Tools and providers
Part of Retail media tools for 2027, read from official supplier records without importing their verdicts
Retail media vendor due diligence, closing only the questions that have evidence
Retail media vendor due diligence for England covers supplier identity, security evidence, shopper-data responsibilities, service disruption and exit planning.
Retail media vendor due diligence should establish what an England retailer is entrusting to the supplier and which evidence supports that decision. Start with the specific advertising service, not a generic company assurance pack. A vendor handling campaign administration may have different access from one processing retailer purchase data.
The checklist below is a proposed desk-review workflow, researched on 6 September 2026. It reports no completed security assessment, certification check or legal clearance. Use qualified security, privacy and commercial reviewers for the actual arrangement; no compliance guarantee or individual legal advice is provided.
Identify the accountable parties
- Obtain the proposed contracting entity and the product or service schedule.
- Record the retailer property and the advertising functions within scope.
- Identify support providers and other parties with access to relevant systems.
- Match each assurance document to the entity and service it covers.
A trading name on a product page may not answer all those questions. Ask the supplier to clarify the contractual chain in writing. Keep the answer with the proposed agreement so the review does not rely on an account manager's informal description.
Examine dependencies and evidence scope
The NCSC supply-chain security principle explains why a cloud provider's dependencies matter to service security. Request enough information for your assessor to understand those dependencies and their relationship to the advertising workload.
If a certificate or audit report is supplied, inspect its issue date, expiry or review period, covered services and exclusions. Record the assessor's interpretation separately from the supplier's claim. An assurance document for another environment should not silently become evidence for the system the retailer plans to use.
Ask how material changes in the supply chain will be communicated. Set an internal owner to decide whether a change needs further review. This is a suggested oversight arrangement, not a claim that every supplier uses the same notification process.
Inspect permissions and service identities
Request a demonstration or suitable evidence of the proposed administrator and advertiser permissions. Ask how the supplier prevents access to another advertiser's information and who can export retailer reports. Document the response without treating a screenshot as a penetration test.
Include support access and automated credentials in the review. Name who authorises access, removes it and investigates unexpected activity. Require a separate production decision before providing keys or live shopper information to a prospective vendor.
Review processor and transfer boundaries
For processing on the retailer's behalf, UK GDPR Article 28 addresses processor guarantees and contractual duties. Ask the privacy reviewer whether the described relationship is in fact processing on behalf of a controller, then assess the documents against that role.
The ICO international-transfer guide covers personal information sent or made accessible to separate organisations overseas. Map the actual entities and access locations before deciding which transfer rules apply. A hosting location alone does not describe the complete relationship.
Record unresolved questions about retention, deletion and supplier reuse. Do not turn a general privacy notice into proof that your proposed audience processing is authorised. Contract terms, lawful basis and operational behaviour need to be considered together by the appropriate specialist.
Ask about disruption and departure
Obtain the process for reporting an incident affecting the retailer's advertising service. Clarify the information available to your incident team and how the supplier will support investigation. Any promised response time should come from the actual agreement, not an assumed industry standard.
Request an exit description covering campaign closure, report export, access removal and outstanding commercial obligations. Have the solicitor examine the proposed termination terms. Record which tasks the retailer would still need to perform after the supplier's service ends.
Close only the questions with evidence
Prepare an exceptions register with the missing evidence, responsible reviewer and next action. Keep security guidance distinct from law and contractual promises. Advance the purchase only through the retailer's actual approval process, and refresh this checklist's sources before using it for a later procurement.