risk
Cross-border personal-data transfer without safeguards
Transferring personal data to jurisdictions lacking equivalent protection without SCCs, BCRs, adequacy decisions, or other recognized mechanisms, exposing individuals and the organization to legal risk.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- privacy
- domain
- Data Protection & Privacy
- Compliance, Audit & Assurance
- Third-Party / Supply-Chain Risk
- taxonomy
- nist-privacy-risk
- enterprise-risk
- inherent_rating
- medium
Details
- risk_id
- privacy-cross-border-transfer
- category
- privacy
- likelihood
- medium
- impact
- medium
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- nist-privacy-risk
- enterprise-risk
Source
No record-specific source URL is provided.
Connections
- UC-TPRM-03 — Bind vendors to security and privacy terms by contract mitigates Cross-border personal-data transfer without safeguards
- strength
- primary
- rationale
- Ensuring agreements satisfy the contractual clauses mandated by privacy regulations (e.g., GDPR transfer clauses/SCCs) directly enables safeguarded cross-border transfer.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates Cross-border personal-data transfer without safeguards
- strength
- primary
- rationale
- Transferring personal data only under a valid mechanism (adequacy/SCC/BCR/derogation) with recorded safeguards directly prevents unsafeguarded cross-border transfers.