DTG-CB19 · Cross-Border Data · 4 min

The API Call That Crossed a Border and Triggered an Obligation Nobody Anticipated

The integration was straightforward: the new analytics vendor's API received event data from the organization's mobile application. The API call was a standard HTTP reque…

DTG-CB17 · Cross-Border Data · 4 min

US State Privacy Laws Are Converging on Principles and Diverging on Everything Else

Twenty states have enacted comprehensive consumer privacy laws. More are in progress. The laws share a common conceptual architecture: consumer rights, controller and pro…

DTG-CB14 · Cross-Border Data · 4 min

Incident Response Across Jurisdictions: Different Clocks, Different Regulators, Same Breach

The breach affected customer data across fourteen countries. The incident response team started the 72-hour GDPR notification clock from the moment awareness was establis…

DTG-CB12 · Cross-Border Data · 4 min

Data Sovereignty Is a Boardroom Issue That Gets Delegated to Legal and Forgotten

Data sovereignty is the principle that data is subject to the laws and governance of the jurisdiction in which it is located. For organizations operating globally, data s…

DTG-CB11 · Cross-Border Data · 4 min

Government Access Requests Across Jurisdictions: What Your Privacy Policy Doesn't Say

Privacy policies describe how the organization handles personal data. They describe the purposes of processing, the legal bases, the rights individuals can exercise, and…

DTG-CB08 · Cross-Border Data · 4 min

The Schrems II Implications That Your Legal Team and Engineering Team Still Haven't Resolved

Schrems II was decided in July 2020. Standard contractual clauses were updated in June 2021. Transfer impact assessments were introduced as a requirement for demonstratin…

DTG-CB04 · Cross-Border Data · 4 min

Data Localization at Enterprise Scale Is an Architectural Problem, Not a Legal One

Data localization requirements tell organizations where data must be stored. They are legal requirements created by legislators. The compliance response to data localizat…

DTG-CB03 · Cross-Border Data · 5 min

Where Is Your Customer Data Right Now, in Which Country, and Under Which Law?

Answer the question precisely. Not in general terms — not 'primarily in the EU' or 'stored in our cloud provider's data centers.' Name the countries.

DTG-282 · Cross-Border Data · 8 min

Data Processing Categories Don't Align Across Regulations

GDPR defines personal data. CCPA defines personal information. PIPL defines personal information. The definitions are similar enough to seem interchangeable.

DTG-275 · Cross-Border Data · 11 min

Opt-Out Mechanisms Exist. They Do Not Propagate Across Systems

A consumer exercises their opt-out right. The mechanism is compliant. The signal is recorded. And then it stops propagating, because the architecture was not built to car…

DTG-270 · Cross-Border Data · 8 min

Global Data Governance Requires Localized Control Models

A global data governance framework defines principles, standards, and policies that apply across the organization. A localized control model implements those principles i…

DTG-269 · Cross-Border Data · 10 min

Cross-Border Data Risk Is Identified. It Is Not Actively Managed

Organizations identify cross-border data risks in assessments, document them in records of processing activities, and note them in risk registers.

DTG-267 · Cross-Border Data · 10 min

Regulatory Obligations Vary. Systems Do Not Adapt

Global enterprises operate under different regulatory obligations in different jurisdictions. Their systems were built for efficiency, not jurisdictional differentiation.

DTG-266 · Cross-Border Data · 8 min

Cross-Border Incident Response Is Slower Than Risk Propagation

Security incidents in cross-border data environments do not wait for regulatory notification timelines, governance approval chains, or the coordination complexity of mult…

DTG-264 · Cross-Border Data · 10 min

Data Is Stored in One Region. It Is Processed Everywhere

Data residency controls where data rests. It does not control where data is processed, accessed, or analyzed. In cloud architectures, processing routinely occurs across r…

DTG-263 · Cross-Border Data · 9 min

Encryption Protects Data. It Does Not Address Jurisdictional Exposure

Encryption is a technically effective data protection control. It prevents unauthorized access to data in transit and at rest. It does not prevent authorized access, incl…

DTG-262 · Cross-Border Data · 10 min

Data Flows Through Vendors Faster Than Governance Can Track

Your data governance program maps the flows you know about. Vendor ecosystems create flows you did not design, did not authorize, and may not know exist.

DTG-258 · Cross-Border Data · 10 min

Subprocessor Chains Extend Beyond Organizational Visibility

You contracted with a vendor. You reviewed their DPA. You confirmed their security certifications. What you did not do is follow your data through the subprocessors they…

DTG-256 · Cross-Border Data · 11 min

Data Sovereignty Conflicts with Distributed Systems by Design

Data sovereignty requires that data stay within a defined jurisdiction. Distributed systems are architecturally designed to move data across boundaries for resilience, pe…

DTG-255 · Cross-Border Data · 8 min

Data Localization Strategies Break Under Cloud Architectures

Data localization requires that data stay within defined geographic boundaries. Cloud architectures are designed to distribute data across boundaries for performance, ava…

DTG-254 · Cross-Border Data · 10 min

SCCs Provide Legal Cover. Not Operational Control

Standard Contractual Clauses create a legal framework for cross-border data transfers. They do not create operational controls that constrain what happens to data after i…

DTG-252 · Cross-Border Data · 8 min

Cross-Border Data Flows Exist. Even When You Think They Do Not

Organizations document the cross-border data flows they know about. The flows they do not know about are determined by how their technology architecture actually behaves.

DTG-251 · Cross-Border Data · 10 min

Data Residency Is Defined. Data Movement Ignores It

Data residency defines where data should be. Data movement defines where data goes. In modern enterprise architectures, these two things are frequently different, and the…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center