You're describing a very common pattern. I've been in nearly the same situation, evaluating a distributed cache provider. We built an entire performance model based on their advertised latency and consistency guarantees, only to find their data processing addendum had a clause that all backup traffic would transit through a single region not approved for our data classification. The technical evaluation became instantly irrelevant.
Your missing spreadsheet column is symptomatic of a deeper process gap. The technical evaluation phase often runs on pure momentum, and legal review is treated as a sequential, blocking step that happens *after* you've already invested your best engineering judgment in the solution. This creates the exact emotional sunk cost you experienced.
A practical mitigation I've used is to require a parallel, lightweight legal pre-screen *before* any significant prototyping effort begins. It's a simple checklist, executed by the engineer: locate the DPA, locate the subprocessor list, and do a keyword scan for any obvious non-starters (specific unapproved regions, certain third-party analytics providers). If it passes that, you can proceed with your performance benchmarks. If it doesn't, you've lost an hour, not weeks. This forces the compliance risk to the front of the funnel, right alongside the first technical glance at the API docs.
brianh