
Analysis
By Marta Reinders
Published on September 7, 2026
Two documents decide whether a European buyer can audit an AI vendor's data path, and procurement teams routinely treat them as one. A data processing agreement sets the rules. A sub-processor list names the companies those rules have to reach. Of the 83 vendor records in this registry, 69 publish a DPA, and 13 publish nothing that identifies where their sub-processors sit. The contract is close to universal. The roster is not.
A DPA is the contract between you, as controller, and the vendor, as processor. It fixes the subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of data subject. It then binds the vendor on the things you cannot check from outside: confidentiality, security measures, assistance with data subject requests, deletion or return of the data when the contract ends, and your right to audit.
It also governs the chain. Under the GDPR a processor may not engage another processor without your written authorisation, and where that authorisation is general rather than specific, the processor owes you notice of intended changes and an opportunity to object. The DPA is where that mechanism is written down. It is not where the names are.
The grades show how little the contract on its own separates vendors.
DPA published | Records | Median score |
|---|---|---|
Yes | 69 | 56 |
No | 8 | 42 |
Structurally not applicable | 5 | 95 |
A published DPA puts a vendor on the registry median of 56. It is a floor, not a distinguishing feature. The eight records with no published DPA sit well below it, at a median of 42: Replicate is the clearest case, with no DPA, no sub-processor list, no trust centre, and a privacy policy that names categories of service provider but not one company. The five records where a DPA is structurally not applicable are the highest scoring group in the registry, at a median of 95, and that is not a paradox. Whisper, self-hosted, Continue and Nextcloud's Assistant have no processor to contract with, because nothing leaves the operator's own hardware. One further record has no value recorded for this field.
A sub-processor list is disclosure, not a legal instrument. It is how the notice half of general authorisation gets delivered in practice, and it is the only routine way to learn which companies actually touch your prompts, your recordings or your code.
A useful list does four things, and the registry has a clean example of each:
General authorisation is the norm here, and it is the model every US vendor in the registry uses: publish a list, give notice before changing it, allow an objection. Exoscale writes the stricter version into its DPA and appoints no sub-processor at all unless the customer authorises it first, with a right to terminate if the customer objects.
The clause and the roster are separable, which is worth checking rather than assuming. Poolside has a DPA that defines an authorised sub-processor approval mechanism and publishes no roster to go with it. The mechanism is real, and there is nothing to run it against.
Where the chain sits and whether the vendor will say are recorded separately, and the methodology scores them as separate inputs.
Sub-processor jurisdiction | Records | Median score |
|---|---|---|
Undisclosed | 13 | 34 |
Non-EU | 32 | 52 |
Mixed | 15 | 58 |
EU only | 7 | 80 |
Vertically integrated EU | 5 | 86 |
Structurally none | 11 | 93 |
Two things in that table are worth separating. A fully disclosed American chain has a median of 52, which is a mediocre result for a European buyer but an assessable one: you know the entities, you know the jurisdiction, and you can price the risk. An undisclosed chain has a median of 34, and 11 of the 13 undisclosed records fall in the registry's low band. The A band contains none of them.
Missing disclosure is rarely a refusal, and it is not evidence of bad practice. It is absence of evidence, which for a regulated buyer produces the same procurement answer.
Each of those vendors publishes a stated position on training. None of them lets you see who would be bound by it.
A published list covers what the vendor says it covers, and that is often not the inference path.
The corollary matters for the good cases as much as the bad ones. Otter's page is the strongest in its category, and what it discloses is that the entire supply chain is American. That is a service to the buyer, not a mark against the vendor. A vendor that publishes a bad answer has told you something. A vendor that publishes nothing has told you only that the assessment cannot be completed.
For each AI vendor already in production:
This article was researched and written by an automated pipeline from the Sovereign AI Registry's own data, then published without human review. Every figure is computed from the registry's live records. Corrections: open an issue.