Compliance
Do I have to list third-party processors in my privacy policy
What 13x checks
This is rule compliance.subprocessors in the public registry: Third-party processors are disclosed. It runs on every audit, against the pages we actually fetched, and its result is derived from the response rather than estimated.
- Surface
- Compliance
- Score weight
- 6 of the readiness score
- Scope
- Runs on every audited page
- Applies
- Only where the market or the page shape makes it relevant
Registry version 2026-07-30. Every rule is published, and the audit is deterministic — the same page produces the same finding every time.
The fix
The same text the audit hands you when this check fails on your own site.
third-party origins load on your site, but the privacy policy does not appear to mention third parties or recipients.
Art. 13(1)(e) GDPR requires you to name the categories of recipient of personal data. Every one of these is a recipient, because loading a resource from them transmits the visitor's IP address:
- Analytics providers - Font and asset CDNs - Video embeds (YouTube, Vimeo) - Chat widgets and support tools - Payment processors - Error tracking
Add a section listing each service, what it processes, and where. A table works well, and many companies publish it as a separate subprocessor page that the policy links to.
13x does not generate legal text — this is a search for the relevant terms in your policy, not a judgement on whether the list is complete. A lawyer should confirm that part.
Does your site have this problem?
13x checks this and 112 others against your live URL in about 30 seconds. No account, and every finding comes with the fix for your framework.
No signup. Results in 30 seconds.
More compliance checks
- Does my site need a privacy policyPrivacy policy is linked
- Does my website need an ImpressumImpressum is linked and reachable
- My analytics fires before consentNo trackers fire before consent
- Do I need a cookie consent bannerConsent banner present when third-party scripts load
- Is loading Google Fonts from the CDN a GDPR problemNo fonts loaded from Google's CDN
- Does the privacy policy need to be called DatenschutzerklärungDatenschutzerklärung is a separate page