unified
UC-DATA-11 — Control data flows, leakage, and cross-border transfers
Enforce approved authorizations for information flows within and between systems using technical flow-control mechanisms, and deploy data-leakage-prevention measures on systems and channels that could exfiltrate sensitive data. Transfer personal data across borders only under a valid transfer mechanism (adequacy decision, standard contractual clauses, binding corporate rules, or a documented derogation), with the transfer risk assessed and the safeguard recorded.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Data Protection & Privacy
- type
- preventive
- category
- technical
Details
- unified_id
- UC-DATA-11
- title
- Control data flows, leakage, and cross-border transfers
- statement
- Enforce approved authorizations for information flows within and between systems using technical flow-control mechanisms, and deploy data-leakage-prevention measures on systems and channels that could exfiltrate sensitive data. Transfer personal data across borders only under a valid transfer mechanism (adequacy decision, standard contractual clauses, binding corporate rules, or a documented derogation), with the transfer risk assessed and the safeguard recorded.
- domain
- Data Protection & Privacy
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AC-4
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.12
- coverage
- full
- relationship
- superset_of
- framework
- gdpr
- control_id
- GDPR-Art44-49
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- A004
- coverage
- partial
- delta
- leakage of intellectual property and confidential information through AI system outputs, requiring model-output safeguards beyond network and channel flow controls
- relationship
- intersects_with
- framework
- aiuc-1
- control_id
- A005
- coverage
- partial
- delta
- tenant isolation inside AI systems: retrieval indexes, memory, fine-tuning data, and caches segregated so one customer's data cannot surface in another customer's outputs
- relationship
- intersects_with
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-07
- propositionTitle
- Prompt provenance and data-flow tracking
- sourcePages
- Concept paper p. 6: Tracking Data Flows of an AI System
- source
- nist-ai-tevv-athlon
- sourceTitle
- NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
- propositionId
- NIST-TEVV-04
- propositionTitle
- Test for disclosure of confidential information
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks
Source
No record-specific source URL is provided.
Connections
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates Data exfiltration and theft of information by attackers
- strength
- primary
- rationale
- Data-leakage-prevention on systems/channels plus technical flow-control directly block exfiltration of sensitive data.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers maps_to GDPR-Art44-49 — International transfers of personal data
- framework
- gdpr
- control_id
- GDPR-Art44-49
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Regulation (EU) 2016/679
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-11 — Control data flows, leakage, and cross-border transfers
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates Privacy-program non-compliance (GDPR, CCPA, state laws)
- strength
- related
- rationale
- Valid, documented transfer mechanisms remove the invalid-cross-border-transfer driver of non-compliance.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers maps_to A005 — Prevent cross-customer data exposure
- framework
- aiuc-1
- control_id
- A005
- coverage
- partial
- delta
- tenant isolation inside AI systems: retrieval indexes, memory, fine-tuning data, and caches segregated so one customer's data cannot surface in another customer's outputs
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Enforcing approved information-flow authorizations and DLP directly prevents data leaking to parties not entitled to it.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers informed_by NIST-TEVV-04 — Test for disclosure of confidential information
- framework
- nist-ai-tevv-athlon
- control_id
- NIST-TEVV-04
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- NIST AI 200-2 ipd (Initial Public Draft), August 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers maps_to A.8.12 — Data leakage prevention
- framework
- iso-27001
- control_id
- A.8.12
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers maps_to AC-4 — Information Flow Enforcement
- framework
- nist-800-53
- control_id
- AC-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers maps_to A004 — Protect IP & trade secrets
- framework
- aiuc-1
- control_id
- A004
- coverage
- partial
- delta
- leakage of intellectual property and confidential information through AI system outputs, requiring model-output safeguards beyond network and channel flow controls
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Network Segmentation & Boundary Rule Management operates UC-DATA-11 — Control data flows, leakage, and cross-border transfers
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates Cross-border personal-data transfer without safeguards
- strength
- primary
- rationale
- Transferring personal data only under a valid mechanism (adequacy/SCC/BCR/derogation) with recorded safeguards directly prevents unsafeguarded cross-border transfers.
- Security Control Assessment & POA&M Remediation tests UC-DATA-11 — Control data flows, leakage, and cross-border transfers
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- DLP on exfiltration channels catches inadvertent user spillage of sensitive information.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers informed_by NIST-AGI-07 — Prompt provenance and data-flow tracking
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-07
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper p. 6: Tracking Data Flows of an AI System