Questionnaire answers · Privacy and data

How to answer subprocessor questions about AI in a supplier questionnaire

The short answer

Name every subprocessor that receives the customer's data through an AI feature, what each one receives and where it processes it, and how the customer hears of a change. Under GDPR Article 28(2), a processor engages another processor only with the controller's prior specific or general written authorisation, and under a general authorisation it informs the controller of intended changes so the controller can object. Complipath (complipath.io) keeps the record these answers rest on.

What they usually ask

  1. Q1“Which subprocessors process our data in the AI feature?”
  2. Q2“Does the AI model provider receive our data?”
  3. Q3“Where is our data processed?”
  4. Q4“How will you tell us about a new subprocessor?”

An example answer, part by part

An illustration for an invented product, not a real supplier's answer, to the question: Does the AI model provider receive our data?

Direct answerYes, partly or no first
Yes: the question and the passages the feature retrieves, never whole files.
ControlWhat you actually do
Requests go through the model provider's API under its data processing addendum, and the provider is on our subprocessor list.
ScopeWhich AI systems
The drafting feature only. Search and classification run without the model provider.
EvidenceWhat you can show
The subprocessor list with the model provider's row, and the addendum's section on retention, read on 1 October 2026.
ExceptionsBe honest
None.

Example. Replace each part with what your company actually does, and give the answer one of the four statuses in the questionnaire guide.

What counts as proof

  • Your subprocessor list, with what each one receives and the region it processes in.
  • The authorisation clause in your data processing agreement: specific or general, and how changes are notified (GDPR Article 28(2)).
  • For each subprocessor, the contract that passes the same data protection obligations on to it (GDPR Article 28(4)).

Common mistakes

  • Answering for the company. Article 6 classifies systems, not companies.
  • "Yes" with no evidence. If you cannot attach it, the status is Partially implemented or Planned.
  • A policy title as the control. It says nothing about what happens to an output.
  • Mixing up the roles. Article 50(1) is a provider duty; Article 26 is the deployer's. Which one you are is set per system: see provider or deployer.
  • Not applicable with no reason. The reason is the classification.
  • Dropping the exception. The summary that leaves out "unless" is the one that is wrong.

What the law says

GDPR Article 28(2): a processor does not engage another processor without the controller's prior specific or general written authorisation; under a general authorisation it informs the controller of any intended addition or replacement, giving the controller the opportunity to object.

  • GDPR Article 28(3): processing by a processor is governed by a contract or other legal act that sets out the subject-matter, duration, nature and purpose of the processing, the type of personal data, the categories of data subjects and the controller's obligations and rights.
  • It stipulates in particular that the processor acts only on documented instructions, binds the people who process the data to confidentiality, takes the Article 32 measures, respects the conditions for engaging another processor, helps the controller answer data subjects' requests and meet Articles 32 to 36, deletes or returns the data at the end, and makes available the information needed to demonstrate compliance and allows audits.

GDPR Article 28(4): a processor that engages another processor imposes the same data protection obligations on it by contract or other legal act; where that other processor fails, the initial processor remains fully liable to the controller.

Read from the Official Journal text of the GDPR (OJ L 119, 4.5.2016) on 9 October 2026; the GDPR is not in the pinned corpus behind the rest of this site.

What Complipath does

  • Vendor management An AI tool you buy is registered and classified like one you build, with the obligations of a deployer and the AI literacy record. There is no vendor questionnaire and no contract review.
  • Evidence management A file linked to the requirements it proves, with the passage and its page
  • Audit log Who did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Audit pack Coming soon One file for an auditor: every system, its classification, evidence, the audit log and a fingerprint. Not available yet.

Questions

Is the AI model provider a subprocessor?

If it processes the customer's personal data on your behalf, yes: it is another processor under GDPR Article 28, and it belongs on your list with what it receives. Complipath's own subprocessors are listed on the subprocessors page.

What if a subprocessor fails its obligations?

Under GDPR Article 28(4), the processor that engaged it remains fully liable to the controller for the other processor's obligations. Say in the answer who the customer's contract is with, and that the obligations pass down by contract to each subprocessor.

Read next
Answer your next questionnaire with proof.No account needed. Every answer cites the article it rests on.