DAT-03Data and Privacy

Deliberate data sharing

Data leaves the organization only through a decided channel, with a defined end and a record of what was shared.

Why it exists

Most exposure is not a breach; it is sharing nobody ended.

What usually proves it

Sharing decision records, data room logs, revocation evidence.

Smaller organizations

A record per share, and a close-out when it ends.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC6.7
  • Fully addressedISO/IEC 27001 Annex A · A.5.14
  • Fully addressedNIST Cybersecurity Framework · PR.DS-02
  • Fully addressedPCI DSS · 4.2.1
  • Fully addressedHIPAA Security Rule · 164.308(b)
  • Fully addressedGDPR · Art. 28, 44
  • Deliberately absentEU AI Act — No general data sharing duty; obligations attach to the AI system and its documentation.
  • Partially addressedNIST AI Risk Management Framework · MAP 4.1 — Third-party data flows are mapped.