The contract ended.The citizens' data did not.
Exit is where most vendors are weakest, and where citizens are most exposed.
In one line: As a processor, the vendor should return data to the department and delete remaining copies, including backups and test environments, unless law requires retention. Contracts should specify this.
Handover is not finished until the last copy is gone.
The scene
The scheme's portal moved to a new vendor. The old vendor handed over the database. It kept the backups, the test environment, the analytics warehouse and three engineers' laptops.
Where the thinking breaks
Exit plans on day one
Write the exit plan at contract start: what returns, what deletes, where, by when, and who certifies.
Monday morning
- 01For each contract, list every environment holding data.
- 02Draft the exit and deletion plan.
- 03Agree certification with the department.
Questions, answered plainly
What happens to personal data when a government IT contract ends?
As a processor, the vendor should return data to the department and delete remaining copies, including backups and test environments, unless law requires retention. Contracts should specify this.
Should vendors certify deletion?
Yes. A written certificate of deletion, covering all environments and backups, is good practice and evidences compliance.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner