Migration

Data processing agreements: what changes when you switch vendors

A vendor migration in geocoding or IP data is not purely a technical exercise, since the data flowing through these APIs, addresses, coordinates, and IP addresses, often qualifies as personal data under privacy regulations in a meaningful number of jurisdictions. Switching providers means switching who is processing that data on your behalf, and that change deserves the same review a new vendor relationship would get in any other part of a business, not less scrutiny just because the technical migration is small.

A few specific things worth reviewing when evaluating a new location data vendor from this angle, separate from the technical evaluation:

Where the data is processed and stored. Depending on your regulatory obligations, the geographic location of a vendor's infrastructure and any sub-processors involved can matter as much as the vendor's technical capability. This is worth confirming directly with any new vendor rather than assuming it matches your previous provider's setup.

What data is retained, and for how long. IP addresses and query addresses sent to a geocoding or IP lookup API are, by nature of the request, transmitted to that vendor. Understanding whether and how long a vendor retains that data, separate from whether it processes it to return a result, is a distinct question worth asking explicitly rather than assuming based on the vendor's general reputation.

Whether a data processing agreement is available and what it covers. Many jurisdictions' privacy frameworks expect a formal agreement covering how a processor handles data on a controller's behalf. Confirming this exists, and reading what it actually says rather than just confirming its existence, is worth doing before committing to a new vendor relationship, exactly as it would be for any other data processor a business relies on.

How the change affects your own privacy notices and internal documentation. If your organization's privacy policy or internal data flow documentation names a specific vendor, or a category of vendor with specific characteristics, a migration means updating that documentation to reflect the new relationship accurately, which is easy to overlook amid the technical work of the migration itself.

My Geocode is a company built specifically to run a geocoding API, described plainly as: we build and run a geocoding API, that is the whole company. For any specific compliance question relevant to your own regulatory obligations, whether that involves data processing terms, retention practices, or infrastructure location, the direct path is to review the relevant terms and privacy documentation for the specifics that apply to your situation, since these are the kind of details that deserve a direct, current answer rather than a general summary in a blog post. See /pricing/ and /about/ for more on how the company operates, and reach out through /contact/ with specific compliance questions relevant to your migration.

Treating this review as a normal part of vendor onboarding, not a special extra step required only for large enterprises, keeps a technical migration from accidentally creating a compliance gap that surfaces much later, usually at the worst possible time, during an audit or a customer's own vendor review.