unified

UC-DATA-11 — Control data flows, leakage, and cross-border transfers

Enforce approved authorizations for information flows within and between systems using technical flow-control mechanisms, and deploy data-leakage-prevention measures on systems and channels that could exfiltrate sensitive data. Transfer personal data across borders only under a valid transfer mechanism (adequacy decision, standard contractual clauses, binding corporate rules, or a documented derogation), with the transfer risk assessed and the safeguard recorded.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Data Protection & Privacy
type
preventive
category
technical

Details

unified_id
UC-DATA-11
title
Control data flows, leakage, and cross-border transfers
statement
Enforce approved authorizations for information flows within and between systems using technical flow-control mechanisms, and deploy data-leakage-prevention measures on systems and channels that could exfiltrate sensitive data. Transfer personal data across borders only under a valid transfer mechanism (adequacy decision, standard contractual clauses, binding corporate rules, or a documented derogation), with the transfer risk assessed and the safeguard recorded.
domain
Data Protection & Privacy
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    AC-4
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.12
    coverage
    full
    relationship
    superset_of
  • framework
    gdpr
    control_id
    GDPR-Art44-49
    coverage
    full
    relationship
    superset_of
  • framework
    aiuc-1
    control_id
    A004
    coverage
    partial
    delta
    leakage of intellectual property and confidential information through AI system outputs, requiring model-output safeguards beyond network and channel flow controls
    relationship
    intersects_with
  • framework
    aiuc-1
    control_id
    A005
    coverage
    partial
    delta
    tenant isolation inside AI systems: retrieval indexes, memory, fine-tuning data, and caches segregated so one customer's data cannot surface in another customer's outputs
    relationship
    intersects_with
guidance
  • source
    nist-ai-agent-identity
    sourceTitle
    NIST NCCoE: Software and AI Agent Identity and Authorization
    propositionId
    NIST-AGI-07
    propositionTitle
    Prompt provenance and data-flow tracking
    sourcePages
    Concept paper p. 6: Tracking Data Flows of an AI System
  • source
    nist-ai-tevv-athlon
    sourceTitle
    NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems
    propositionId
    NIST-TEVV-04
    propositionTitle
    Test for disclosure of confidential information
    sourcePages
    NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks

Source

No record-specific source URL is provided.

Connections