Track 3 platforms and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Snowflake's official list of third-party companies and Snowflake-owned affiliates that may process Customer Data as part of delivering Snowflake's cloud data platform services. The document discloses four authorized third-party sub-processors (Amazon Web Services, Microsoft Azure, Google Cloud Platform, and Cloudflare), each engaged for specific infrastructure or feature-level purposes, with Standard Contractual Clauses as the transfer mechanism for all international data flows. Snowflake customers with an executed Data Processing Agreement may object to any newly added sub-processor by emailing privacy@snowflake.com within twenty-eight days of receiving notice of the change.
This document is Snowflake's Sub-processor and Affiliates disclosure page, governing the engagement of third-party data processors and Snowflake-affiliated entities authorized to process Customer Data in connection with Snowflake's cloud data platform services, with Standard Contractual Clauses (SCCs) serving as the stated transfer mechanism for all listed entities. The document states that customers with an executed Data Processing Agreement (DPA) may object to a new Third-Party Sub-processor by notifying privacy@snowflake.com within twenty-eight days of Snowflake's notice of such new sub-processor, with objections handled as described in the applicable DPA. The document identifies three primary cloud infrastructure sub-processors (Amazon Web Services, Microsoft Azure, and Google Cloud Platform) as customer-selected for hosting and infrastructure, with Cloudflare listed as an optional sub-processor for R2 cloud storage in connection with the Egress Cost Optimizer feature, and AWS additionally engaged for specific feature-level functions including Data Clean Rooms, native app security scanning, and cross-region inference for the Cortex feature. This disclosure engages the EU General Data Protection Regulation (GDPR), specifically the requirements of Commission Decision (EU) 2021/914 SCCs including Clause 14(c) third-country assessment obligations, as well as the UK International Data Transfer Addendum issued under the Data Protection Act 2018; customers in EU, EEA, and UK jurisdictions face heightened compliance obligations when evaluating cross-region data flows, particularly for Cortex cross-region inference functionality which routes data across AWS, Azure, and GCP regions. Compliance teams should note that Clause 14(c) assessments for applicable third countries are available only upon request to privacy@snowflake.com, requiring affirmative action by customers to obtain transfer impact documentation necessary for their own GDPR accountability obligations.
Institutional analysis available with Compliance
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.
Get ComplianceEvery distinct legal provision identified in this document. Featured provisions appear above with analysis.
Monitoring
Snowflake has updated this document before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Compliance Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Get ComplianceCross-platform context
See how other platforms handle AWS authorized as cloud hosting sub-processor and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.