S0115RS3-T07-S0115-Z · Full risk code

Cross-Border Transfer Violating Localization Requirements

跨境傳輸違反在地化要求

Operation & Monitoring
Risk Description

When an organization adopts an external AI service to process customer data without confirming where processing actually occurs; due to unmitigated control gaps, an audit finds regulated data has been transferred abroad, requiring immediate suspension of the service, notification to the authority, and rebuilding a compliant alternative, triggering compliance exposure and operational reputational costs.

Framework Mappings

EU AI ActArt.10
NIST AI 600-1Data Privacy
ISO/IEC 42001Annex A.7.5、A.10.3
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Confirm actual processing and storage locations before adopting external AI services, ensuring regulated data meets localization requirements; Contractually fix processing locations, cross-border restrictions and change-notification duties; Periodically audit consistency between the provider's declarations and actual practice