7. of Transfer
Our systems are being administered from outside the EU, but admin access is not personal data access, right?
Threat |
|
You have not implemented the principle of least privilege on your systems. Due to that, an administrator has access to everything, whenever they want. So, by accessing this information, they are effectively exporting the information to another state outside of the EU. |
|
GDPR |
Chapter 5, Art. 44 Chapter 5, Art. 45 Chapter 5, Art. 46 |
CCPA & CPRA |
CPRA SEC. 4. Section 1798.100 General Duties of Businesses that Collect Personal Information (d)(2) |
OECD |
Part 4, Basic Principles of International Application: Free Flow and Legitimate Restrictions 16 and 17 |