DAT-03Data and Privacy
Deliberate data sharing
Data leaves the organization only through a decided channel, with a defined end and a record of what was shared.
Why it exists
Most exposure is not a breach; it is sharing nobody ended.
What usually proves it
Sharing decision records, data room logs, revocation evidence.
Smaller organizations
A record per share, and a close-out when it ends.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC6.7
- Fully addressedISO/IEC 27001 Annex A · A.5.14
- Fully addressedNIST Cybersecurity Framework · PR.DS-02
- Fully addressedPCI DSS · 4.2.1
- Fully addressedHIPAA Security Rule · 164.308(b)
- Fully addressedGDPR · Art. 28, 44
- Deliberately absentEU AI Act — No general data sharing duty; obligations attach to the AI system and its documentation.
- Partially addressedNIST AI Risk Management Framework · MAP 4.1 — Third-party data flows are mapped.