4. of Transfer
We call an API with personal data, but we do not know where the API is being hosted geographically.
Threat |
|
An API you are calling is hosted in the cloud, but you have no idea what data center it’s hosted in. As you are processing EU citizens’ personal data, EU regulations apply. If the data is being processed in a country with less stringent protection of personal data, this would be in violation of GDPR. |
|
GDPR |
Chapter 5, Art. 44 Chapter 5, Art. 45 Chapter 5, Art. 46 |
CCPA & CPRA |
CPRA SEC. 4. Section 1798.100 General Duties of Businesses that Collect Personal Information (d)(2) |
OECD |
Part 4, Basic Principles of International Application: Free Flow and Legitimate Restrictions... |