8.5.2 Countries and international organizations to which PII can be transferred
The organization must specify and document the countries and international organizations to which personal data can possibly be transferred, making those identities available to customers and including countries arising
4
artefacts
0
held by a system
1
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Evidence the list is available to customers and kept current · Document repository
governing documentDocuments that govern the control
- Documented destination list covering the organization and its subcontractors · Document repository
- Reconciliation between destinations and the transfer bases held · Document repository
- Maintenance process triggered by supply chain and regional change · Document repository
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Destination list covering hosting regions while support, monitoring and development locations are omitted
- Subcontractor destinations excluded, which is the most common gap and the one customers most need
- List published at onboarding and never refreshed as the platform expands regionally
- Destinations listed with no transfer basis behind some of them
- Follow the sun support arrangements not recognised as creating destinations
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.5.1 Basis for PII transfer between jurisdictions · 8.5.3 Records of PII disclosure to third parties