Kordano Founding 100 for teams of 6+: $3/user/month, month to month, locked for 24 months
Kordano
Kordano Insights

Practical guidance for running clearer, more accountable teams.

Privacy & Trust

Who Controls Your Workforce Data? 12 Questions to Ask Every Software Vendor

By Haris Ali D. · Published July 22, 2026

Share

On a vendor review call, “the customer owns the data” can sound like the final answer. Then someone asks which other companies receive screenshots, whether support staff can open them, and what survives after cancellation. The ownership sentence gets very small, very quickly.

I used to read that clause as the end of the issue. It is only the first line.

Control is the practical question. Who decides why workforce data is collected? Who can see it? What may be inferred from it? Where can it travel? How long does every copy remain, and can the employer retrieve or remove it when the relationship ends?

Most small teams do not answer those questions. The UK government's Cyber Security Breaches Survey 2025/2026 found that 15% of surveyed businesses formally reviewed cyber risk from immediate suppliers. The result came from 2,112 UK businesses and is not a global estimate, but it captures a familiar operating gap: software is easy to approve, while responsibility for its data is left unnamed.

Start with the Workforce Data Control Map

Do not begin with the vendor's security badge. Begin with the records the system will hold or create.

The Workforce Data Control Map is a working framework for this guide, not a legal classification. It separates five data classes that behave differently during access, export, retention, and deletion.

Table: five classes to map before approving a workforce-software vendor.

Data classCommon examplesThe decision to record
SuppliedNames, emails, schedules, projects, pay identifiers, notesWho entered it, which purpose needs it, and which roles may change it
ObservedHours, screenshots, app use, device details, location where enabledWhat starts collection, what stops it, and which people can see the raw record
DerivedActivity scores, flags, summaries, classifications, predictionsHow it is calculated, who may act on it, and whether a worker can challenge it
Administrative and auditApprovals, edits, exports, access events, IP and device logsWho can inspect the history, how long it remains, and whether it leaves with an export
Replicas and downstream copiesBackups, integrations, support tickets, report files, model-provider inputsWhich party holds each copy, when it expires, and who can prove its deletion

If one row cannot be completed, the review is not done. Mark the answer Needs proof instead of filling the gap with a reassuring assumption.

For each of the 12 questions below, keep four artifacts: the vendor's written answer, the action used to test it, the person inside the company who owns the decision, and the contract or policy term that makes the answer durable.

That is the control record. A certificate can support it. A certificate cannot replace it.

Who decides and why

1. Who decides why each data type is processed?

“We are the processor” is not enough. Ask the vendor to describe its role for each service, feature, integration, and optional module. Then ask which decisions remain with the employer and which purposes the vendor chooses for itself.

Under EU data-protection concepts, a controller decides the purpose and essential means of processing, while a processor acts on the controller's instructions. The European Data Protection Board's SME guide also makes clear that the relationship and its duties belong in a contract. Other jurisdictions use different labels and tests, so have qualified counsel apply the rules that cover the workforce.

The important operating point is broader than one law: the role follows the real decision, not the heading in a sales document.

Current workforce platforms show why this needs to be service-specific. Remote's privacy policy describes the company as a controller for some services and a processor for others. That does not make the arrangement wrong. It means a buyer should never assume one label covers an entire product family.

Record the answer beside every row in the data map. If the vendor cannot name who decides a purpose, nobody on the buyer's side should pretend the contract already did.

2. What workforce data exists, including data the product creates?

Ask for a field-level inventory, then compare it with the product itself. Include hidden and generated records: confidence scores, flags, edit histories, support transcripts, device identifiers, access logs, report caches, integration payloads, and model inputs or outputs.

The contract pages were more revealing when I stopped searching only for “ownership” and searched for verbs: process, disclose, retain, train, derive, and delete.

Run a controlled test with fictional people and harmless data. Start a timer, edit a record, approve it, export it, contact support, connect one integration, and request deletion. List every new record produced along the way. Do this before real employee data enters the account.

An inventory that lists “time data” but omits the approval history is incomplete. So is one that lists screenshots but not thumbnails, support copies, or the activity score calculated from them.

3. What may the vendor use the data for?

Separate service delivery from every secondary purpose: diagnostics, analytics, benchmarking, product improvement, fraud detection, human review, AI feature operation, model evaluation, and model training.

Storage and training are different questions. A vendor can give a careful answer about where data is stored and still leave its model-use terms unanswered. The FTC has warned AI companies that secret training uses, quiet policy changes, and material omissions can conflict with their commitments to customers. Its guidance on AI privacy promises is written for companies under US law, but the procurement lesson travels well: name the purpose and put the promise where it can be enforced.

Ask whether the restriction covers raw data, metadata, derived data, prompts, outputs, feedback, and data sent through an API. Also ask what happens when an AI feature is introduced after the original contract.

Honestly, I would rather see one specific limitation than a page of unqualified “compliant” badges.

Who can see it and where it travels

4. Which vendor employees can access the data?

The answer should name the roles, reasons, approval path, authentication, logging, review cadence, and revocation process. “Authorized personnel” is a category, not a control.

Ask the vendor to show a sample privileged-access record with customer information removed. It should make clear who requested access, who approved it, what was opened, why, when access ended, and whether the customer is notified for support access.

The risk is not limited to malicious insiders. Shared credentials, stale contractor accounts, and broad support permissions all weaken accountability. In the FTC's Chegg action, the agency alleged that a former contractor used login information shared with employees and contractors to reach a third-party database. Across four breaches, customer data and employee medical and financial information were exposed.

That case is not a verdict on every cloud vendor. It is a reminder that “our staff may access data when needed” leaves out the part a buyer must verify: how need becomes temporary permission, and how temporary permission becomes a reviewable event.

5. Which subprocessors, integrations, and model providers receive it?

Request a current list showing the recipient, purpose, data classes, processing location, and the service features that use it. Then read the integration and AI terms separately.

The subprocessor lists looked tidy until I compared them with integration terms. The same third party can sit outside the vendor's ordinary processor chain because the customer connected it directly or accepted separate terms.

The UK's National Cyber Security Centre says cloud buyers should understand both customer data and metadata shared with a provider's supply chain. Its cloud supply-chain guidance also asks buyers to understand which party implements each security function.

For every recipient, record:

  • whether the vendor or the customer chose it
  • what is sent, in which direction, and under whose instructions
  • how the customer hears about a change and whether it may object or disconnect
  • what happens to the recipient's copy after the connection is removed

An integration directory is not a data-flow diagram. Draw the arrows.

6. What can workers see, correct, or challenge?

Workforce data is unusual because the account buyer is not the person described by most of the records. That makes an admin dashboard only half of the review.

Ask the vendor to show the worker view for raw records, derived scores, edits, approval history, screenshots, and rejection reasons. Then rehearse a request: one fictional worker asks for a copy, correction, explanation, and deletion where applicable. Time the retrieval, inspect what is missing, and record which party communicates the answer.

Under the UK GDPR, the ICO's access guidance says an access response can include a copy plus information about recipients, retention, source, and automated decision-making where relevant. Rights and deadlines vary by jurisdiction and circumstance. The test still exposes an operational fact everywhere: can the employer find the record it promised to manage?

If screenshots are collected, decide access and challenge rules before rollout. The 2026 employee-monitoring legal guide maps the method, worker location, notice, consent, and consultation questions to review before collection. The remote-team time-tracking guide shows how to compare monitoring depth without treating more capture as automatically better.

In a small company, the person who bought the tool often becomes its privacy owner by accident. Bad assignment. Nobody told them the job existed.

Where control commonly breaks

7. Where is the data stored and processed?

Ask about primary databases, backups, disaster-recovery copies, support access, analytics systems, file storage, integrations, and international transfers. “Hosted in the US” or “EU data residency available” may describe the main database while leaving support and subprocessor access elsewhere.

Match the answer to the five-class map. Raw timesheets, screenshots, logs, and model inputs may follow different paths. Record the transfer method or contractual basis where the applicable law requires one, but do not let a transfer mechanism substitute for the simpler question: which company in which country can receive this class of data?

If the vendor changes hosting or support locations, decide who reviews the change and how quickly. A location answer is a dated record, not a permanent property of the software.

8. How long is each data class kept?

Ask for a retention schedule with one row per data class and per copy. It should state the trigger, period, reason, deletion method, exceptions, and who approves an extension.

Payroll and time records may need to stay available because of local recordkeeping duties. Monitoring detail, support files, and report caches may have a shorter useful life. One account-wide period is often a sign that the vendor has not separated the purposes.

The ICO's storage-limitation guidance says UK GDPR does not set one universal retention period. An organization must justify its period, review it, and address archived and backup copies. Other laws may require different periods, especially for payroll, tax, health, or litigation records.

I expected deletion to be the easiest question. It had the most footnotes: backups, logs, legal holds, support copies, and model inputs.

Require an admin control where shorter retention is part of the policy. A promise the customer cannot configure or verify is fragile.

9. What does the security evidence actually cover?

A certification or assurance report can be useful. Check the named legal entity, product, systems, period, control scope, subservice organizations, exceptions, and management response. Then compare that scope with the feature being purchased.

The certificate question got weaker the longer I looked at it. Scope and exceptions carried more information than the logo.

Ask for the current report or a suitable summary, a recent penetration-test summary, unresolved high-risk findings, recovery-test evidence, and the security terms that bind the vendor. A sales representative does not need to disclose exploitable detail. The buyer does need enough evidence to see whether the claimed control covers this service now.

The distinction matters. The ICO's 2025 Advanced software enforcement announcement says attackers entered through a customer account without multi-factor authentication even though MFA existed across many other systems. The regulator fined the provider £3.07 million after personal data relating to 79,404 people was taken.

Broad coverage can still leave one important path open.

10. What happens after a security incident?

Make the vendor walk through the first hours, not just say it has an incident-response plan.

The contract should define the notice trigger, clock, contact method, minimum contents, update cadence, evidence preservation, cooperation, cost responsibilities, and final report. Ask whether notice waits for the vendor to finish confirming legal liability. The employer may need operational facts sooner to protect workers, freeze integrations, reset access, or meet its own duties.

Run a tabletop with a concrete scenario: a support account downloaded screenshots and time records for one team. Who disables access? Who identifies the affected records? Can the vendor produce access logs? Who tells employees, customers, insurers, or regulators if required? When is the next update due?

If a support-team operator had one day for vendor review, I would spend more of it tracing subprocessors and deleting test data than watching dashboards. The same applies here. One incident rehearsal reveals more control than another hour of security adjectives.

Can you leave with the record intact?

11. Can you take a complete, usable copy out?

“CSV export” is not a complete answer. Request a sample export before signing and again before renewal.

Check for people, projects, time records, notes, attachments, approvals, edits, audit events, screenshots or references, derived values, permission assignments, and the definitions needed to interpret them. Relationships matter. A file of approval events is not useful if it cannot be tied back to the approved entries.

Also test scope. Can an account owner export the whole organization, or only records visible to the requesting role? Are deleted, archived, and inactive objects included? Is there an API, a charge, a delay, or a professional-services dependency?

This goes further than the general export question in our time-tracking software buying guide. Here the test is whether the exit file preserves the meaning and control history of workforce data, including data the product created.

Open the file in software the old vendor does not control. Reconcile record counts and a few known histories. Portability begins when the former customer can understand the result.

12. What remains after deletion or termination?

Ask the vendor to account for the live database, backups, logs, support systems, integration queues, report exports, subprocessors, and AI-provider copies. For each one, record whether it is deleted, anonymized, placed beyond use until rotation, or retained for a stated legal reason.

Every copy.

The FTC's 2024 Blackbaud order announcement is a hard lesson in why this matters. The agency said the software provider retained information belonging to former customers longer than necessary, the breach went undetected for three months, and customer notice came nearly two months after detection. The order required a retention schedule and deletion of data no longer needed.

Ask for the deletion timeline, exceptions, and written confirmation. A certificate from the vendor can document completion, but it cannot prove what the contract never required. Put the copy list and deadline into the agreement before data arrives.

Also cover insolvency, acquisition, and service shutdown. Who returns the data if the original vendor disappears? Which successor receives the contract and the copies? What notice allows the customer to export before access ends?

My failed assumption was that ownership language solved exit. It does not. An owner without a usable copy and a deletion right has a label, not control.

Turn the answers into a decision

Do not average these questions into a cheerful percentage. A vendor can score well overall and still fail on the one control that matters most to a payroll, monitoring, or HR workflow.

Use four decisions:

  • Approve when the required answers are written, tested, owned internally, and covered by durable terms
  • Limit when the software can be used with fewer data classes, disabled features, narrower roles, or no sensitive integration
  • Renegotiate when the behavior is acceptable but the notice, evidence, retention, or exit promise is missing from the contract
  • Replace or reject when a high-impact purpose, access path, recipient, incident duty, export, or deletion answer remains unknown

Rerun the record at renewal, after a material feature or subprocessor change, and after an incident. The purchase review is only the first version.

The same rule should govern management use. If a derived score cannot be explained or challenged, it should not decide performance by itself. Activity is not productivity, and vendor control does not make a weak metric meaningful.

Apply the same questions to Kordano

Kordano Time is in Early Access, with access planned to begin on December 1, 2026. Some behavior is still being built, so an unpublished privacy or security answer should be marked Needs proof, not turned into a promise.

GPS, geofencing, and employee-location tracking are not currently confirmed Kordano features. Kordano may consider them in the future depending on customer demand.

For Founding 100 customers, migration is free, unlimited, human-assisted, and available from any product. A customer can provide a CSV export or secure access to the old account, and movable information can include projects, users, work history, and other available data. That migration promise creates its own data-control questions: who can access the transfer copy, where it is staged, and when it is removed. Until Kordano publishes or supplies those answers in writing, they remain Needs proof too.

Use all 12 questions on Kordano. Review the current public answers and ask what is still unconfirmed.

The vendor may operate the database. The employer still owns the decision to put workforce data there.

Privacy & Trust
Become a founding member

Companies with teams of 6 or more can lock $3 per person per month for 24 months.

Claim your spot
Limited to 100 qualifying companies
Haris Ali D.
Haris Ali D.
Co-Founder at Kordano
Get in touch

Haris Ali D. is the Founder of Kordano, a workforce operating system for modern teams. He focuses on building practical tools for time tracking, attendance, productivity visibility, and team operations.

He also brings experience in branding, digital strategy, and software development through FullStop, a company he co-founded in 2012.

World-class productivity advice

Practical tips in your inbox. No spam.