Home/Questions/Data handling and policy/Cross-border transfers
Data handling and policy

Is the Applicant compliant with cross-border data transfer laws?

Most organisations transfer data internationally without deciding to, because their cloud services and their vendors do it on their behalf.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether transfers of personal data across borders are lawful under the applicable regimes, which usually means the European framework and its equivalents. The mechanisms are contractual clauses, adequacy decisions, and certification frameworks, supported by an assessment of the destination country.

Why it is underwritten

Regulatory exposure for unlawful transfers is separate from breach exposure and can be substantial. It also affects incident handling, since a breach involving data of European residents triggers notification obligations regardless of where your systems sit. Carriers ask because it determines which regulators may be involved.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Where your data physically resides is measurable in the cloud. Whether the transfers are lawful is a legal determination.

PlatformWhere the setting livesWhat has to be true
AzureResource regions and the regions of paired replicasWhere data resides and where it replicates, including the paired region used for geo-redundancy
Microsoft 365Tenant data location and multi-geo configurationThe declared data residency for each workload, which differs by workload more than most people expect
AzureBackup and log destinationsWhere backups and telemetry land, since these frequently cross borders when the primary data does not
Vendor registerSub-processors and their locationsA maintained sub-processor list with locations, which is where most unnoticed transfers occur
Legal documentsStandard contractual clauses, transfer impact assessments, and framework certificationsExecuted and current for each transfer. Attested
Support access is a transfer

A vendor whose data is stored in your region but whose support team accesses it from elsewhere is transferring data. This is the most commonly missed transfer in any vendor estate, and it is usually disclosed in the sub-processor list nobody reads.

What a defensible yes requires

  • Data residency is known per workload rather than assumed from the tenant setting.
  • A sub-processor register exists with locations, and it is reviewed when vendors update it.
  • Transfer mechanisms are executed and current for each transfer.
  • Transfer impact assessments exist where the regime requires them.
  • Backups, logs, and support access are included in the analysis, not only primary storage.

How this answer goes wrong

The organisation selected a European region and considers the question closed. Its telemetry goes to a workspace elsewhere, its support vendor accesses systems from a third country, and its backup copies land in a paired region it never chose. None of that was a decision, and all of it is a transfer.

Frequently asked

Does this apply if we are entirely domestic?

Only if you hold data about residents of other jurisdictions, which happens more often than expected through customers, employees, and website visitors.

Is choosing a local cloud region enough?

It handles primary storage. Backups, logs, telemetry, and support access frequently sit elsewhere and need separate consideration.

Do we need a transfer impact assessment?

Under the European framework, generally yes for transfers to countries without an adequacy decision. Counsel should confirm which of your transfers require one.

How does this affect a claim?

It determines which regulators are involved and which notification deadlines apply, which affects the cost and speed of the response the carrier funds.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture