@zanii/subprocessor
v0.2.0
Published
Prove the onward-transfer chain - which downstream processors actually saw the data, under which agreement (zero-retention, DPA id), tied to the junction/settlement. Answers the exact GDPR Art. 28 question every AI DPA raises: 'you sent my data to OpenAI,
Readme
@zanii/subprocessor
Which third parties actually touched it? The fear behind every AI DPA — "you sent my data to OpenAI, who sent it where?" This makes the onward-transfer chain a first-class provable graph: which downstream processors saw the data, under which agreement, tied to the junction. The exact GDPR Art. 28 answer.
npm install @zanii/subprocessor @zanii/coreimport { buildTransfer, verifyTransfers, subprocessorGraph } from '@zanii/subprocessor';
await zanii.record(buildTransfer({ from: 'controller', to: 'openai',
agreement: { type: 'zero-retention' }, ts: now, ref: dataRef }));
// verify the recorded onward chain against your DECLARED subprocessor list:
const r = verifyTransfers(transfers, ['openai', 'anthropic', 'stripe']);
r.ok; // false if data reached any party NOT on the declared list — a provable Art. 28 violation
subprocessorGraph(transfers, declared); // { parties, edges, undeclared, missing_agreement_id }Python: from zanii.subprocessor import build_transfer, verify_transfers, subprocessor_graph
The load-bearing check
Every to must be in the declared subprocessor list. A transfer to an undeclared party
is surfaced (undeclared) as a provable violation — discovered by the check, not after a
breach. dpa/scc transfers with no agreement id are flagged too. Composes
@zanii/data-custody's junction and @zanii/x402's settlement.
The limit, stated up front
Proves the transfers that were recorded. It cannot prove an off-record leak — a processor that received plaintext and emitted nothing (that's the enclave/broker problem). An agreement id is a reference, not a guarantee the counterparty honored it.
