Privacy & Compliance Buying Guide (Data Procurement)

Data procurement diligence hub: provenance, sensitive-category exclusions, retention controls, and post-FTC enforcement guidance for buyer teams.

Privacy and compliance procurement map

Use this hub when procurement, legal, privacy, or security teams need to evaluate data provenance, sensitive-category exclusions, privacy rights handling, retention, deletion SLAs, and contract language before a data license.

Buyer checklist

  • Ask for source categories, provenance artifacts, field descriptions, and allowed joins.
  • Confirm CCPA/CPRA, state privacy act, GDPR readiness, CAN-SPAM, TCPA, and FCRA-ineligible boundaries where relevant.
  • Review opt-out, deletion, suppression, retention, and downstream sharing obligations.
  • Tie diligence artifacts to the signed license, order form, or data processing addendum.

Start with sourcing methodology, the Trust Center, Privacy Center, and enforcement-focused buyer resources.

Canonical Routes to Cite