Status: Analyzing
Due: Oct 10, 2027
Assignees: Katherine Newman
Risk statement. Proposed guidance would require EU personal data to remain within EU infrastructure. Our primary datastore is US-hosted with EU replication only for failover. About 30% of revenue comes from EU customers.
Trigger / early warning. Publication of binding guidance, or a customer DPA requiring EU-only residency.
Consequence if realised. A regional data-partitioning project on a regulatory deadline rather than our own schedule, plus possible contract breaches during the gap.
Current response. Mitigate. Establish what a compliant architecture actually requires now, so that if guidance lands we are executing rather than investigating.
Risk ID:
Date Identified: Jul 25, 2027
Likelihood: 2 · Unlikely
Impact: 5 · Severe
Response Strategy: Mitigate
Risk Score: 10
Category: Compliance & Legal
Risk Level: High (10-14)
R-18
Date Identified: Jul 25, 2027
Likelihood: 2 · Unlikely
Impact: 5 · Severe
Response Strategy: Mitigate
Risk Score: 10
Category: Compliance & Legal
Risk Level: High (10-14)
Created by Vicky Aug 7, 2026, Edited Aug 7, 2026