Data Portability in Service Contracts
Ensure service contracts cover data portability for backups, migration, and decommissioning.
Plain language
This control is about making sure that your business data can be easily moved or backed up when using services like cloud storage. It's important because if your provider goes down or if you switch services, you want your data safe and away from being stuck or lost.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
The storage of data in a portable manner that enables backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.
Why it matters
Without data portability, your business risks losing access to crucial information, facing operational delays, and financial losses if you change or leave a service provider.
Operational notes
Regularly review and update service contracts to ensure they include terms that facilitate easy data portability and conformity with legal standards.
Implementation tips
- Procurement teams should ensure that contracts with service providers include clear clauses about data portability. Do this by specifying how and when data can be extracted or transferred during and after the contract.
- IT managers should work with service vendors to test data migration and backup processes. They can create small test data sets to perform a mock transfer, ensuring compatibility with other systems.
- Legal teams should review all service agreements for compliance with data portability requirements. They should check that there are no hidden fees or barriers that prevent easy data transfer.
- Managers should establish a regular review schedule for service contracts to assess data portability clauses. This can be done annually to ensure that the clauses still meet business needs and legal requirements.
- Operational staff should maintain an inventory of systems and services to track where data resides. Use this inventory to ensure you know how data can be retrieved or moved if needed.
Audit / evidence tips
- Askthe service contract agreements: Request to see documents that outline data portability clauses with service providersLook atsections detailing how and when data can be migrated or backed upGoodincludes clear, non-restrictive terms about data transfer rights
- Askevidence of successful data migration tests: Request reports or logs of any recent data migration or backup tests performedLook atdetails on the timing and success of the data transfersGoodshows no data loss and documents how the process was completed
- Askthe inventory of data assets used in service contracts: Review how data assets are listed and managedLook atcomprehensive details about data location and portability optionsGoodinventory provides clarity on all data managed by third-party services
- Askperiodic review meeting records: Request minutes or reports from meetings held to discuss contract reviewsLook atwhat actions were taken concerning data portabilityGoodincludes documented discussions and decisions made on maintaining or improving portability
- Asklegal compliance checks: Request documentation of legal reviews for service contractsLook atevidence of compliance with Australian regulations related to data transferGoodincludes legal sign-offs and compliance confirmations
Cross-framework mappings
How ISM-1574 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 5.14 | ISM-1574 requires contractual arrangements with service providers to document portable data storage arrangements that support backups, se... | |
| Annex A 8.10 | ISM-1574 requires service agreements to document how data can be migrated and decommissioned without loss, which typically includes speci... | |
handshakeSupports(2)expand_less | ||
| Annex A 5.19 | ISM-1574 requires organisations to document data portability expectations (backup, migration, and decommissioning without data loss) in c... | |
| Annex A 8.13 | ISM-1574 requires supplier contracts to document portable storage arrangements that enable backups and restoration/migration without losi... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Procurement and outsourcing
See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.