TL;DR: Avoiding vendor lock-in means proving, before you sign, that you can leave. Ask for a live export demo, a named file format, a written exit clause, and API access you control. If a vendor describes the exit instead of showing it, treat that as your answer.
Avoiding vendor lock-in comes down to four things you settle before money changes hands: who owns the data, how it comes out, what the contract says about leaving, and who controls the hardware. Everything else is negotiable later. These four are not.
I have sat in demos where the software was excellent and the exit was a trap. The buyer found out three years later, when payroll history would not come out in any format their new system could read. So they stayed. That is lock-in doing exactly what it was built to do.
What is vendor lock-in in HR software?
Vendor lock-in is when leaving your provider costs more than staying, even after the product stops serving you. Avoiding vendor lock-in therefore starts with one habit: assume you will leave one day, and check that you can.
The cost is rarely the subscription fee. It is the rebuilt attendance history, the re-enrolled fingerprints, the payroll rules someone has to code again from scratch. Researchers named data lock-in an obstacle to cloud computing back in 2010, and the shape of the problem has not changed since.[2]
The uncomfortable part is how few buyers see it coming. In a survey of 114 UK IT managers and CIOs, only 44% had even a basic understanding of the term “vendor lock-in”, and just 3% rated their knowledge as exceptional.[1] These are technical people. If they are unclear on it, an HR manager comparing three quotes has almost no chance.
Key stats
44% of IT managers had only a basic grasp of vendor lock-in
71% said lock-in risk would deter further cloud adoption
76.6% were unsure which portability standards even exist
Source: Opara-Martins, Sahandi & Tian (2016), survey of 114 UK IT managers and CIOs.
Why is avoiding vendor lock-in harder in Bangladesh?
The local market adds two pressures that generic buying advice ignores.
First, most HR platforms here ship with hardware. Fingerprint and face devices get sold as part of the package, and those devices often speak only to the vendor’s own server. Switch software and the machine on your wall may become a paperweight. That is a hardware dependency dressed up as a software subscription, and it is why the cloud versus on-premise decision matters more here than in markets where the two layers are separate.
Second, several vendors are small teams building custom work per client. Custom is comfortable until you need your data in a format anyone else can read. Bespoke database schemas are the single most effective lock-in mechanism ever invented, and nobody has to intend it.
Bangladeshi law also assumes you hold your own records. Section 9 of the Bangladesh Labour Act, 2006 requires an employer to maintain a register of workers and produce it for an Inspector at any time during working hours. Your vendor is not the one who gets fined if that register is unavailable. You are.
What are the four lock-in traps to test for?
Lock-in is not one problem. It is four, and vendors are usually strong on some and quietly weak on others. Avoiding vendor lock-in means testing all four, because one weak link holds you just as firmly.
Data lock-in
Data lock-in is when your records exist but will not come out in a usable shape. A PDF export is not portability. Neither is a CSV that drops attachments, approval history, and the timestamps that prove an overtime claim. Ask what leaves the building, not whether an export button exists.
Contract lock-in
Contract lock-in lives in auto-renewal clauses, multi-year terms with no exit for convenience, and export fees that appear only when you try to leave. Read the termination clause before the feature list. It tells you more about the vendor than the demo does.
Integration lock-in
Integration lock-in is the quiet one. The same survey found 47.7% of respondents hit a lack of integration points between their existing management tools, and incompatibility with on-premise software.[1] Every custom connector your vendor builds and holds is a rope you did not know was tied.
Hardware lock-in
Hardware lock-in is the Bangladesh special. Ask whether the devices work with any other system, and whether biometric templates can be exported. Often the honest answer is no, because templates are stored in a proprietary format. That is worth knowing before you buy forty units, and it is a core part of how biometric attendance data gets secured and stored.

That chart is the whole argument in one image. When businesses were asked what actually reduces lock-in risk, 66.4% named making well-informed decisions before selecting a vendor or signing the contract.[1] Not better software. Not a smarter migration later. Better questions, earlier.
What exact questions should you ask before buying?
Bring these to the demo and ask for demonstrations, not descriptions.
| Ask this | A good answer sounds like | Red flag |
|---|---|---|
| Show me a customer leaving. Export everything, now, on screen. | They do it live in the demo without a support ticket. | “We’d arrange that with our team.” |
| What exact formats do exports come in? | Named formats: CSV, XLSX, JSON, with attachments included. | “Standard format” with no name given. |
| Does the export include history, attachments and approval trails? | Yes, with a sample file you can open today. | Current balances only. |
| What does export cost, during and after the contract? | Free, unlimited, self-service, in writing. | A migration or data-retrieval fee. |
| How long do we keep access to our data after termination? | A defined window, typically 30 to 90 days. | Access ends the day billing does. |
| Can we terminate for convenience, and with what notice? | Yes, with a stated notice period. | Auto-renewal with a narrow cancellation window. |
| Is there a documented API we can use ourselves? | Public docs, our own keys, no gatekeeping. | “Integrations are handled by our team.” |
| Do the biometric devices work with other software? | Open protocol, or templates exportable. | Devices tied to their server only. |
| Can we speak to a customer who left you? | They give you a name. | Visible discomfort. |
Ask them to show you the exit, not describe it. A vendor who has built a real export runs it in ninety seconds. A vendor who has not will talk for ten minutes.
That last question in the table is the one I would never skip. A confident vendor has customers who left and came back, or left on good terms. Reluctance to name one tells you the exit has never been tested. Pair these questions with a careful read of the hidden fees buried in cloud HR pricing models, because export charges and migration fees tend to live in the same paragraph.
Does the law protect you from vendor lock-in?
Less than most buyers assume, and this is where I push back on the common advice.
Bangladesh now has a real data protection regime. The Personal Data Protection Ordinance was enacted on 6 November 2025. It recognises every citizen as the owner of their personal data and grants data subjects rights including access, correction, deletion and portability. The Personal Data Protection (Amendment) Ordinance, 2026 then narrowed the data localisation requirement on 5 February 2026, limiting the synchronised local copy rule to Critical Information Infrastructure under the amended Section 29(7)(b).
Here is the catch. Those portability rights belong to the individual employee, not to your company. Your accountant cannot invoke the PDPO to force a vendor to hand over three years of payroll runs. That right does not exist. Data protection law protects the person in the record, not the business holding it.
So your leverage is the contract, and only the contract. The law will not rescue a badly drafted exit clause. Write portability in yourself, before signature, while you still have something the vendor wants.
How do you score a vendor’s lock-in risk?
Score each vendor out of 10 before you compare prices. A cheap system you cannot leave is not cheap. This scorecard turns avoiding vendor lock-in from a worry into a number you can put on a spreadsheet.
| Check | Points | How to verify |
|---|---|---|
| Live self-service export, all data, on demand | 3 | Watch it run in the demo |
| Open, named formats including history and attachments | 2 | Open the sample file yourself |
| Written exit clause: no fees, defined post-termination window | 2 | Read the actual contract text |
| Documented API with your own credentials | 1.5 | Find the public docs online |
| Hardware usable with other systems | 1 | Ask for the device protocol |
| A reference customer who left | 0.5 | Call them |
Anything below 7 needs fixing in the contract before you sign. Above 8 and you have real freedom to change your mind later. Run this alongside a straight comparison of HR software pricing in Bangladesh, and compare the scores next to the quotes.
At Tipsoi we take these questions as fair ones, because we would rather earn year three than trap it. Our exports run on demand in open formats, our attendance and payroll history leaves with attachments and approval trails intact, and our contract terms are written to be readable before signature rather than after. Buyers comparing options across the market can start with this review of the best HR software in Bangladesh and put every vendor, us included, through the same scorecard.
Key takeaways
- Test the exit before you buy. Ask for a live export in the demo, not a promise about one.
- Name the format. “Standard format” means nothing until someone writes CSV, XLSX or JSON into the contract.
- Read the termination clause first. Auto-renewal and export fees are where lock-in actually lives.
- Check the hardware. In Bangladesh, biometric devices tied to one server are a common trap.
- Do not rely on the law. PDPO portability rights belong to your employees, not to your company.
- Score before you price. Freedom to leave is a feature, and it belongs on the comparison sheet.
Frequently asked questions
What is vendor lock-in in simple terms?
Vendor lock-in is when switching providers costs more than staying, even if a better option exists. In HR software the cost is usually trapped data, custom integrations, and hardware that only works with one system.
Is vendor lock-in always deliberate?
No. Small vendors building custom systems create lock-in without intending it, simply by using their own database structure. Unintentional lock-in traps you just as effectively as the deliberate kind.
What data should I be able to export from HR software?
Employee records, full attendance history with timestamps, leave balances and history, payroll runs, approval trails, and document attachments. If any of those stay behind, your export is incomplete.
Can I be charged a fee to get my own data back?
Yes, unless your contract says otherwise. Export and migration fees are common and legal. Make free, unlimited, self-service export a written condition before you sign.
Does the Personal Data Protection Ordinance let me force my vendor to release company data?
No. The Ordinance grants portability rights to individual data subjects over their own personal data. A company cannot use it to compel a vendor to release its business records. That has to come from your contract.
How long should I keep data access after ending a contract?
Aim for 30 to 90 days of continued access in an exportable form, with written certification of deletion afterwards. Migrations slip, and a hard cut-off on the final billing day creates real risk.
What is the single best question to ask a vendor?
“Show me how a customer leaves.” Not tell me. Show me. The demo answers the question faster than any clause you will read.
References
- Opara-Martins, J., Sahandi, R., & Tian, F. (2016). Critical analysis of vendor lock-in and its impact on cloud computing migration: a business perspective. Journal of Cloud Computing: Advances, Systems and Applications, 5(1). https://doi.org/10.1186/s13677-016-0054-z
- Armbrust, M., Fox, A., Griffith, R., Joseph, A. D., Katz, R. H., Konwinski, A., Lee, G., Patterson, D. A., Rabkin, A., Stoica, I., & Zaharia, M. (2010). A view of cloud computing. Communications of the ACM, 53(4), 50-58. https://doi.org/10.1145/1721654.1721672
- Lewis, G. A. (2013). Role of Standards in Cloud-Computing Interoperability. 46th Hawaii International Conference on System Sciences, 1652-1661. https://doi.org/10.1109/hicss.2013.470
- Urquhart, L., Sailaja, N., & McAuley, D. (2017). Realising the right to data portability for the domestic Internet of things. Personal and Ubiquitous Computing, 22(2), 317-332. https://d



