Is your vendor a subprocessor, a reseller or storing PII?
These three flags on the vendor form record how a vendor fits into your data-processing chain, and your auditor reads them against your subprocessor list and privacy disclosures. Check Is Subprocessor if the vendor processes your customers' data on your behalf, Is Reseller if you buy another company's product through this vendor instead of from them directly, and Stores PII if the vendor holds personal data about anyone. They're independent — a vendor can tick all three, one, or none.
How to decide which flags apply
Is Subprocessor: does it handle your customers' data?
A subprocessor is a third party that processes your customers' data on your behalf to help you deliver your service. The test is whose data it touches: your customers' data, not your own company's internal data. Your cloud host that stores your app's database is a subprocessor. Your accounting tool that only holds your company financials is not.

Is Reseller: are you buying through a middleman?
A reseller sells you another company's product or service rather than building it themselves. You pay the reseller; the actual software or service is operated by someone upstream. Check this when the company on your contract isn't the one that runs the product. It matters because the real data processor is the upstream provider — the reseller flag is a reminder that there's another party behind this vendor you may need to account for. If the reseller does more than pass along a license — it also hosts, supports, or manages the product for you — it can be a subprocessor too, so check both.
Stores PII: does it hold personal data?
PII — personal data — is anything that can identify a person, on its own or combined with other data. Names, emails (including work emails like [email protected]), phone numbers, and home addresses are the clear cases. Others depend on context: an IP address or an internal user ID can identify someone in one setting and not another, and the exact line shifts by privacy law — so when it's borderline, treat it as personal and let your privacy policy and counsel settle the edge cases. Check this if the vendor stores personal data about anyone — your customers, your employees, or your leads. "Stores" is broad: even holding it temporarily counts. Leave it unchecked only when the vendor sees nothing but fully anonymized or aggregate data that can't be traced back to a person.
Examples
The right answer follows from how you use a vendor, not its name. Each row assumes the typical use described — the same vendor lands differently if you use it differently (see the note under the table).
Vendor | Is Subprocessor | Is Reseller | Stores PII |
|---|---|---|---|
Cloud host running your app + database (AWS, GCP) | Yes | No | Yes |
Product analytics receiving your users' events (PostHog, Mixpanel) | Yes | No | Yes |
Helpdesk holding your customers' support tickets (Zendesk) | Yes | No | Yes |
Payroll / HR provider (Gusto) | No — it holds your employees' data, not your customers' | No | Yes |
IT partner reselling you software licenses, no access to your data (CDW, SHI) | No — the software vendor upstream is the subprocessor |
The payroll row is the one people get wrong: it clearly stores PII, but it isn't a subprocessor, because that data is your own company's, not your customers'. The two flags answer different questions — Is Subprocessor asks whose data and why (your customers', to run your product); Stores PII asks only whether any of it is personal, whoever it belongs to. So a vendor can be one without the other. It cuts both ways: a cloud host you use only for internal tools — no customer data on it — isn't a subprocessor either, exactly like payroll. The name never decides; what you put through it does.
When it's a judgment call
- "We only reach them through an API." Still counts. If your customers' data flows through their systems and they process it on your behalf to help deliver your service, they're a subprocessor — the integration type and pricing tier don't change that.
- Free tools. Free doesn't exempt a vendor. If a free tool holds personal data or processes your customers' data, check the flag.
- Anonymized or aggregate only. If a vendor can never tie its data back to a real person, leave Stores PII unchecked.
- More than one can apply. A single vendor can be both a subprocessor and store PII, or a reseller that also holds personal data. Check every flag that applies.
- When you're genuinely unsure, be honest and slightly over-inclusive. An extra name on your list is defensible; a missing one is a gap.
Why it matters / what your auditor expects
Your subprocessor list is something you disclose to your own customers — usually in a data processing agreement (DPA) or on a public subprocessors page — and auditors cross-check that list against your vendor inventory. Getting Is Subprocessor wrong means your published disclosure is wrong: you're either claiming a data-sharing relationship you don't have, or hiding one you do. A missing subprocessor is the kind of gap an auditor and your customers care about. These flags also help you prioritize reviews — a subprocessor that stores PII is higher-stakes than a company-only tool and deserves a closer look.
Common mistakes
- Treating "Stores PII" and "Is Subprocessor" as the same flag. A payroll tool stores PII but isn't a subprocessor. They're independent — decide each on its own.
- Leaving all three unchecked because you're not sure. Unchecked reads as a definite "no" to your auditor. Make the call.
- Skipping a vendor because you're on its free or API-only tier. The relationship decides, not the plan you pay for.
