Resources

What is a material change in a vendor agreement?

A material change is a vendor terms, privacy, or DPA edit that shifts your risk posture — the change your control framework assumes you'll catch.

Published 2026-07-21

A material change is an edit to a vendor's terms of service, privacy policy, or data processing agreement that meaningfully shifts your risk posture — as opposed to a typo fix, a re-worded sentence, or a formatting change. It is precisely the change your control framework assumes you will notice.

Why "material" is the hard part

Vendors change their legal documents constantly. The vast majority of edits are immaterial: a clarified sentence, an updated address, a reordered section. Buried among them are the few that matter — a new AI subprocessor, a broadened data-use grant, a shortened breach-notification window, a weakened deletion commitment. The work is not detecting that something changed; it is deciding whether this change moves your risk.

Examples of material changes

  • A new subprocessor, especially an AI or model provider.
  • A grant of rights to train on or reuse your data.
  • A change to breach-notification timelines.
  • A shift in data-retention or deletion terms.
  • A new international transfer arrangement.

Frameworks assume you catch these

GDPR Article 28, DORA, SOC 2, and ISO 27001 all assume you will know when a vendor materially changes. None of them monitor the documents for you. That gap — between the obligation to know and the ability to know — is exactly where continuous monitoring lives.

Driftline reads the change, uses AI to judge whether it is material, and surfaces the ones that move your posture — with the exact document diff behind every finding.

Which of your vendors can train on your data?

Send us your vendor list and we'll map — free, within 48 hours — which vendors add AI subprocessors or reserve the right to train on your data, and where your nth-party exposure concentrates.

Request your free AI exposure report