entities including major cloud infrastructure providers (AWS, Google, Microsoft Azure), AI vendors (OpenAI, Anthropic, ElevenLabs), observability and analytics tools, and customer support platforms, with data processed across the USA, EU, and UK depending on service configuration. The document engages GDPR Chapter V transfer mechanisms, CCPA processor obligations, and standard controller-to-processor contractual requirements; customers contracting with non-US Twilio entities (e.g. Twilio Ireland Ltd.) should note that Twilio Inc. itself is listed as a sub-processor, creating an intra-group transfer that may require separate evaluation under applicable data protection law. Material compliance considerations include the breadth of AI vendors (OpenAI, Anthropic, Amazon Bedrock, Microsoft Azure, Lakera, ElevenLabs) processing personal data from customer-defined workflows, and the Regional Twilio footnote disclosing that fraud and abuse investigations may result in data being processed in the United States regardless of selected region.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance
Featured — High severity
Featured — Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

48 provisions
12 featured
7 clause types
8 high severity
data_usage 26
data_sharing 7
ai_automated 6
data_retention 5
disclosure_requirements 2
other 1
platform_discretion 1

Monitoring

Segment has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle Fraud And Abuse Investigation Processing Exception and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 7, 2026 00:21 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000937
Version ID CA-V-004548
SHA-256 eb0c920c72df0732ba3434b4acbc87ddf3cac2ad805f3e24639ec619d81bba39
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans