Data processing agreements and sub-processors
In shortYour vendor's sub-processor list is the most honest dependency map you can get for free.
Every service processing personal data on your behalf needs a contract under Article 28 GDPR. Most companies sign it, file it and never read it again. That is a mistake, though not for the reason data protection training gives.
Why the document is interesting
Attached to every such contract is a sub-processor list: every company the vendor itself uses to deliver the service to you. The list is public, usually on a subpage of the vendor's site, and it is the one place a vendor has to disclose what it builds on.
That is where you learn the European SaaS vendor buys its compute from AWS, sends its mail through SendGrid and runs its support on Zendesk. Three US companies in the chain of a product marketed as "hosted in Germany". See Data residency and data sovereignty.
What to do with it
Take your ten most important services. Open the sub-processor list for each. Note two columns: company seat and processing location. That takes a morning and replaces most consultancy decks on this subject.
It also answers the question a tender clause like "data stays in Germany" never answers: does it stay there in the second row too?
The duty attached to it
Under Article 28 the processor must inform you of intended changes to sub-processors, and you may object. In practice the objection right is rarely exercised, because it effectively means terminating — but the notification itself is a free early-warning system for shifts in your supply chain.
If a vendor does not keep the list, or will not hand it over, that is information too. See Schrems II.