Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Business Users have 30 days from the date a sub-processor is added to this page to submit a written objection under the DPA. Failure to object within that window constitutes deemed acceptance of the new sub-processor appointment.
This analysis describes what Stripe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a time-limited objection mechanism that requires active monitoring of the sub-processor list by Business Users who wish to preserve their right to object under the DPA. The deemed-acceptance mechanism means that inaction within the 30-day window operates as contractual consent to the new sub-processor arrangement.
Under this clause, Business Users who do not submit a written objection to Stripe within 30 days of a new sub-processor being listed are treated as having accepted that appointment under the DPA. This provision requires Business Users to actively monitor the page or subscribe to email notifications in order to exercise the objection right within the specified window.
Cross-platform context
See how other platforms handle 30-Day Sub-Processor Objection Window with Deemed Acceptance and similar clauses.
Compare across platforms →Monitoring
Stripe has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Under the terms of our Data Processing Agreement (DPA), a Business User may reasonably object in writing to the processing of its personal data by a new Sub-processor within 30 days following the update of this page. If a Business User does not object during the 30 day time period, the appointment of the new Sub-processor shall be deemed accepted by the Business User.Excerpt from Stripe's Service Providers (Sub-Processors)
1. REGULATORY LANDSCAPE: This provision engages GDPR requirements applicable to controller-processor relationships, under which data processors are required to inform controllers of intended sub-processor changes and afford an opportunity to object. The Irish Data Protection Commission serves as Stripe's lead supervisory authority under GDPR's one-stop-shop mechanism. The deemed-acceptance construct must be evaluated against GDPR obligations on data controllers to maintain documented and auditable sub-processor consent records; national DPA guidance may vary on whether deemed acceptance through inaction satisfies controller accountability requirements. 2. GOVERNANCE EXPOSURE: Medium. The 30-day deemed-acceptance window creates an ongoing monitoring obligation for Business Users whose compliance programs require active sub-processor consent. For organizations with formal data processing inventories and DPA schedules, failure to detect and respond to page updates within the window may result in undocumented sub-processor relationships that conflict with their own downstream privacy notices or contractual obligations. 3. JURISDICTION FLAGS: Heightened exposure exists for Business Users subject to GDPR (EU and EEA), UK GDPR, and Swiss data protection law, each of which imposes sub-processor management obligations on data controllers. Business Users in regulated sectors such as financial services or healthcare may face additional requirements under sector-specific frameworks that go beyond the 30-day window construct. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement and vendor management teams should confirm that existing DPA schedules enumerate a process for tracking sub-processor list updates and logging objection decisions. The provision shifts the burden of active monitoring to Business Users; teams should assess whether the email notification subscription mechanism constitutes adequate operational controls for timely response. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should subscribe to Stripe's sub-processor update notifications, establish internal workflows to review new sub-processor additions within the 30-day window, and document the basis for acceptance or objection decisions. For Business Users who are themselves data controllers under GDPR, each newly accepted sub-processor may require an update to Article 30 records and, where cross-border transfers are involved, a transfer impact assessment.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes a time-limited objection mechanism that requires active monitoring of the sub-processor list by Business Users who wish to preserve their right to object under the DPA. The deemed-acceptance mechanism means that inaction within the 30-day window operates as contractual consent to the new sub-processor arrangement.
Under this clause, Business Users who do not submit a written objection to Stripe within 30 days of a new sub-processor being listed are treated as having accepted that appointment under the DPA. This provision requires Business Users to actively monitor the page or subscribe to email notifications in order to exercise the objection right within the specified window.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stripe.