// Blog / Guide

What to check in a vendor's data terms

Share

Every tool you sign up for gets some of your data, and often your customers' data too. Yet almost nobody reads the terms, you click "I agree" and move on. Most of the time that is fine. But when a vendor holds personal or sensitive information, what their data terms actually say is your problem, because under Canadian privacy law you stay responsible for personal information even after you hand it to a supplier. You do not need to become a lawyer. You need to know the handful of things worth checking before you trust a tool with real data.

Why the terms are your problem

When you give a vendor personal information, you do not hand off the responsibility. If they lose it, mishandle it, or get breached, it is still your customers' data and, in the eyes of a regulator, still your obligation. That is why serious vendors offer a data processing agreement (a DPA): a document that spells out how they will handle the data you entrust to them. For anything touching personal or sensitive information, the presence and content of that agreement tells you a lot about whether a vendor is safe to rely on.

What to actually look for

  • Where your data lives. Which country is it stored and processed in? This matters for data residency and can trigger extra obligations, especially for sensitive data.
  • Who else touches it. Most vendors use their own subcontractors (subprocessors). You want to know they exist, that the vendor holds them to the same standard, and ideally that you will be told of changes.
  • What happens in a breach. Will they tell you, and how fast? You cannot meet your own breach-notification duties if your vendor sits on the news.
  • What they do with your data. Do they use it only to provide the service, or also to train their models or for their own purposes? For customer data, that distinction matters.
  • Getting your data back, and deletion. Can you export your data, and will they delete it when you leave rather than keep it indefinitely?
  • Their security commitments. Do they say anything concrete about how they protect the data, or nothing at all?

A sensible, non-lawyerly approach

Match the effort to the risk. For a tool that will never see personal data, a quick glance is fine. For anything holding customer, employee, financial, or health information, look for a real DPA and check the points above before you commit, and keep a simple record of which vendors hold what. This pairs with vetting a vendor's security: security tells you whether they can protect the data, the data terms tell you what they are actually promising to do with it. For a big or sensitive contract, a short review by a professional is money well spent.

Do you know what your key software vendors are actually allowed to do with your customer data? We help small businesses check vendor terms and security, so you are not carrying risk you never agreed to.

Talk to us

Related