Subprocessor Addendums for New Zealand Businesses: What SaaS Providers Should Include

Alex Solo
byAlex Solo11 min read

If you sell software to business customers, a subprocessor addendum is often where deals slow down. Customers want clear answers about who handles their data, where that data goes, and what happens if you swap vendors later. SaaS founders often make three avoidable mistakes: they copy overseas wording that does not fit New Zealand privacy expectations, they list subprocessors too vaguely, or they promise blanket customer approval rights that become unworkable as the product grows.

The result is messy contract negotiations, avoidable security questions, and pressure from enterprise customers before you sign. A well-drafted subprocessor addendum should explain your third party processing chain in plain English, fit with your main services agreement and privacy policy, and give customers enough transparency without freezing your operations. This guide explains what a subprocessor addendum means for New Zealand businesses, when you are likely to need one, what clauses SaaS providers usually include, and the practical mistakes that cause trouble later.

Overview

A subprocessor addendum is a contract document that explains when a service provider can use third parties to process customer personal information, and on what conditions. For New Zealand SaaS businesses, it usually sits alongside your main customer agreement, privacy documents, and security commitments.

  • define what counts as a subprocessor and what does not
  • identify current subprocessors and describe the services they provide
  • set rules for appointing replacement or new subprocessors
  • confirm the provider stays responsible for its subcontractors
  • cover offshore data transfers and privacy compliance
  • deal with customer notice, objections, and termination rights
  • align the addendum with your security, confidentiality, and data breach response clauses

What Subprocessor Addendum Means For New Zealand Businesses

A subprocessor addendum tells your customer how you use third party suppliers to deliver your software, and what legal protections apply when those suppliers handle personal information.

In SaaS, very few providers operate without third parties. You might host your platform with a cloud provider, use a customer support tool, rely on analytics software, or engage an email delivery platform. If those suppliers process customer data on your behalf, your customer will usually want that chain documented.

For New Zealand businesses, the issue sits closely with the Privacy Act 2020. Even where the customer is the main party collecting personal information from end users, your business still needs to handle that information carefully under your contract and operational setup. If data is disclosed offshore, that also raises extra questions about cross border handling, contractual protections, and what your own privacy statements say.

What is a subprocessor?

A subprocessor is usually a third party engaged by a service provider to process personal information for the purpose of delivering the service to the customer. The exact definition matters. If it is too broad, you may accidentally capture suppliers that never touch customer data. If it is too narrow, you may leave out core vendors that clearly do.

A practical definition often covers suppliers that:

  • process personal information received from the customer, or from the provider on the customer's behalf
  • help host, store, transmit, analyse, or support customer data
  • act under the provider's instructions in connection with the services

Some third parties should be carved out if they are not really acting as subprocessors in the contractual sense. Common examples can include payment processors acting as separate service providers, telecom carriers, or general professional advisers, depending on the arrangement.

Why customers ask for one

Enterprise customers, government related customers, and privacy mature SMEs often ask for a subprocessor addendum because they need visibility and control. Their own contracts may require them to know where personal information goes and who touches it. Their procurement teams also want leverage before they sign.

This is where founders often get caught. They assume a simple privacy policy is enough, or they rely on a short line in the main SaaS agreement saying subcontractors may be used. That may be technically true, but it rarely answers the customer's real concerns.

How it fits with other contract documents

Your subprocessor addendum should not sit alone. It needs to line up with the rest of your legal documents. If your customer terms say one thing, your privacy policy says another, and your addendum says something else again, negotiations get harder and trust drops quickly.

In practice, the addendum should be consistent with:

  • your master services agreement or SaaS terms
  • any data processing schedule or privacy schedule
  • your confidentiality clauses
  • your security commitments and incident response wording
  • your data retention and deletion provisions
  • your public privacy notices, where relevant

Customers will often read these documents together. If one document says data stays in New Zealand, but another silently relies on offshore hosting, that inconsistency can derail a deal.

Why New Zealand context matters

Many template addendums are drafted for the United States or Europe. They may refer to legal concepts, regulator expectations, or mandatory terms that do not translate neatly to New Zealand. Copying those forms without checking them can create awkward promises or internal contradictions.

For example, an overseas template may assume a particular overseas transfer mechanism, regulator filing process, or objection regime that your business cannot realistically operate. New Zealand businesses usually need wording that reflects local privacy law, your actual service model, and the commercial expectations of your customers.

When This Issue Comes Up

A subprocessor addendum usually becomes urgent when a customer asks hard questions during procurement, security review, or contract negotiation.

Many founders do not think about subprocessors until a larger customer sends over a vendor questionnaire. Suddenly you are asked to list every hosting, support, analytics, and infrastructure supplier that may access personal information. If your contracts and internal records are not ready, the sales process slows down fast.

Common founder moments

You are likely to need a subprocessor addendum in situations such as:

  • before you sign an enterprise SaaS deal with a larger New Zealand customer
  • when a customer asks for a data processing addendum and wants subprocessor terms included
  • when your product starts using offshore cloud or support providers
  • when you add AI, analytics, monitoring, or customer support tools that interact with user data
  • when your existing customer contract says you need to notify customers about new subprocessors
  • when you are trying to standardise procurement responses across multiple customers

As your business scales

The more your company grows, the more likely it is that a subprocessor addendum shifts from nice to have to expected. Early stage SaaS businesses often start with a simple stack and a small customer base. Later, they add more tools, more regions, and more complex support arrangements.

At that point, customers often want to know:

  • which third parties are essential to the platform
  • whether personal information leaves New Zealand
  • how new subprocessors are assessed
  • what happens if a customer objects to a new vendor
  • whether the provider remains liable if a subprocessor causes a privacy or security problem

If your business is selling online across multiple markets, these questions become even more common. New Zealand customers may be comfortable with offshore providers, but they usually expect transparency and sensible contractual controls.

During due diligence and investment

Subprocessor terms can also surface before you spend money on setup for a bigger funding round, partnership, or strategic contract. Due diligence often checks whether your customer contracts, privacy position, and vendor management process match your actual operations.

If your addendum says customers receive 30 days' prior notice of every new subprocessor, but your team regularly turns on new tools without legal review, that gap can become a due diligence issue. Investors and larger counterparties tend to focus on repeatability. They want to see that your legal position can scale with the product.

Practical Steps And Common Mistakes

A workable subprocessor addendum should give customers real transparency without locking your business into operational promises you cannot keep.

1. Define the scope carefully

Start with clear definitions. The addendum should say what customer data or personal information it covers, who counts as a subprocessor, and whether the document applies to all services or only certain modules.

Ambiguity creates negotiation friction. If a customer reads the term broadly and you read it narrowly, the disagreement usually appears later, after launch or during a security incident.

2. List current subprocessors in a usable way

Most customers want more than a bare company name. They want to understand the role each subprocessor plays and where processing may occur.

A practical list usually includes:

  • the subprocessor's name
  • the service or function provided, such as cloud hosting, customer support, email delivery, analytics, or error logging
  • the relevant processing location or region, where known
  • whether the subprocessor may access or store personal information

You do not need to overcomplicate the list, but you do need enough detail for a customer to assess risk sensibly.

3. Set a realistic appointment process for new subprocessors

You will probably change vendors over time. The addendum should explain how you can appoint replacement or additional subprocessors, what notice you will give, and what happens if a customer objects.

This clause often causes the biggest commercial problems. Some customers ask for prior written consent before any new subprocessor is appointed. For most SaaS businesses, that is too restrictive. It can make ordinary operational changes almost impossible.

A more workable model may include:

  • advance notice of material new subprocessors
  • a defined objection period
  • objections limited to reasonable privacy or security grounds
  • a process for discussing alternatives
  • a right for the customer to terminate the affected services if no reasonable solution is available

The right balance depends on your customer base and bargaining position. The key is to avoid promising an approval process that your team cannot administer consistently.

4. Confirm you remain responsible

Your customer will usually expect your business to stay responsible for acts and omissions of subprocessors related to the services. That does not always mean accepting unlimited liability, but it usually means you cannot simply point to the third party and walk away.

Your addendum should make clear that you impose written obligations on subprocessors that are appropriate to the nature of the processing. Those obligations commonly cover confidentiality, security, use restrictions, and assistance with deletion or return of data where relevant.

5. Deal with offshore data handling honestly

If your subprocessors host or access personal information outside New Zealand, say so clearly. Trying to gloss over offshore processing is a common mistake, especially where founders assume cloud hosting location is a technical rather than legal question.

Customers usually want to know:

  • which countries or regions are involved
  • whether support staff can access data from other jurisdictions
  • what contractual protections apply to those transfers
  • whether your own customer contract permits that offshore disclosure

This point also needs to align with your privacy disclosures. If your business tells customers one thing in the addendum and something else in your privacy policy, trust erodes quickly.

6. Match the addendum to your security wording

A subprocessor addendum should not promise security standards that differ from the rest of your contract set. Customers often compare your security schedule, confidentiality obligations, and subprocessor wording line by line.

Make sure the documents answer the same practical questions, such as:

  • who can access the data
  • what controls you require from vendors
  • how incidents are escalated
  • what assistance you will provide after a breach or unauthorised access event
  • how and when data is deleted at the end of the relationship

7. Keep your vendor list and internal process current

The legal drafting matters, but the operational process matters just as much. If your engineering or product teams can activate new tools without anyone checking whether they handle customer personal information, your addendum can become inaccurate quickly.

A simple internal process usually helps, including:

  • a central list of approved vendors
  • privacy and security review before a new tool is adopted
  • a legal check before customer facing commitments are changed
  • clear ownership for customer notices and contract updates

Common mistakes New Zealand SaaS businesses make

The same drafting and process errors appear again and again.

  • copying an overseas subprocessor addendum without adapting it to New Zealand law or the actual product
  • using inconsistent definitions across the SaaS agreement, privacy policy, and addendum
  • failing to mention key hosting or support providers
  • promising customer consent rights for every vendor change
  • ignoring offshore transfer issues because the vendor is well known
  • treating all vendors as if they are subprocessors, even where they are not
  • forgetting to update the list when tooling changes

These mistakes are usually fixable, but they are easier and cheaper to sort out before you sign a large customer contract.

What a good subprocessor addendum usually includes

The exact terms depend on your service model, but a useful subprocessor addendum commonly covers:

  • definitions and scope
  • authority to appoint subprocessors
  • a current subprocessor list or schedule
  • obligations imposed on subprocessors
  • provider responsibility for subprocessors
  • notice and objection process for new subprocessors
  • offshore processing and transfer wording
  • deletion, return, and termination mechanics where relevant
  • consistency with the main agreement and privacy documents

If your business handles more sensitive data, sells to larger organisations, or works across several regions, you may also need more detailed drafting around audits, certifications, or incident cooperation. The right level of detail depends on your customer profile and your actual delivery model.

FAQs

Do all SaaS providers need a subprocessor addendum?

No. Some smaller providers can address the issue in their main services agreement or privacy schedule. A standalone subprocessor addendum becomes more useful where customers expect a separate document, you use multiple third party processors, or procurement teams want a clear schedule and notice process.

Is a subprocessor the same as an ordinary supplier?

No. A supplier is only a subprocessor if it processes customer personal information on your behalf in connection with the services. Many suppliers never handle customer data at all, and some may act independently rather than under your instructions.

Do New Zealand businesses need to tell customers about offshore subprocessors?

Often yes, at least as a practical and contractual matter. If customer personal information is stored, accessed, or processed overseas, customers usually expect that to be disclosed clearly in the contract set and reflected consistently in your privacy messaging.

Can customers object to a new subprocessor?

They can if the contract gives them that right. The more practical approach is usually to allow objections on reasonable privacy or security grounds within a set time, rather than requiring individual approval for every operational change.

Can we just use a UK, EU, or US template?

Not safely without review. Overseas templates often contain legal assumptions, transfer language, and notice mechanics that do not match New Zealand law, your sales process, or your actual vendor setup.

Key Takeaways

  • A subprocessor addendum explains when your SaaS business can use third parties to process customer personal information and what protections apply.
  • New Zealand SaaS providers should align the addendum with the Privacy Act 2020, offshore data handling, and the rest of their contract documents.
  • The most important clauses usually cover definitions, current subprocessors, appointment of new subprocessors, notice and objection rights, provider responsibility, and security obligations.
  • Founders often get into trouble by copying overseas templates, listing vendors too vaguely, or promising approval rights they cannot operate in practice.
  • Your legal wording needs to match your internal vendor management process, otherwise the addendum can become inaccurate as your product stack changes.

If your business is dealing with a subprocessor addendum and wants help with SaaS customer contracts, privacy compliance, offshore data handling terms, and vendor-related contract review, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

When should you formalise this?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.