# Institutional exit and handover checklist

DRAFT PLANNING TEMPLATE — not an executed agreement, completed test, certification or delivery record. Prepared 19 September 2026. Complete, review and approve before institutional rollout. Do not enter real student data in public copies.

1. Identify the authorised institutional recipient and approved scope. Distinguish aggregate usage, account records, career documents and student-controlled encrypted vault copies.
2. Agree ownership, lawful authority, accessible formats, encryption, secure delivery, checksums and acceptance date.
3. Test export with synthetic records and reconcile totals. Suppressed aggregate groups are not zero counts. Do not infer unique beneficiaries by adding categories.
4. Explain student access after subscription expiry and separately after account deletion/service discontinuation. Export vault backups before exit; original passphrases remain necessary.
5. Agree cutoff for new processing and revoke staff/institutional access at the approved point.
6. Inventory live databases, storage, logs, support, billing, AI processors and backups; identify applicable legal holds.
7. Record approved retention period, deletion action, executor, date and supporting evidence for each system.
8. Obtain processor acknowledgements and backup expiry/restore controls. Application deletion alone is not proof of provider/backup erasure.
9. Document retained records and reasons, unresolved exceptions and follow-up owner/date.
10. Obtain recipient acceptance and accountable closure approval. Issue a deletion confirmation only for actions actually verified.

Record ID / institution / version / owner / approved scope / evidence / exceptions / reviewer: [complete]. This blank checklist is not a deletion certificate.
