Data ownership and export questions for compliance software buyers
“You own your data” sounds reassuring but does not explain what a customer receives when a contract ends. A compliance system may hold files, decisions, status histories and relationships among people, sites and assets. A flat file export without those connections can be hard to use for an audit or migration. Buyers should test the exit task before they become dependent on the platform.
This guide is a focused procurement checklist. It does not claim that any particular Complys export feature exists. The general software-selection guide briefly raises data questions; this page owns the detailed contractual and practical exit test.
Inventory the evidence you would need back
Choose representative records: a contractor approval with attachments, a training history, an inspection finding with corrective action and a superseded risk document. List the data fields, versions, files, comments, dates, decision makers and links among records needed to understand each case. Some information may be stored in a third-party integration or external file store; identify those dependencies.
Ask whether the customer can retrieve the material during ordinary use, during a dispute and at termination. Those may be different processes and costs. A screenshot of an export menu does not answer whether a former worker's evidence or a closed action can be reconstructed after migration.
Specify format and completeness
Ask the supplier what formats it can provide, whether attachments retain meaningful names, how identifiers connect related files and records, and whether version history and timestamps are included. Test a sample export in software outside the platform. Can a reviewer read it without a supplier account? Is a data dictionary supplied? Do characters, dates and time zones remain interpretable?
Include the limitations in the decision record. A product may support a useful basic export but not a full historical reconstruction. The buyer can plan compensating work, negotiate a service or choose another system. What matters is an evidenced answer, not a claim that export is “easy.”
Put roles and exit terms in writing
Identify who is controller and processor for the personal data involved, recognising that not every record will have the same legal treatment. Where a processor acts for a controller, the ICO's contract guidance explains written terms, including return or deletion of personal data at contract end, subject to legal retention. Legal or privacy counsel should assess the actual arrangement.
Agree timing, assistance, format, fees and verification of the return. Define how long access remains available after termination, what happens to backups and how deletion is confirmed. Do not assume that “data ownership” alone settles copyright in templates, supplier analytics, aggregated statistics or third-party material; address those categories in the contract if they matter.
Run a small migration rehearsal
Before commitment, request a test using non-sensitive or appropriately protected sample data. Have a person who did not build the export reconstruct one case. Note missing attachments, lost relationships, undocumented codes and inconsistent dates. Ask the supplier to explain discrepancies and confirm whether the fix is already available or only planned. Keep the test result with the procurement decision.
Repeat the test when the implementation adds new modules or a large new data category. A contract can be sound on day one and incomplete after years of product changes. Assign an internal owner to maintain the exit inventory, not just the supplier contract.
For a product comparison, see how Complys works and ask the team to demonstrate exactly what can be retrieved from the current plan. No automated export, API, archival or deletion capability is promised by this guide.
Example: files export, but the decision history does not
A buyer tests a sample contractor case. The vendor exports the certificate PDFs and a CSV of contractor names, but the reason a certificate was rejected and the name of the later approver stay in the application. The buyer should record that the export is incomplete for its audit purpose. It may negotiate a service to include status history, change its internal archiving process or choose a different system. Calling the output a “full export” would conceal the operational risk. The buyer should test an old, closed case as well as a current one, because an export that works for live records may omit archived versions.
Questions about termination day
Who can request the export and how is identity verified? How many days does the customer have to retrieve data after termination? Are there extra charges for files or support? How will the parties reconcile a count of exported records against the platform's own count? Who confirms deletion or a lawful retention exception, and what happens to backups? The answers should be in the agreed commercial and data-processing documents, not a last-minute email from a support agent.
Keep an internal copy strategy proportionate
Not every customer needs a daily copy of every record. Decide which evidence would be hardest to reconstruct, how often it changes and how quickly the organisation would need it during an outage or supplier failure. Test the chosen backup or export routine periodically. Avoid collecting more personal data than the organisation can secure and justify merely because a bulk download is available.
Run a small sample export test with records that include attachments, status changes and user identifiers. Compare the output with the source screen and note anything that loses context. Ask what happens to records after contract end and which party is responsible for deletion, retention or transfer under the actual agreement.