CRISC Certified in Risk and Information Systems ControlGovernanceMedium

An organization is migrating its sensitive customer data to a new cloud service provider. The due diligence process identified that the cloud provider's data centers are located in a jurisdiction with less stringent data protection laws than the organization's home country. Which of the following is the MOST appropriate action to ensure legal and regulatory compliance and maintain trust?

  1. ACancel the migration entirely, as any use of a less stringent jurisdiction is inherently non-compliant.
  2. BSeek a waiver from regulatory bodies in the home country due to the cost savings offered by the new cloud provider.
  3. CImplement robust contractual clauses with the cloud provider, including data processing agreements and specific security controls, exceeding the provider's local legal minimums.
  4. DProceed with the migration, assuming that the cloud provider's standard contracts offer sufficient protection.
Show answer & explanation

Correct answer: C. Implement robust contractual clauses with the cloud provider, including data processing agreements and specific security controls, exceeding the provider's local legal minimums.

Contractual agreements, particularly Data Processing Agreements (DPAs) and specific security clauses, can bridge the gap between differing legal jurisdictions, ensuring the organization's compliance obligations are met and demonstrating due diligence.

Why the other options are wrong

  • A. Canceling the migration might be an option of last resort but is not the 'MOST appropriate' immediate action. Contractual measures often provide a viable solution without completely abandoning the project.
  • B. Regulatory bodies are unlikely to grant waivers based solely on cost savings, especially for sensitive data, and this does not address compliance.
  • D. Assuming standard contracts are sufficient is risky; they may not address the specific requirements of the organization's home jurisdiction.

Cross-Jurisdictional Data Protection

The practice of using robust contractual agreements, such as Data Processing Agreements (DPAs) and specific security clauses, to ensure compliance with an organization's home jurisdiction's data protection laws when processing data in a jurisdiction with less stringent regulations.

  • Crucial for legal and regulatory compliance.
  • Maintains data subject trust.
  • Mitigates risks associated with varying international laws.

Memory trick: When cloud laws differ, contractually bind for safety and trust.

More Governance questions