Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document lists the third-party companies and Snowflake affiliates that Snowflake is permitted to use to process customer data as part of its service. The three major cloud providers—AWS, Azure, and Google Cloud—are authorized as core infrastructure processors depending on which one a customer has selected. If Snowflake adds a new sub-processor, customers with a Data Processing Agreement have twenty-eight days to object by emailing privacy@snowflake.com.
This document establishes Snowflake's authorized sub-processor arrangements, identifying Amazon Web Services, Microsoft Azure, and Google Cloud Platform as customer-selected foundational cloud infrastructure sub-processors, and Snowflake's own affiliates as authorized sub-processors for technical services, support, and service management. Additional cross-cloud sub-processor authorizations govern specific features, including Cortex cross-region inference and the Data Clean Rooms Web App, in which data processed in one cloud provider's regions may be routed through a different provider's infrastructure. DPA customers retain a right to object to newly added sub-processors by notifying privacy@snowflake.com within twenty-eight days of Snowflake's notice, with the substantive handling of any such objection determined entirely by the customer's individual Data Processing Agreement. Information required under Clause 14(c) of the standard contractual clauses regarding third-country laws and practices is available only upon request to privacy@snowflake.com, not published proactively.
For an individual user, this document means that data stored or processed on Snowflake may be handled by AWS, Microsoft Azure, Google Cloud Platform, or Snowflake's affiliates depending on the cloud region selected and the features used—including routing through a different cloud provider for specific features like Cortex cross-region inference. If a new sub-processor is added and you are a DPA customer, you can object by emailing privacy@snowflake.com within twenty-eight days of Snowflake's notice; after that window closes, the ability to challenge the new sub-processor is governed solely by your individual DPA. You can also email privacy@snowflake.com to request information about third-country laws and practices under Clause 14(c) of the standard contractual clauses.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Snowflake has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle AWS authorized as cloud hosting sub-processor and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.