#79: Risk Register / External, Market & Compliance Risks
Status: Analyzing
Due: Oct 10, 2027
Assignees: Katherine Newman

Risk statement. Proposed guidance would require EU personal data to remain within EU infrastructure. Our primary datastore is US-hosted with EU replication only for failover. About 30% of revenue comes from EU customers.

Trigger / early warning. Publication of binding guidance, or a customer DPA requiring EU-only residency.

Consequence if realised. A regional data-partitioning project on a regulatory deadline rather than our own schedule, plus possible contract breaches during the gap.

Current response. Mitigate. Establish what a compliant architecture actually requires now, so that if guidance lands we are executing rather than investigating.

Risk ID:

R-18


Date Identified: Jul 25, 2027
Likelihood: 2 · Unlikely
Impact: 5 · Severe
Response Strategy: Mitigate
Risk Score: 10
Category: Compliance & Legal
Risk Level: High (10-14)
Created by Vicky Aug 7, 2026, Edited Aug 7, 2026