With this split, three have short answers. And the fifth has to be asked more carefully than anywhere else.
Where the recordings live: in your installation, on your drive, and that settles half the conversation with the legal department. What is outside is the users, the permissions, the status of the units and the route you come in through to watch — and the video is seen over that route, so by design the supplier has an administration door. Minimum permissions, two-factor and a visible access log: the same as with the others.
If the line goes down everything carries on recording at the site, with nothing lost, because the recorder does not need the cloud to work. What goes down is the management and the access from outside. For places with bad connections, that is the main argument.
The cost of uploading video: small and predictable, because the video is not uploaded. Status data and thumbnails go up, and video when somebody watches or when a copy of something specific has been configured. A site with a modest line copes with this, which with a lot of small sites is no small detail.
RGPD and international transfers: there is less surface than with a pure cloud because the images are not stored outside, and there is still processing —accounts, access logs, metadata and the ability to view through the service—. Ask for the usual: a processor contract, guarantees for the transfer, the region in writing and information given to the staff.
And the dependency, which here has to be asked about more carefully: what happens to the unit at the site if you leave the service? Does it carry on recording? Can you get in to watch it and to export locally, without the cloud, and with which functions? You need that answer from the manufacturer, in writing, before you buy. On the good side: the cameras are standard and they stay.