Vendor offboarding for small teams: the data deletion checklist

Cancelling a SaaS subscription is a two-click operation. Offboarding the vendor — making sure they stop holding your customer list, your documents, your API access, and your billing card — is a different job, and almost nobody does it. The result shows up a year later as a surprise: the "cancelled" tool still appears in your SSO dashboard, its API key still works, and its privacy policy still says it retains customer data. If you passed the cyber insurance application questions about third parties, that ghost vendor is exactly the exposure the underwriter was asking about.

This checklist takes one afternoon per vendor and leaves you with three artifacts: an export, a written deletion confirmation request, and a dated record that the door is closed. Run it before the renewal date — the order matters.

1. Read the exit clause before you send the cancellation email

Every lever you have was agreed at signing, in the contract and the data processing agreement (DPA). Before cancelling, find and note:

2. Export what you own, while you still have admin

The day admin access ends, so does your leverage to get data out. Export on your schedule, not the vendor's:

Store the export where your backups actually run — an export sitting inside the same vendor's cloud is not a backup, it's a copy with the same failure mode.

3. The untangle list: everything that connects you to them

Vendors don't connect by password alone. Walk this list before you cancel, because half of it breaks silently:

4. Revoke everything that opens a door

Access offboarding follows the same logic as employee offboarding — same order as a leaver, but the account is the vendor's:

5. The deletion request, in writing, with a date

Don't assume cancellation deletes data. Send a short deletion request referencing the contract, and ask for specifics:

6. Verify instead of trusting

Offboarding fails at the verification step because it happens after everyone stopped caring. Three cheap checks:

7. The paperwork (ten minutes, saves the next argument)

Keep one record per vendor exit: who approved it, the cancellation date, the export location, the deletion request, and the confirmation (or the follow-up you still owe). This is the same discipline as the incident changelog — the record exists so a future you doesn't re-litigate a decision from memory.

The failure modes this checklist exists for

The pattern: an exit is complete when access, data, and billing are all three verifiably closed — not when the subscription stops charging. Vendors you keep get an annual review; vendors you fire get an exit record. The only bad vendor relationship is the one you can't prove is over.

The decision to fire a vendor gets made on the vendor renewal calendar, at T−60 while cancellation is still cheap; this checklist is what runs in the thirty days after that decision.

Need all of it at once? The Ops Mega Bundle collects all five ops kits in one download — $29.