/ THE SHORT ANSWER
- 01Follow logs and support access as well as primary storage.
- 02Determine roles from the actual service arrangement.
- 03Request evidence for deletion, access control and subprocessors.
- 04Define approved datasets and actions before onboarding users.
/ dotSuper point of view
AI procurement should approve an evidenced processing arrangement and allowed use, rather than a brand name or hosting label.
Start with one concrete use case
An assistant summarising public product manuals has different data needs from a service answering questions about employee absence.
Define the first task, its intended users and the records it needs.
List the actions the tool may perform.
Reading a document and sending its contents to a customer should be separate permissions.
Ask the business owner what success looks like without assuming every available feature must be enabled.
A narrower task can be easier to evaluate and may reveal that sensitive information is unnecessary.
Record prohibited inputs in practical terms.
For example, a purchasing assistant may use approved supplier specifications while excluding employee case files and unrelated customer drawings.
Users need examples they can recognise during normal work.
Follow data beyond the model request
Then add conversation history, usage logs, backups and support troubleshooting.
These secondary paths can change the procurement assessment.
The ICO's contracts guidance addresses processing instructions, confidentiality, security, subprocessors, assistance, end-of-contract arrangements and audit rights.[
1] Use those topics to request evidence, while having the actual terms reviewed for the service's roles.
Do not assume every provider component has the same role.
A business may process data on instructions for one activity and use some information for its own purposes elsewhere.
Ask for an activity-specific explanation.
Separate a supplier promise from a setting you can configure.
If retention depends on disabling history or selecting a particular service tier, document who applies the setting and how the business will detect later changes.
Assess transfers using organisational relationships
2] Procurement therefore needs to understand relevant recipients and access arrangements, not just a storage-region label.
Ask which organisation provides support and which entities operate downstream processing.
A map showing servers alone may omit the relationships needed to assess the arrangement.
Where a restricted transfer is identified, ask the responsible privacy adviser to determine the applicable route and supporting assessment.
Do not let a sales assurance that the product is compliant replace that work.
This does not mean every overseas connection is automatically prohibited.
It means the decision needs enough specific information to apply the correct rules and agree an acceptable service configuration.
Follow a hypothetical supplier-enquiry assistant
Some documents contain named contacts, phone numbers and commercial terms.
The initial demo uses public examples.
Before production use, the buyer asks how real files enter the index, whether deleted quotations remain in logs, and which support organisations can inspect a failed request.
The team removes personal contact details from the initial dataset because the task concerns specifications and price comparisons.
It keeps an authorised route to the original quotation for staff who need the contact.
Then it tests an intentionally unavailable document.
The assistant should explain the access limit rather than answering from a cached copy belonging to another user.
That behaviour is part of the purchasing evidence, not an optional polish item.
Turn supplier answers into an approval decision
Mark unanswered questions explicitly.
A partially completed questionnaire should not become a blanket approval because the trial account already exists.
Assign each unresolved item to a business, technical or privacy owner.
This prevents the IT manager from being asked to approve legal terms and the finance director from being asked to judge retrieval permissions alone.
The tradeoff may be accepting less functionality to obtain a clearer service boundary.
A tool that cannot meet the required retention or access controls might still be suitable for public information, subject to a separate decision.
Capture the approved configuration and dataset categories in the onboarding instructions.
Procurement work has little value if employees later enable an unassessed connector because it appears in the product menu.
| Area | Ask for | Decision enabled |
|---|---|---|
| Processing roles | Activity-specific role explanation | Allocate responsibilities |
| Subprocessors | Current list and change process | Assess downstream exposure |
| Retention | Rules for files, prompts and logs | Set acceptable data life |
| Access | Support and administrator permissions | Limit who can inspect data |
| Exit | Usable export and deletion process | Plan service replacement |
| Incidents | Notification and response procedure | Connect provider to local response |
Plan operation and exit before expansion
Ensure the business can remove a departing employee without losing shared evidence or leaving their personal account as the service administrator.
Test how approved documents and decision records can be exported.
A contract promising portability is more useful when the team knows what the export contains and how another system would read it.
Review the approval when the task changes materially, such as adding employee records or external sending.
An earlier assessment should not silently expand to a different purpose.
The next deliverable is a service map with a bounded approval decision.
That gives users a useful starting point and gives the business a way to expand AI on evidence instead of accumulating subscriptions it cannot explain.
What this page cannot conclude
- 01Controller, processor and international-transfer conclusions require assessment of the actual contracts and processing.
- 02ICO marks parts of its contracts guidance as under review after the Data (Use and Access) Act.
- 03The checklist is an implementation aid, not legal approval of any provider.
- 04This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Sources
- 01Contracts and liabilities between controllers and processorsInformation Commissioner's Office · accessed Sep 15, 2026
- 02What is an international transfer of personal information?Information Commissioner's Office · accessed Sep 15, 2026
This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 15, 2026). Buy AI Services With a Complete Data Map. dotSuper. https://dotsuper.net/feeds/applied-systems/uk-ai-procurement-data-map-processor-transfers