An AI vendor data privacy checklist for procurement: what to ask about training data, sub-processors, SOC 2, residency and exit terms before you sign.
An AI vendor data privacy checklist should be sitting on your desk before you approve budget for a chatbot platform, CRM AI add-on, or any tool touching customer data. Most businesses skip this step, evaluating vendors on features, price, and how slick the demo looked, then discover months later that the vendor trains its models on customer conversations, routes data through undisclosed sub-processors, or makes it nearly impossible to delete data on exit.
TL;DR: Before signing with any AI vendor, get written answers on five things: whether your data trains their models, who their sub-processors are, what compliance certifications they hold (SOC 2, GDPR), where your data is stored, and how deletion works if you leave. IBM’s 2025 Cost of a Data Breach Report found breaches involving unsanctioned “shadow AI” tools added USD 670,000 to the average breach cost. Vendor due diligence at the buying stage is cheaper than any of that.
The Cost of Skipping Due Diligence
IBM’s 2025 Cost of a Data Breach Report, based on Ponemon Institute research across 600 breached organisations, found that a high level of shadow AI use added USD 670,000 to the average cost of a breach. Nearly two-thirds of shadow-AI-linked breaches exposed customer personal information, and 63% of the organisations studied had no AI governance policy at all.
That figure covers unsanctioned tools employees adopt on their own. A formally procured vendor is not automatically safer. Skip the questions before signing and you get a sanctioned version of the same exposure, with a contract that may not even protect you when something goes wrong. Procurement is the point of highest leverage: the one moment you can demand answers and audit rights before the vendor has your data at all.
Data Use and Model Training: Get This in Writing
The most-skipped question is also the most important one: does the vendor use your inputs, outputs, or customer data to train or fine-tune its models, and can you opt out contractually, not just through a settings toggle that changes with a product update?
Ask whether customer data trains models by default and whether opt-out is written into the contract, whether the vendor distinguishes real opt-out from “anonymised” data still used behind the scenes, and, where a sub-processor such as a foundation model provider has different training terms, which terms actually govern your data. A demo answer of “we take privacy seriously” is not an answer. You want the clause number in the Data Processing Agreement, not a marketing page.
Sub-Processors, Certifications, and Data Residency
Every AI product runs on other companies’ infrastructure: a cloud host, a foundation model API, sometimes a transcription or embeddings vendor bolted on top. Each is a sub-processor with access to your data, usually buried in an appendix nobody reads.
Request a current sub-processor list with notice before new ones are added, a SOC 2 Type II report rather than Type I (Type I only proves controls exist on paper; Type II proves they worked over time), confirmation of where data is stored and whether it leaves that region, and a documented breach notification timeline rather than a vague “as required by law.”
This matters more in 2026 than it did two years ago. Under Australia’s Privacy Act reforms, businesses using AI or algorithmic systems to make or materially influence decisions about individuals must disclose that use in their privacy policy from 10 December 2026. If your AI vendor makes decisions about customers on your behalf, that disclosure obligation is yours, which is exactly the question our strategy and advisory engagements now start with, before implementation.
Exit Terms: What Happens When You Leave
Vendors sell you on getting started. Almost none volunteer what happens when you leave, and that is precisely the clause you need before you sign, not after you’ve decided to switch providers.
Confirm in writing how long your data is retained post-termination, whether deletion is automatic or requires a written request, whether backups are purged too, and whether you can export data in a usable format rather than a proprietary dump. If the contract is silent on deletion timelines, assume the vendor keeps your data indefinitely, because nothing obligates them not to. For any tool wired into operational workflows, an AI automation review is worth running first, mapping which systems the tool touches and what “delete our data” means once it has synced into three other platforms.
Your AI Vendor Data Privacy Checklist
This works best as a short document you bring to every vendor call, not a mental list. Cover model training and opt-out rights, the full sub-processor chain, SOC 2 Type II and GDPR posture, data residency, breach notification timelines, and exit and deletion terms with a specific number of days attached. If a vendor cannot answer one of these in writing within a sales cycle, treat that as the answer.
None of this slows AI adoption in any real way. Working through an AI vendor data privacy checklist makes the decision defensible later, and costs far less than the alternative. A breach traced back to an AI tool nobody vetted is not hypothetical anymore, and 2026’s regulatory environment gives it a paper trail too.
If you are about to sign with an AI vendor and want a second set of eyes on the contract first, that is the kind of technology assessment we run. Talk to us about a strategy and advisory review before you commit.
Frequently Asked Questions
What should I ask an AI vendor about data privacy before signing a contract?
Ask whether your data trains their models and whether you can opt out contractually, who their sub-processors are, whether they hold a current SOC 2 Type II report, where data is stored, and what happens to it on exit, including deletion timelines. Get every answer in writing.
What is shadow AI and why does it matter for vendor selection?
Shadow AI is AI tools employees adopt without IT or security approval. IBM’s 2025 Cost of a Data Breach Report found breaches linked to shadow AI added USD 670,000 to the average breach cost, largely because these tools sit outside governance and access controls. Vetting vendors before signing avoids creating a sanctioned version of the same risk.
Do Australian businesses need to disclose AI use to customers in 2026?
Yes. Under Australia’s Privacy Act reforms, businesses using AI or algorithmic systems to make or materially influence decisions about individuals must disclose that use in their privacy policy from 10 December 2026. If a vendor’s AI tool makes decisions about your customers, you need their cooperation to meet this obligation.
What is a sub-processor and why does it matter for due diligence?
A sub-processor is any third party the vendor relies on, such as a cloud host or foundation model provider, and each one gets some access to your data. Ask for a current list and notice before new ones are added, since a vendor’s own privacy terms don’t automatically bind its sub-processors.