Data location and transfers: the clause the question tests
Where the customer's data physically sits and on what basis it crosses a border.
How the customer usually asks it
example"In which countries will our data be stored and processed?"
Anchor clauses
3 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.31 Legal, statutory, regulatory and contractual requirements |
| CSA Cloud Controls Matrix v4.0.1 | DSP-19 Data Location |
| GDPR, Regulation (EU) 2016/679 | Art. 44 General principle for transfers · Art. 46 Transfers subject to appropriate safeguards |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
A list of the countries and facilities where the customer's data is stored, processed and backed up, and the transfer mechanism for each country outside the customer's own region.
The clauses, with what an assessor asks for
ISO 27001 5.31 Legal, statutory, regulatory and contractual requirementsIdentify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
Where answers usually fall short: Outdated legal register; Missing security clauses in contracts
Source: ISO/IEC 27001:2022
CSA CCM DSP-19 Data LocationWhat it asks for, in one line (the standard's own text is not quoted here):
Record the physical locations where data is held, processed and backed up, and be able to produce that record.
Where answers usually fall short: Locations recorded for primary storage with backup and replica locations omitted; Record based on contracted regions rather than actual deployment
Source: CSA Cloud Controls Matrix v4.0.1
GDPR Art. 44 General principle for transfersTransfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.
Where answers usually fall short: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all; The transfer register recording the contracting entity's location rather than the locations the data can actually be accessed from
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 46 Transfers subject to appropriate safeguardsIn the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.
Where answers usually fall short: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined; No assessment of destination law and practice, so the clauses are relied on in a jurisdiction whose law makes them unenforceable
Source: GDPR, Regulation (EU) 2016/679