Global

Vendor Due Diligence Checklist

The short answer. Due diligence on a data vendor is the process of testing six things before you pay: the consent artifacts, where the speakers were recorded, the chain of custody from recording to delivery, the sub-processor list, the security posture, and what happens when a speaker asks for their data to be deleted. GDPR Article 28(1) states the underlying rule, that a controller may use only processors providing sufficient guarantees. Article 5(2) puts the burden of demonstrating compliance on the controller, which is you.

The law

GDPR Article 28(1)

Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.

This is the hook. It is a duty on the controller to make a judgment about the vendor before using it, and the judgment has to be documented. A vendor that cannot show consent artifacts is not providing sufficient guarantees, whatever the audio sounds like.

GDPR Article 5(2)

The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 ('accountability').

Accountability is why diligence is not optional and why relying on the vendor is not a defense. You have to be able to show the choice was reasonable at the time it was made. The diligence file — what you asked, what the vendor answered, when — is that demonstration.

GDPR Article 28(3)(g)

deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data.

Deletion at the end of the arrangement. For a dataset purchase the useful question is not whether the vendor will delete, but what deletion means when the same recordings were also supplied to other buyers. If the corpus is shared, deletion on your instruction does not remove the speaker from the vendor's product.

GDPR Article 28(3)(h)

makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

The audit right, which has to be in the contract before you need it, and which should reach the sub-processors rather than stop at the vendor. Ask whether the right covers the studio that recorded the audio, because that is where the consent forms are.

Who it applies to

This checklist is not jurisdiction-specific. Article 28(1) is the hook for EU data, but the same six questions decide whether a corpus is usable in a US enterprise sale, whether an insurer will write the risk, and whether the dataset survives a diligence review by your own customer. The accountability obligation in Article 5(2) sits on the controller, which is the buyer, so "we relied on the vendor" is not a defense anywhere.

Two categories of vendor are hardest to diligence and most common in this market. The first is the broker that resells corpora it did not collect, where the chain of custody has an extra link and the consent forms belong to a party you have no contract with. The second is the platform that aggregates contributions from many studios, where the collection standard varies by contributor and the aggregate looks uniform.

Both can supply good data. Both require the chain to be traced one link further than the buyer expects. The rule of thumb we use: if a vendor cannot name the studio or the recruitment source behind a sample, treat the consent artifact for that sample as unverified, and treat the delivery as a whole as unverified until a sample proves otherwise.

What it costs to get wrong

No statute fines a buyer for choosing a bad vendor. The consequences are of three kinds, and all three are real.

Regulatory: if the vendor's consent is invalid, the processing is unlawful, and the buyer as controller carries the exposure. A breach of Articles 5, 6 or 9 sits in the higher tier under Article 83(5) — up to 20 million euros, or up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher.

Contractual: a corpus with a broken chain cannot be resold, cannot be sublicensed, and often cannot be used in the product it was bought for. The purchase price becomes a write-off, and the indemnity in the supply contract is only as good as the vendor's balance sheet.

Reputational and operational: a speaker who finds their recordings in a distributed model, or a reporter who traces a corpus back to how the speakers were recruited, produces a problem that no indemnity resolves quickly. The diligence file is what you have when any of the three arrives, and it is much cheaper to build at purchase than to reconstruct afterwards.

How to comply when you are buying data

The list below is written to be checkable rather than reassuring. Each item has an answer that can be verified against a document.

  • Consent artifacts: ask for the executed form for twenty randomly chosen speakers from the delivery. Check that each form names the purpose, the term, and the permitted disclosures. A scanned signature with no purpose statement is not a consent artifact.
  • Speaker location: the country, and where relevant the state or province, of each recording, with counts by country rather than a list of markets. This decides GDPR, BIPA and transfer questions, and it cannot be reconstructed after delivery.
  • Chain of custody: the studio or platform that recorded the audio, the date, the equipment or application, the transfer to the vendor, and the storage location at each step. Ask for the same twenty samples to be traced end to end and compare the answers with the consent forms.
  • Sub-processor list: every party that touches the audio, including annotation vendors, quality reviewers and cloud storage. Ask for the current list in writing and the process by which you are notified of changes.
  • Security posture: encryption at rest and in transit, access control, whether the corpus shares storage with other clients' data, retention limits on the vendor's own copies, and the breach notification time frame in the contract.
  • Erasure: the procedure when a speaker withdraws, the response time, whether it covers derived data and model artifacts, and whether there is a charge. Ask for it as a written procedure rather than a verbal assurance.
  • Continuity: who owns the corpus if the vendor is acquired, and what happens to your license, the consent records and the retention obligations. Get the answer as a contract term, because the acquisition will not be renegotiated.

How we handle consent and licensing →

Related compliance topics

Not legal advice

We are a sourcing company, not a law firm. Nothing on this page is legal advice, and it does not create a lawyer–client relationship. Whether a particular dataset is permissible in your jurisdiction depends on your use case, where you operate, and where the people in the recordings are located. Our role is to document the chain of consent accurately so that your counsel can assess it.

Sourcing data under Vendor Due Diligence Checklist?

Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.

  • Pilot batch before the full run, so problems surface early.
  • Consent documentation delivered with the data.
  • No medical or clinical data. No recorded telephone calls.

We reply within two business days. Your details are used only to answer this request. See our privacy policy.

Contact

Talk to a human

Send a specification and we will come back with a real number and timeline.

Submit a sourcing request

Or email hello@linguacorpus.com