
Tools and providers
Part of Social scheduling tools chosen on the whole service rather than the headline plan
Social scheduling supplier due diligence, from plan identity to public procurement and exit
A practical England due-diligence checklist for social scheduling suppliers, covering plan identity, data, security, accessibility, contracts, cost and exit.
Social media scheduling vendor due diligence should end with a versioned evidence file and a clear decision, not a folder of undated web pages. Use this checklist for the exact product, plan, legal entity and configuration proposed to an organisation in England.
What to take away
- Due diligence should end with a versioned evidence file and a clear decision, not undated web pages.
- A fail in privacy, security, accessibility or procurement cannot be offset by extra features.
- Map data flows, sub-processors, transfers, retention and deletion before signing the deal.
- Test rights assistance, suppression handling and offboarding with synthetic records and a rehearsal.
- Normalise all commercial terms and specify export, deletion proof and credential revocation on exit.
Identity and scope
- Record the contracting parties, registered details, plan name, order number, countries of supply, users, social accounts, platforms, add-ons, term and renewal date.
- Attach the feature schedule that forms part of the deal. Marketing copy for a different edition does not fill a gap.
- Name every excluded workflow, including direct messages, social listening, paid ads, creator content or AI generation if it is outside scope.
The Small Business Commissioner's contract guide prompts buyers to define parties, supply, quantities, limitations, duration and payment. It is not a substitute for negotiated legal advice.
Identity and scope record
- Contracting parties and registered details
- Plan name and order number
- Countries of supply and users
- Social accounts and platforms
- Add-ons, term and renewal date
- Feature schedule attached
- Excluded workflows named
Data and platform dependencies
- Map each data source, purpose, controller or processor role, instruction, recipient, sub-processor, location, transfer route, retention period and deletion event.
- Obtain the applicable data-processing terms and change-notification process. Test rights assistance and suppression handling with synthetic records.
- Identify which functions depend on each social network's API and what happens when access, format or permission changes.
The ICO's controller and processor contract guidance lists contract subjects such as instructions, confidentiality, security, sub-processors, assistance and end-of-contract data. Its post-DUAA review warning means publication-day checking and qualified UK privacy advice are required. PECR analysis for direct messages or tracking is separate.
Security and continuity
- Ask for assurance scope and date, not just a certification logo. Verify identity controls, administrator privilege, logs, encryption, incident support, backups and recovery against the intended plan.
- Run an offboarding and queue-suspension rehearsal. Define who can revoke network tokens and publish manually during an outage.
- Check supplier and platform status routes, evidence retention, notification contacts and the buyer's own response duties.
NCSC cloud provider guidance distinguishes public supplier assertions from stronger independent validation. Decide what evidence is proportionate to the data and publishing authority at risk.
Content, people and accessibility
- Require evidence fields for claims, ad disclosures, licences, territories, expiry and accessible alternatives. A scheduler must not convert an unapproved asset into an approved one.
- Test authoring, approval and recovery with the buyer's assistive technologies. Obtain the current accessibility report and defect-remediation route.
- If logs, inbox allocation or analytics are used to assess workers, require separate employment, equality and privacy review.
GOV.UK explains that using protected work may require permission, ownership or a valid exception in its copyright guide. Preserve the evidence that supports the actual use.
Commercials, public procurement and exit
- Normalise currency, VAT, seat or user, channel or profile, send or usage limits, add-ons, implementation, support, assurance, renewal and termination.
- If the buyer may be a contracting authority, document the specialist decision on Procurement Act scope. Do not impose that conclusion on a private organisation.
- Specify export objects and formats, deletion proof, asset return, credential revocation, transition help, open incidents and surviving duties. Rehearse a restore into the manual baseline.
Close each item as passed, failed or unresolved with evidence owner, expiry and reviewer. A fail in privacy, PECR, security, accessibility, advertising, IP, employment, contract, procurement, tax or continuity cannot be offset by extra features. This checklist gives general information only and does not certify compliance or supplier suitability. The qualified reviewers named above must inspect the actual deal.
Before you act
- Record the exact product, plan, legal entity and configuration proposed.
- Map each data source, purpose, role, recipient and retention period.
- Ask for assurance scope and date, not just a certification logo.
- Run an offboarding and queue-suspension rehearsal before committing.
- Require evidence fields for claims, licences, territories and expiry.
- Normalise currency, VAT, seat, usage limits, renewal and termination terms.
Common questions
What should the evidence file contain?
It should record the contracting parties, plan name, order number, countries of supply, users, social accounts, platforms, add-ons, term and renewal date. Attach the feature schedule that forms part of the deal, and name every excluded workflow such as direct messages or paid ads.
How should platform API dependencies be handled?
Identify which functions depend on each social network's API and what happens when access, format or permission changes. Map each data source, purpose, controller or processor role, instruction, recipient, sub-processor, location, transfer route, retention period and deletion event, then obtain the applicable data-processing terms.
What must be agreed for exit and offboarding?
Specify export objects and formats, deletion proof, asset return, credential revocation, transition help, open incidents and surviving duties. Define who can revoke network tokens and publish manually during an outage, and rehearse a restore into the manual baseline before committing to the deal.



