Choosing cloud software involves more than checking the advertised hosting region. Identify what personal data will enter the service, who controls the processing and how the provider and its subcontractors use it. Consider remote support access and optional features as well as the main storage location.
Review the agreement and settings together. Check sharing defaults, authentication, logs, retention, export and deletion. If a restricted international transfer occurs, assess the applicable mechanism under current ICO guidance; a UK customer account does not itself resolve that question.
Define the proposed use before comparing vendors
List the records that will enter the cloud service and the tasks staff will perform. A scheduling application holding names and appointment times presents a different proposal from one storing detailed case files and identity documents. Include attachments, message histories and integrations that copy information automatically. Decide which information the business can exclude, shorten or pseudonymise before assessing the supplier's standard security questionnaire.
Identify the purchased plan and contracting entity. Security, retention and export features can vary between a free account and a business subscription from the same provider. Record which commitments form part of the agreement and which appear only in marketing material. A salesperson's statement about regional hosting should be confirmed against the service terms and configuration available to the actual account being purchased.
Map access as well as storage
Ask where live records, backups and support access are located. Identify relevant recipients and subprocessors, including services used for error reporting or optional product improvement. The ICO's transfer guide explains why the relationship and transfer conditions need examination rather than a conclusion based only on a server address. [1] Use International transfers of personal data for the detailed transfer decision and document the route applicable to the arrangement.
Review the provider's roles by activity. Processing customer records on instructions may differ from using account administrator details for billing or the provider's own business purposes. Clarify whether customer content can be used to train models or improve products, and whether the setting can be controlled centrally. Do not assume every employee's individual account has inherited the protections negotiated for the organisation's main subscription.
Configure the controls the contract assumes
Set individual accounts, appropriate authentication and role-based access. Check whether users can create public links, invite outside collaborators or connect unapproved applications. A secure platform can still expose records through permissive customer settings. Save the approved configuration and decide who may change it. Test access using an ordinary staff account rather than relying solely on the administrator's view of the permissions screen.
Review logs and alerts proportionately to the records involved. Identify who investigates an unusual export or a new administrator account. Consider device access and downloaded files, because moving documents to a controlled cloud platform does not prevent copies being stored locally. The guide to Access controls for client records helps establish permission reviews across the full working environment rather than only the main application.
Test continuity and an exit using sample records
Before migration, export a small synthetic dataset with attachments and inspect the result. Check whether filenames, dates, permissions and relationships survive in a usable format. Find out how long export takes, whether it costs extra and whether access continues after termination. A theoretical export right may not support a practical move if key records are available only as unreadable technical files.
Agree how the provider assists with incidents and individual requests. Record support channels, escalation contacts and realistic response arrangements. Check deletion of live content and the controlled treatment of backups at exit. Do not cancel the old service until necessary records and evidence have been transferred and verified. Temporary migration copies also need a deletion decision once reconciliation is complete.
For Data processing agreement review, assemble the order form, terms, processing schedule, subprocessor list and settings summary. Ask the technical owner to identify controls the supplier cannot provide. A useful review distinguishes contractual amendments, configuration actions and risks requiring a different purchase decision. Set another review when the provider introduces a new data use or when the business starts uploading more sensitive categories than originally assessed.
Test a support incident using realistic permissions
Ask the vendor to explain how an engineer would investigate a problem involving a confidential customer attachment. Identify whether support access is permanent, approved for each case or limited through a technical role. Check how the customer can see when access occurred and how an unnecessary attachment is removed from the support ticket afterwards.
Repeat the exercise using the business's ordinary account settings, not a demonstration environment with enhanced controls. Record any feature that requires a different subscription or manual configuration. This turns a general assurance about secure support into a purchasing decision about the access, logging and administration arrangements the organisation will actually receive for its chosen service.
Illustrative scenario
A consultancy stores client files in a cloud platform configured for public sharing links. The contract review finds appropriate service terms, but the business still changes the sharing defaults and limits administrator access. It also checks the provider's support locations and end-of-contract export process before moving live files.
Preparation checklist
- List the data and intended cloud activities.
- Review roles, subprocessors and access locations.
- Configure permissions, authentication and sharing controls.
- Test export and deletion arrangements before relying on the service.
Frequently asked questions
Does UK hosting mean there are no international transfers?
Not necessarily. Assess the entities and overseas access arrangements as well as storage. The applicable transfer analysis depends on the actual relationship and activities.
Can staff use personal cloud accounts for work files?
Only an appropriately authorised and assessed arrangement should handle the material. Personal accounts may lack the organisation's contractual terms, access controls and ability to retrieve or delete records.
What should an export test include?
Use sample records with attachments, dates and relationships. Confirm that the receiving team can read and use the export, and identify missing fields or extra charges before migration.
Who owns cloud settings after purchase?
Assign an operational owner and controlled change process. Procurement approval alone will not prevent later changes to sharing, integrations, retention or optional provider reuse of content.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction