Most of the useful diligence on a data supplier fits on one page. These are the eight questions we would ask, why each one matters, and what a good answer sounds like.
The answers matter less than the willingness to answer plainly. A supplier who treats these as reasonable questions is usually a supplier worth working with, and one who treats them as an accusation has told you something too.
1. Where is the primary copy of our data physically stored, and under whose account?
You are asking two things: which country or region, and whose name is on the account. A supplier who stores your data in their own cloud account has practical control of it regardless of what the contract says. A good answer names the location and confirms that you hold, or can hold, an account of your own. A vague answer about a secure cloud is not an answer.
2. Can we hold a complete copy ourselves, continuously rather than on request?
Continuously is the load-bearing word. An export you can ask for is a favor with a process attached. A copy that lands with you as data is produced means you are never waiting on anyone. Suppliers who are comfortable with this usually say yes quickly, because they think of themselves as processing your data rather than owning it.
3. What exactly can we export: raw data, or processed summaries? In what format, and at what granularity?
This is where most contracts quietly fail. Almost every agreement promises export; far fewer specify that it means the raw feed rather than aggregated summaries. Summaries answer the questions somebody already thought of. Ask for a sample export before signing, not a description of one.
4. How long does a full export take, and has it been done for another client?
A supplier who has genuinely done this can tell you how long it took and what broke. One who has not will estimate. The difference matters because you will typically want the export at the least convenient moment, during a migration or a dispute.
5. Who at your organization can access our data, and is that access logged?
Support staff usually need some access, which is reasonable. What you want is a named scope and a log you can request. If nobody can tell you who looked at your medical or scouting data last month, that is your answer.
6. Is our data used to train models or build products sold to anyone else, including our competitors?
Ask it that directly, and listen for hedging. Aggregated and anonymized covers a wide range of practice, some of it fine and some of it your positional data improving a product sold to the team you play next month. If the answer is yes, you may still be comfortable, but you should be paid for it or aware of it rather than surprised.
7. What happens to our data if we do not renew, and how long is it retained afterwards?
Two failure modes here. Deleted faster than you expected, so a season of history vanishes. Or retained far longer than you expected, so it still exists somewhere you no longer have any relationship with. Both are common. Get the retention period in writing with the deletion mechanism attached.
8. If you are acquired or cease trading, what is the mechanism by which we retain access?
The least comfortable question and the most revealing. Escrow arrangements, a continuously held local copy, or documented open formats are all real answers. Nobody plans to go out of business, so an answer that assumes continuity is not one.
Using these
Ask them before signing rather than after, and ask for a sample export rather than a description of one. If several answers come back vague, that is not necessarily a reason to walk away, but it is a reason to keep your own copy of everything from the first day.
For why the answers matter commercially as well as technically, see sports data sovereignty. For working out which data to ask about in the first place, the team data inventory lists what a season actually produces.