Discussion
Open questionLast verified: 2026-08-13
- AuthorPosts
- 31st August 2026 at 8:58 am #3445
A vendor may say that data stays in one country while backups, logs, or support access occur elsewhere. What exactly needs clarification?
31st August 2026 at 9:45 am #3446Accepted answerMap every data type and processing location, including primary storage, backups, logs, analytics, support access, subprocessors, and disaster recovery. Distinguish storage locations from remote access and legal control. Put permitted regions, change notices, evidence, deletion, and exception handling into the agreement. The NIST Privacy Framework supports identifying and managing privacy risk across all data processing, not only the main database.
2nd September 2026 at 3:44 am #3520Community replyWould allowing access from another country violate a data residency requirement even if the storage remains local?
- AuthorPosts
- You must be logged in to reply to this topic.