49 Total
6 High severity
14 Medium severity
29 Low severity
Summary

This is Twilio's official list of third-party companies (sub-processors) that process personal data on behalf of Twilio's customers as of April 2026. The list includes approximately 35 entities spanning cloud infrastructure (AWS, Google, Microsoft Azure), AI functionality vendors (OpenAI, Anthropic, ElevenLabs), analytics and observability tools (Datadog, Clickhouse, Honeycomb), and communications delivery services (Sinch, Postmark, VoiceBase), each identified by applicable service, subject matter, processing purpose, and geographic location. A footnote discloses that while Regional Twilio customers may store Customer Content in Ireland or Australia, all other account and service usage data continues to be processed in the United States, with exceptions permitted for fraud and abuse investigations.

Technical / Legal Breakdown

This document is Twilio's Sub-Processor List (last updated April 2026), which discloses the third-party companies engaged to process personal data on behalf of Twilio customers, in accordance with customer instructions, and under written contracts imposing data protection obligations aligned with applicable data protection laws. The document states that Twilio imposes obligations on sub-processors to implement appropriate technical and organizational measures, that Transfer Impact Assessments have been performed where cross-border data transfers are required, and that customers may subscribe to notifications of sub-processor changes. The list spans approximately 35 third-party and Twilio Group sub-processors including infrastructure providers (AWS, Google, Microsoft Azure), AI vendors (OpenAI, Anthropic, ElevenLabs, Lakera), analytics platforms (Datadog, Clickhouse, Elastic), and communications delivery services (Sinch, Postmark, VoiceBase), with processing locations spanning the USA, EU member states, UK, South America, and Asia-Pacific regions. The document engages GDPR (including Standard Contractual Clauses and Transfer Impact Assessment obligations under Chapter V), UK GDPR, and potentially CCPA given the volume of personal data categories processed across US-based sub-processors; the footnote clarifying that Regional Twilio stores Customer Content in selected regions (Ireland or Australia) but that all other account data continues to be processed in the United States creates a material residual transfer exposure for EU and UK customers to evaluate. Compliance teams should note that the inclusion of AI vendors such as OpenAI, Anthropic, ElevenLabs, and Microsoft Azure as sub-processors for customer-defined workflows raises questions about onward transfer chains, sub-processor security assurance depth, and alignment with emerging EU AI Act obligations.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance
Featured — High severity
Featured — Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

49 provisions
12 featured
7 clause types
6 high severity
data_usage 23
data_sharing 12
ai_automated 7
data_retention 3
data_collection 2
disclosure_requirements 1
policy_changes 1

Monitoring

Twilio has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle Duration of processing tied to customer service use and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 6, 2026 22:44 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000933
Version ID CA-V-004531
SHA-256 eb0c920c72df0732ba3434b4acbc87ddf3cac2ad805f3e24639ec619d81bba39
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans