Not one of them is really technical. All five are contract questions, and they get answered before you buy or they never get answered.
Where the recordings live and who can get in. The video, in the camera; the index, the users and the permissions, at the supplier — which by design has an administration route into your system. That calls for minimum permissions, mandatory two-factor, an access log you can see, and in writing who at the manufacturer can see what. There have been incidents like that in this industry, and trust does not prevent them.
What happens when the line goes down. Recording carries on, because it records in the camera. What you lose is the console: no live view from outside, no alerts, no search. For most installations that is fine; for a control room watching live, it is not.
The cost of uploading video. Continuously it uploads little. The usage appears when somebody watches and it multiplies by each person watching at the same time: a shop with a tight line works right up to the day of the incident, which is when three people open six cameras.
RGPD and international transfers. A supplier from outside the EU: you have to be able to explain to a supervisory authority which region the data is stored in, which processor contract and which safeguards cover the transfer, and what analysis was done beforehand. You ask for it in writing for your contract and your region. And then there is the part that gets forgotten: telling the staff, and making the record of processing activities say what really happens.
And the dependency. The day you want to leave, the cameras do not go with you: they cannot be reused with another system. The recording is got out by exporting while the licence is alive, and when it expires there is no local way in to see what is inside. It is not a hidden defect, it is the model — what you cannot do is find it out in year five.