Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Snowflake maintains and publishes a list of sub-processors and affiliates, indicating that customer data may be processed by third-party sub-processors in addition to Snowflake itself.
This analysis describes what Snowflake's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The Sub-Processors and Affiliates list is a material GDPR Article 28 compliance element, as it discloses the third-party entities to whom Snowflake may transfer or provide access to customer personal data in the course of service delivery. Under standard DPA terms, customers may have rights to object to new sub-processor additions.
The updated Privacy Notice no longer includes explicit language stating that users 'may unsubscribe through unsubscribe links at any time.' This removal means the document no longer contains that specific commitment to unsubscribe availability. The updated terms still reference a Privacy Notice governing data processing and retain cookie-related disclosures, but the removal of the unsubscribe guarantee eliminates a documented mechanism users may have relied on. You can review the full Privacy Notice to understand current communication and preference management options.
View change record →Customer data processed through Snowflake may be handled by sub-processors identified on the published list. Organizations subject to GDPR or other data protection frameworks that require sub-processor assessment should obtain and review this list as part of their vendor management and data mapping obligations.
Cross-platform context
See how other platforms handle Sub-Processors and Affiliates Disclosure and similar clauses.
Compare across platforms →Monitoring
Snowflake has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Snowflake Sub-Processors and AffiliatesExcerpt from Snowflake's Privacy Notice
1. REGULATORY LANDSCAPE: Sub-processor disclosure directly engages GDPR Article 28(2) and (4), which require controllers to obtain processor authorization for sub-processing and require processors to impose equivalent data protection obligations on sub-processors. The CCPA and other state privacy laws may also require disclosure of service providers and contractors who process personal information. Enforcement authorities include EU member state data protection authorities for GDPR obligations. 2. GOVERNANCE EXPOSURE: Medium to High for GDPR-subject customers. Under GDPR Article 28, customers who have executed a DPA with Snowflake must be notified of new sub-processors and may have the right to object. Failure to maintain an up-to-date sub-processor list review process may result in unapproved sub-processing, creating compliance exposure for the customer as controller. 3. JURISDICTION FLAGS: EU and UK organizations face the most direct compliance obligation under this provision. Organizations in countries with equivalent sub-processor oversight requirements should conduct a similar review. California organizations should assess whether sub-processors qualify as contractors or service providers under the CPRA and whether appropriate contractual terms are in place. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should obtain the current Sub-Processors and Affiliates list and conduct risk assessments for all listed sub-processors as required by their internal vendor management policies. DPA terms should be reviewed to confirm the mechanism for sub-processor change notification and the objection period provided to customers. Any right to object to new sub-processors and the consequences of such objection (including potential termination rights) should be assessed. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should implement a process to monitor Snowflake's sub-processor list for changes and assess new sub-processors against applicable data protection requirements. The sub-processor list should be incorporated into the organization's data processing records maintained under GDPR Article 30. Any sub-processors operating in high-risk jurisdictions should receive enhanced scrutiny.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The Sub-Processors and Affiliates list is a material GDPR Article 28 compliance element, as it discloses the third-party entities to whom Snowflake may transfer or provide access to customer personal data in the course of service delivery. Under standard DPA terms, customers may have rights to object to new sub-processor additions.
Customer data processed through Snowflake may be handled by sub-processors identified on the published list. Organizations subject to GDPR or other data protection frameworks that require sub-processor assessment should obtain and review this list as part of their vendor management and data mapping obligations.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Snowflake.