Security Questionnaire Mapper

Data location and transfers: the clause the question tests

Where the customer's data physically sits and on what basis it crosses a border.

How the customer usually asks it

example

"In which countries will our data be stored and processed?"

Read this question

Anchor clauses

3 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.31 Legal, statutory, regulatory and contractual requirements
CSA Cloud Controls Matrix v4.0.1DSP-19 Data Location
GDPR, Regulation (EU) 2016/679Art. 44 General principle for transfers · Art. 46 Transfers subject to appropriate safeguards

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

A list of the countries and facilities where the customer's data is stored, processed and backed up, and the transfer mechanism for each country outside the customer's own region.

The clauses, with what an assessor asks for

ISO 27001 5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Evidence an assessor expects: Legal register; Contractual obligations; Regulatory filing records; Privacy impact assessments
Where answers usually fall short: Outdated legal register; Missing security clauses in contracts
Source: ISO/IEC 27001:2022
CSA CCM DSP-19 Data Location

What it asks for, in one line (the standard's own text is not quoted here):

Record the physical locations where data is held, processed and backed up, and be able to produce that record.

Evidence an assessor expects: The data location record covering processing, storage and backup sites; The method that keeps it current as infrastructure changes; Evidence it is available to customers or regulators who may ask; Coverage of sub-processor locations
Where answers usually fall short: Locations recorded for primary storage with backup and replica locations omitted; Record based on contracted regions rather than actual deployment
Source: CSA Cloud Controls Matrix v4.0.1
GDPR Art. 44 General principle for transfers

Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

Evidence an assessor expects: A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on; The onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism; Evidence that remote access from a third country was assessed as a transfer alongside physical movement of data; The reasoning that the level of protection is not undermined by the arrangement as a whole, not only by the chosen instrument
Where answers usually fall short: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all; The transfer register recording the contracting entity's location rather than the locations the data can actually be accessed from
Source: GDPR, Regulation (EU) 2016/679
GDPR Art. 46 Transfers subject to appropriate safeguards

In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

Evidence an assessor expects: The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank; The transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there; The supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place; Supervisory authority authorisation where ad hoc contractual clauses or administrative arrangements are relied on; Evidence that data subjects can in practice exercise the rights the instrument confers, such as an operable third party beneficiary route
Where answers usually fall short: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined; No assessment of destination law and practice, so the clauses are relied on in a jurisdiction whose law makes them unenforceable
Source: GDPR, Regulation (EU) 2016/679

Other families in data protection and encryption