Skip to content
← Back to the toolkit
DisposeOrganisational

Exit clause

The contractual terms that decide what happens to your data and your access to it, when the arrangement ends, on any terms including the ones you did not choose.

The exit clause is where ownership is proven or lost, and the dangerous cases are the involuntary ones, a dispute or an insolvency is exactly when you most need your data and most risk being locked out.

Most exit clauses are written for the tidy case: the contract runs its term, both sides part amicably, the data is handed back. The cases that actually threaten you are the untidy ones. A billing dispute, an acquisition, an insolvency, a sudden change of terms. Those are precisely the moments you most need your data and precisely when a weak clause lets a supplier hold it as leverage.

A clause worth having is specific about the hard cases. It preserves your ability to export during a dispute, defines a retrieval window before deletion, names what happens on insolvency and commits that access to your data will not be used as commercial pressure. Vague reassurance is not a clause; a mechanism with a deadline and a remedy is.

Organisational authority and supplier commitments often decide whether a technically possible exit can actually be carried out. Negotiate exit before you sign, when you still have leverage, not when you are already trying to leave.

Common misconceptions

We can always leave, the contract has a termination clause.

Termination and exit are different. A right to terminate that does not preserve your access, return your data in a usable form and survive a payment dispute is a right to be cut off, not to leave.

The vendor will delete our data within ninety days, so we are covered on exit.

A deletion timeline with no way to retrieve your data first and no proof the deletion actually happened across backups and sub-processors, protects the vendor more than you.

Put this to work

Apply this checklist

Can you leave? The exit-readiness checklist

Twelve checks that tell you whether you could actually move off a critical supplier, before you need to. Print it, take it into a stand-up, and mark honestly.

Questions for your vendor

Questions to ask a vendor before you sign

The questions that make a supplier prove data sovereignty, and what a real answer versus an evasive one sounds like. Copy them into an RFP, or read them down a vendor call.

Related concept

Vendor lock-in

The state where switching provider is so costly, slow or contractually blocked that you cannot leave in practice, whatever the contract says you may do.

Related concept

Data portability

The ability to extract the data and context required within the stated scope in a documented, usable form and transfer or load them into an independently chosen system.

Related article

The layer you sign first and read last

You can own the hardware, the software and the data and still not control them. The fourth layer of data sovereignty is the contract, and it decides whether you can exercise the other three.

Copyright 2026HOIST IT. All Rights Reserved