Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document lists Anthropic, Amazon Bedrock, OpenAI, and Microsoft Azure as sub-processors for AI Products, each processing personal data contained in customer-defined workflows or communications, with primary processing in the USA and, for Microsoft Azure, also in the EU.
This analysis describes what Twilio's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The engagement of multiple AI vendors as sub-processors for personal data in customer-defined workflows creates layered processing chains in which the nature and extent of personal data processed by each AI vendor depends on the content of customer-configured workflows, and may require separate evaluation under GDPR, the EU AI Act, and applicable AI governance frameworks.
Interpretive note: The document describes AI vendor processing as covering 'personal data contained in customer defined workflows' without specifying which data categories are transmitted to each vendor, creating interpretive uncertainty about the scope of AI sub-processing for individual customer configurations.
Under these terms, personal data contained in customer-defined workflows processed through Twilio's AI Products may be transmitted to and processed by Anthropic, Amazon Bedrock, OpenAI, and Microsoft Azure in the USA or EU; the specific data categories processed depend on customer workflow configurations, and customers retain responsibility for ensuring their use of AI Products is consistent with their own data protection obligations.
Cross-platform context
See how other platforms handle AI Vendor Sub-Processors for Customer-Defined Workflows and similar clauses.
Compare across platforms →Monitoring
Twilio has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Anthropic All AI Products Personal data contained in communications sent through Flex. Vendor for AI functionality in product USA ... Amazon Bedrock All AI Products Personal data contained in customer defined workflows Vendor for AI functionality in product USA ... OpenAI All AI Products Personal data contained in customer defined workflows Vendor for AI functionality in product USA ... Microsoft Azure All AI Products Personal data contained in customer defined workflows Vendor for AI functionality in product USA, EUExcerpt from Twilio's Sub-Processors
1) REGULATORY LANDSCAPE: This provision engages GDPR Article 28 (sub-processor obligations), GDPR Chapter V (cross-border transfers for US-based AI vendors), and potentially the EU AI Act depending on the AI system risk classification applicable to customer-defined workflows. The processing of personal data by AI vendors for purposes defined by customer workflows may also engage national AI governance frameworks and sector-specific regulations in financial services, healthcare, or public sector contexts. Relevant enforcement authorities include EU member state supervisory authorities, the UK ICO, and emerging EU AI Act supervisory bodies. 2) GOVERNANCE EXPOSURE: High. The breadth of personal data categories potentially processed by AI vendors (described as 'personal data contained in customer defined workflows') means that the scope of AI sub-processing is largely determined by customer workflow configuration rather than defined data categories. This creates accountability exposure for customers who may not have fully mapped which personal data categories flow into AI-enabled Twilio services. The inclusion of multiple competing AI vendors for the same service category (OpenAI, Anthropic, Amazon Bedrock) may also create uncertainty about which vendor processes data for specific workflow executions. 3) JURISDICTION FLAGS: EU/EEA customers face heightened exposure given the US-based processing by OpenAI, Anthropic, and Amazon Bedrock and the requirements of GDPR Chapter V for valid transfer mechanisms. The EU AI Act's requirements for high-risk AI systems may impose additional obligations on customers using AI-enabled Twilio services for certain use cases. UK customers face parallel exposure under UK GDPR and the UK AI governance framework. 4) CONTRACT AND VENDOR IMPLICATIONS: Customers should review whether their DPA with Twilio covers the specific AI vendors listed and whether the security links provided (Claude by Anthropic, Amazon Bedrock, OpenAI security page) constitute sufficient due diligence documentation for their vendor risk management programs. The document does not specify data retention periods for AI vendor processing, which may require clarification in the customer's DPA or service agreement. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct data flow mapping to identify which personal data categories are transmitted to each AI vendor through customer-defined Twilio workflows. Privacy impact assessments should be updated to account for AI sub-processing, particularly for sensitive personal data categories. Customers should confirm that applicable transfer mechanisms are in place for US-based AI vendor processing and should monitor developments under the EU AI Act for obligations applicable to their specific AI workflow use cases.
The engagement of multiple AI vendors as sub-processors for personal data in customer-defined workflows creates layered processing chains in which the nature and extent of personal data processed by each AI vendor depends on the content of customer-configured workflows, and may require separate evaluation under GDPR, the EU AI Act, and applicable AI governance frameworks.
Under these terms, personal data contained in customer-defined workflows processed through Twilio's AI Products may be transmitted to and processed by Anthropic, Amazon Bedrock, OpenAI, and Microsoft Azure in the USA or EU; the specific data categories processed depend on customer workflow configurations, and customers retain responsibility for ensuring their use of AI Products is consistent with their own data …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Twilio.