Vendor Offboarding Checklist Template
Three documents and three sheets that compute your real notice deadline from the contract, then track every data category, including subprocessors, to actual proof.
Free download · No account needed
Data Deletion Confirmation
Cascade Timber Co., exit from Ridgeway HR
| Termination effective | 1 Jun 2026 |
| Categories tracked | 7 |
| Reviewed | 20 Aug 2026 |
| Status | Categories |
|---|---|
| Confirmed | 4 |
| Retained under legal hold | 2 |
| Overdue | 1 |
An assurance is not a subprocessor's proof
Ridgeway HR reported the offboarding complete on schedule. The benefits carrier it fed enrollment data to for two years has not confirmed deletion, 12 days past its own deadline.
Every vendor offboarding checklist ranked for this query assumes a generic timeline: a notice period somewhere between 60 and 120 days, a data-return window somewhere between 30 and 90 days. None of them opens the contract actually governing this exit, and real ones do not agree with each other. Amplitude's own Data Processing Addendum sets a 30-day retrievability period before deletion. Intercom's gives 30 days on request or 180 automatically, with backups purged in 14. A checklist built on an assumed range gets a specific contract's actual deadline wrong in one direction or the other.
On the worked example already in the sheets, Cascade Timber Co.'s Master Subscription Agreement with Ridgeway HR renews every 1 June, and Section 9.1 requires 60 days' written notice to avoid another term. That fixes the real deadline at 2 April, not sometime that spring, and the Termination Letter goes out 27 March, five days ahead of it. Missing that date would not cost a partial extension. It renews the entire contract for another twelve months at $79,200, the current annual fee, whether or not Cascade Timber still wants Ridgeway HR at all.
This space starts once leaving is already decided and a replacement is in hand. Choosing that replacement is a separate RFP evaluation job that runs beforehand, and deciding whether to keep paying a vendor at renewal instead is a vendor renewal call. What is left, ending the contract on the date its own clause allows and proving the data actually left every system it reached, including the four subprocessors a typical HRIS integration touches, is what this pack tracks to close.
What's in the pack
Termination Letter
Cites your contract's own renewal date and notice clause, computed to an exact deadline instead of a guessed range.
Transition Plan
Sequences export, parallel run, cutover and access revocation in order, so nothing is cut before it should be.
Data Return Request
Invokes your contract's actual return-or-delete clause and elects what happens to production data, backups and subprocessors.
Offboarding Checklist
The master task list from exit decision through the last subprocessor confirmation, with an owner and date on every row.
Access Revocation Log
Every SSO app, API key and named seat this vendor held, revoked and logged with proof, not just a checkbox.
Data Deletion Confirmation
Tracks production data, backups and every subprocessor to its own proof, and marks legal holds closed correctly.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and hand it your contract, or download the Word documents and CSV sheets and fill them in yourself.
- 2
Send the term and data clauses
The renewal date, the notice period, and the data return or deletion clause, read straight from your contract and its exhibits.
- 3
Get the computed deadline and letters
The actual notice deadline computed from your contract, plus a Termination Letter and Data Return Request drafted to cite it.
- 4
Track every category to proof
Production data, backups and each subprocessor tracked to its own confirmation, with legal holds marked closed correctly.
Frequently asked questions
Is this template free?
Yes. The zip is Word documents and CSV sheets, with no account and no card needed. Edit with AI is the optional half: River reads your actual contract, computes the real notice deadline, and builds the trackers around your real systems as you go.
What format are the downloaded files?
Three Word documents and three CSV sheets, zipped together. Excel, Numbers and Google Sheets read the sheets with no reformatting, and Word, Pages or Google Docs open the letters and plan directly. Nothing needs converting first.
We already have a generic offboarding checklist. What does this add?
The actual contract. A generic checklist assumes a notice range and a data-return range because it has never read the document governing this exit. This pack computes both from your contract's real clauses, then tracks each data category and each subprocessor to its own proof rather than one closing assurance.
What if there's no separate data processing addendum?
Send what you have. If the return-or-deletion terms sit in the main body rather than a separate exhibit, the tracker is built from those instead. Any category the contract does not address gets flagged as an open question for the vendor, not filled in with an assumed window.
How does this handle data that reached a subprocessor?
As its own row. A primary vendor's obligation is usually to notify a subprocessor of the termination within a stated window, not to guarantee that subprocessor's own deletion. This pack tracks each subprocessor to its own confirmation, separate from the primary vendor's assurance that offboarding is complete.
Does this help decide whether to leave the vendor in the first place?
No, this space starts once that decision is already made. Whether to keep paying at renewal is a vendor renewal call, and holding a vendor to its SLA before deciding is a performance review job. This pack picks up once the exit itself needs executing.
Exit on the date your contract actually allows
Send the termination and data-return clauses. The first thing back is a computed deadline, not a guessed range.
Edit with AI