20 Total
6 High severity
10 Medium severity
4 Low severity

Key Facts

Does Snowflake authorize Amazon Web Services as a customer-selected cloud hosting and infrastructure sub-processor?
Snowflake authorizes Amazon Web Services as a customer-selected cloud hosting and infrastructure sub-processor.
Does Snowflake authorize Microsoft Azure as a customer-selected cloud hosting and infrastructure sub-processor?
Snowflake authorizes Microsoft Azure as a customer-selected cloud hosting and infrastructure sub-processor.
How can DPA customers object to a new third-party sub-processor?
Snowflake permits DPA customers to object to a new third-party sub-processor by notifying privacy@snowflake.com within twenty-eight days after Snowflake's notice.
Does Snowflake authorize Google Cloud Platform as a customer-selected cloud hosting and infrastructure sub-processor?
Snowflake authorizes Google Cloud Platform as a customer-selected cloud hosting and infrastructure sub-processor.
Does Snowflake authorize its affiliates as sub-processors?
Snowflake authorizes its affiliates as sub-processors for the provision of technical services, support services, and supporting the provision, management, and maintenance of the Service.
How must sub-processor objections be handled?
Snowflake requires that sub-processor objections be handled as described in the customer's DPA.
Does Snowflake authorize Amazon Web Services as a sub-processor for the cross-region inference feature of Cortex serving Google Cloud Platform and Microsoft Azure regions?
Snowflake authorizes Amazon Web Services as a sub-processor for the cross-region inference feature of Cortex serving Google Cloud Platform and Microsoft Azure regions.
Does Snowflake authorize Amazon Web Services as a sub-processor for the Snowflake Data Clean Rooms Web App?
Snowflake authorizes Amazon Web Services as a sub-processor for the Snowflake Data Clean Rooms Web App.
Does Snowflake authorize Amazon Web Services as a sub-processor for native app security scanning for customer accounts in Google Cloud Platform regions?
Snowflake authorizes Amazon Web Services as a sub-processor for native app security scanning for customer accounts in Google Cloud Platform regions.
Does Snowflake authorize Microsoft Azure as a sub-processor for the cross-region inference feature of Cortex serving Google Cloud Platform and Amazon Web Services regions?
Snowflake authorizes Microsoft Azure as a sub-processor for the cross-region inference feature of Cortex serving Google Cloud Platform and Amazon Web Services regions.
Stay ahead of the changes
Track Snowflake and get the diff the day its terms change.
Summary

This document lists the third-party companies and Snowflake affiliates that Snowflake is permitted to use to process customer data as part of its service. The three major cloud providers—AWS, Azure, and Google Cloud—are authorized as core infrastructure processors depending on which one a customer has selected. If Snowflake adds a new sub-processor, customers with a Data Processing Agreement have twenty-eight days to object by emailing privacy@snowflake.com.

Analysis

This document establishes Snowflake's authorized sub-processor arrangements, identifying Amazon Web Services, Microsoft Azure, and Google Cloud Platform as customer-selected foundational cloud infrastructure sub-processors, and Snowflake's own affiliates as authorized sub-processors for technical services, support, and service management. Additional cross-cloud sub-processor authorizations govern specific features, including Cortex cross-region inference and the Data Clean Rooms Web App, in which data processed in one cloud provider's regions may be routed through a different provider's infrastructure. DPA customers retain a right to object to newly added sub-processors by notifying privacy@snowflake.com within twenty-eight days of Snowflake's notice, with the substantive handling of any such objection determined entirely by the customer's individual Data Processing Agreement. Information required under Clause 14(c) of the standard contractual clauses regarding third-country laws and practices is available only upon request to privacy@snowflake.com, not published proactively.

What this means for you

For an individual user, this document means that data stored or processed on Snowflake may be handled by AWS, Microsoft Azure, Google Cloud Platform, or Snowflake's affiliates depending on the cloud region selected and the features used—including routing through a different cloud provider for specific features like Cortex cross-region inference. If a new sub-processor is added and you are a DPA customer, you can object by emailing privacy@snowflake.com within twenty-eight days of Snowflake's notice; after that window closes, the ability to challenge the new sub-processor is governed solely by your individual DPA. You can also email privacy@snowflake.com to request information about third-country laws and practices under Clause 14(c) of the standard contractual clauses.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

20 provisions
12 featured
5 clause types
6 high severity
Stay ahead of the changes

Monitoring

Snowflake has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle AWS authorized as cloud hosting sub-processor and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 19, 2026 01:28 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000936
Version ID CA-V-005929
SHA-256 ab51c5e9883d9990a27d1e96619253fa8df12c17340fe296ecc0eaa4c4bd2a25
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans