20 Total
6 High severity
10 Medium severity
4 Low severity
Summary

This is Snowflake's official list of third-party companies and Snowflake-owned affiliates that may process Customer Data as part of delivering Snowflake's cloud data platform services. The document discloses four authorized third-party sub-processors (Amazon Web Services, Microsoft Azure, Google Cloud Platform, and Cloudflare), each engaged for specific infrastructure or feature-level purposes, with Standard Contractual Clauses as the transfer mechanism for all international data flows. Snowflake customers with an executed Data Processing Agreement may object to any newly added sub-processor by emailing privacy@snowflake.com within twenty-eight days of receiving notice of the change.

Technical / Legal Breakdown

This document is Snowflake's Sub-processor and Affiliates disclosure page, governing the engagement of third-party data processors and Snowflake-affiliated entities authorized to process Customer Data in connection with Snowflake's cloud data platform services, with Standard Contractual Clauses (SCCs) serving as the stated transfer mechanism for all listed entities. The document states that customers with an executed Data Processing Agreement (DPA) may object to a new Third-Party Sub-processor by notifying privacy@snowflake.com within twenty-eight days of Snowflake's notice of such new sub-processor, with objections handled as described in the applicable DPA. The document identifies three primary cloud infrastructure sub-processors (Amazon Web Services, Microsoft Azure, and Google Cloud Platform) as customer-selected for hosting and infrastructure, with Cloudflare listed as an optional sub-processor for R2 cloud storage in connection with the Egress Cost Optimizer feature, and AWS additionally engaged for specific feature-level functions including Data Clean Rooms, native app security scanning, and cross-region inference for the Cortex feature. This disclosure engages the EU General Data Protection Regulation (GDPR), specifically the requirements of Commission Decision (EU) 2021/914 SCCs including Clause 14(c) third-country assessment obligations, as well as the UK International Data Transfer Addendum issued under the Data Protection Act 2018; customers in EU, EEA, and UK jurisdictions face heightened compliance obligations when evaluating cross-region data flows, particularly for Cortex cross-region inference functionality which routes data across AWS, Azure, and GCP regions. Compliance teams should note that Clause 14(c) assessments for applicable third countries are available only upon request to privacy@snowflake.com, requiring affirmative action by customers to obtain transfer impact documentation necessary for their own GDPR accountability obligations.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance
Featured — High severity
Featured — Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

20 provisions
12 featured
5 clause types
6 high severity
data_sharing 10
contract_terms 4
disclosure_requirements 3
other 2
privacy_rights 1

Monitoring

Snowflake has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle AWS authorized as cloud hosting sub-processor and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 6, 2026 22:44 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000936
Version ID CA-V-004533
SHA-256 78a6e16dd3159fc2d602a3ee1c68e30dd1fd4b2c775842c21d2702f594f4f363
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans