Data Governance Due Diligence: Retention, Subprocessors & Residency
Privacy diligence asks whether a company respects the rights of the people in its data. Data governance diligence asks a more operational question: does the company actually know what data it holds, where it lives, who it hands it to, and when it is deleted? For a vendor or an acquisition target, weak governance is where privacy promises quietly fall apart — and where an acquirer inherits a data estate no one has fully mapped.
Retention: how long, and why
A company that keeps everything forever is carrying risk, not value. Good governance defines how long each category of data is kept and on what basis, and enforces deletion when that period ends. In diligence, look for a stated retention schedule rather than an open-ended "as long as necessary." Indefinite retention magnifies the damage of any breach and often sits at odds with the minimization principles that privacy law now expects. The absence of a retention policy usually means data accumulates by default.
Subprocessors: the data supply chain
Modern products run on other people's infrastructure — cloud hosting, analytics, support tooling, payment processors. Each is a subprocessor that touches the company's data, and each is a link in a chain the acquirer takes on. A company that publishes a current subprocessor list, names who each one is and what they do, and commits to notifying customers of changes is demonstrating governance. Silence about subprocessors, for a product that obviously uses them, is a gap: the data is flowing to third parties whether or not anyone is tracking it.
Data residency and localization
Where data physically lives has become a contractual and regulatory question. Enterprise customers increasingly require that their data stay in a particular region, and some jurisdictions mandate localization outright. Check whether the company can state where customer data is stored and processed, and whether it offers regional options where its market expects them. A company that cannot answer "where does our data live" has a governance gap that will surface the first time a large customer or regulator asks.
The DPA and the paper trail
A data processing agreement (DPA) is the document that binds a company to handle customer data on defined terms — purpose limits, security commitments, subprocessor rules, breach notification and deletion on termination. Whether a company offers a DPA, and what it commits to inside it, is a strong governance signal. For an acquirer, the target's DPA obligations to its own customers become obligations the combined company must keep honoring.
Access, classification and ownership
Governance also lives inside the company. Is data classified by sensitivity so the important categories get stronger controls? Is access limited to those who need it, rather than open to everyone? Is there an owner accountable for the data program? These are harder to verify from the outside, but a company that describes classification, access control and a named owner is signaling that data is managed deliberately rather than sprawling unowned across systems.
Exit: getting data back and out
The end of a relationship is where governance is tested. A well-run company commits to returning or deleting customer data on termination, within a defined window, and can prove it. For a vendor review, weak exit terms mean data may linger in systems you no longer control; for an acquisition, unclear deletion practices mean inherited data that should have been purged long ago.
Governance is the test of the promises
Policies describe intentions; governance is whether those intentions are operational. Retention that is enforced, subprocessors that are tracked, residency that can be stated, and deletion that actually happens are what separate a company that manages its data from one that merely writes about it. Use the public disclosures to score the posture and flag the gaps, then verify the high-stakes items directly. This is general information, not legal advice.