Data Sovereignty / Source date:

Remote Work Creates Accidental Cross-Border Data Flows

Staff working from other countries moved regulated data across jurisdictions without any policy review.

Illustration of a traveller packing work equipment and return paperwork beside luggage in a temporary residence.

Every transfer register in existence describes systems: this database sits here, that platform replicates there, this processor is in Ireland and its sub-processor is in Virginia. It is a sound way to document architecture and it missed almost everything that happened this year, because the cross-border data flows created in 2020 were not created by systems. They were created by people, and a person is a transfer mechanism that relocates without raising a change request. Nine months on, most organisations are operating with a data map that was accurate in February and a workforce that is not where the map says it is.

Four ways the map broke

People moved and kept working. Someone went home when the borders looked like they were closing, intended to be away for three weeks, and has now been processing customer records from another country for eight months. Payroll did not change, the org chart did not change, and nothing in any system recorded a new country. Work was reassigned. Queues were shifted to whichever site could still operate. Support rotas were rebuilt around who had power, connectivity and permission to work. Approval chains were rerouted to whoever was reachable. Each of those decisions moved a body of data to a new set of eyes in a new jurisdiction, and each was taken by an operations manager solving a staffing problem in an afternoon. Tooling created new destinations. The video platform with a default routing region nobody chose, the storage location picked by whoever first clicked through the setup, the transcription service, the electronic signature provider, the survey tool, the scheduling app. Two dozen small purchases made on cards in March, each with its own hosting geography and its own sub-processors. Copies landed on endpoints. The exported spreadsheet, the downloaded report, the attachment saved to a desktop, the document printed at home because the approval needed a signature. Every one of those is a copy in a place that appears in no inventory, and this is the category that persists longest, because deleting it requires someone to remember it exists. Notice what these have in common. None of them was a technology decision, none passed through architecture review, and none would be caught by re-running the exercise that produced the original register.

Review the human changes behind the data mapQualitative prompts from the article, not a legal conclusion that every employee access event is a regulated international transfer.
ChangeRecord to revisit
People relocatedApproved work locations and dated exceptions.
Work reassignedEntity responsibilities and authorised access.
New tools adoptedProcessor records, routing and retention settings.
Local copies createdEndpoint controls and return or deletion arrangements.

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Why "access is a transfer" ruins the register

The conceptual problem underneath all of this is that remote access to data held elsewhere is generally treated as a transfer to the place the person is sitting. Accept that and the consequence is uncomfortable: your transfer picture is a function of where your people physically are, it changes weekly, and it cannot be maintained as a document. So stop trying. A register that must be accurate about the location of 400 individuals on any given Tuesday is not a control; it is a clerical fiction that will be wrong the day it is signed. The workable answer is to make location either irrelevant or knowable. Location becomes largely irrelevant when the data stays in the service and only pixels reach the endpoint: no local downloads, no synchronised folders, no exports to a personal drive. That single control eliminates the worst category, the uncontrolled copy in an unknown place, and it is a technical setting rather than a policy statement. Location becomes knowable when you decide in advance which countries are approved for work, enforce it with conditional access rather than an email, and run a short exception process for everything else. A named approval, a start date, an end date, an owner and a recorded justification. Twenty exceptions with dates are manageable. Four hundred unrecorded relocations are not.

The reverse failure nobody admits

There is a second pattern, and it is the one compliance teams consistently misdiagnose. Data ended up in the wrong places this year not because people were careless, but because the sanctioned route was unusable. Remote access was slow, the approved file share timed out, the secure transfer tool required a ticket and a day, and there was a customer waiting. So the file went to a personal account, or onto the laptop, or through a messaging app. A rule that forbids the workaround without fixing the underlying performance problem simply relocates the workaround somewhere less visible. If you are going to prohibit local copies, the in-service path has to be fast enough to use.

Why this becomes urgent in the next three weeks

Two dates make December the moment to deal with this. The first is your own year-end. Records of processing are refreshed, statutory audit begins, and customer assurance questionnaires arrive with the new year. A significant number of organisations are about to assert, in writing, that personal data is processed only in stated countries, while their own human resources records would contradict that if anyone joined the two together. The second is the end of the transition period on 31 December. Absent a decision on adequacy, the United Kingdom becomes a third country for these purposes at the turn of the year, which will convert a large volume of entirely ordinary intra-European flows into transfers requiring clauses and an assessment, overnight, in the middle of a holiday period. Anyone with staff, a service centre, a subsidiary or a processor in the UK should be treating the next fortnight as a deadline, not as a wait-and-see.

Practical Guidance for Workforce Location Compliance Review

  • Reconcile human resources records, payroll and aggregate sign-in country data once, this month. Use it to establish where processing actually occurs, and say plainly in the policy that this is a location check for legal purposes and not individual surveillance.
  • Publish an approved country list and enforce it with conditional access. A policy that lives only in a handbook produces no evidence and changes no behaviour.
  • Run a dated exception register for temporary relocations. Start, end, owner, justification, and an automatic expiry so it cannot quietly become permanent.
  • Turn off local downloads and folder synchronisation for sensitive categories. Keeping the data in the service is the single highest-value control available here.
  • Make the sanctioned path fast before you prohibit the workaround. Unusable controls create invisible flows.
  • Add the tools bought on cards in March to the processor list. Check hosting region and sub-processors, and cancel what nobody uses.
  • Check your customer commitments against reality before renewal season. If a contract names processing locations, verify rather than assume.
  • Prepare UK-related flows now for 1 January. Clauses in place, assessment drafted, and a fallback if adequacy does not arrive in time.

The Regional Angle

Four things make this materially sharper in the Gulf. The first is scale. This region experienced a workforce dispersal in 2020 that most markets did not. Large numbers of employees travelled home in the spring, then could not return for months; others were furloughed, resigned or were made redundant and continued working out a notice period from another country. The result is that finance, human resources, IT and customer service work that was performed in Dubai, Riyadh or Doha in January has been performed for much of this year from Kochi, Karachi, Cairo, Manila, Amman and Beirut. In almost every case nobody executed a document, and in many cases the human resources record still shows the person as resident here. If your organisation is answering a European customer's questionnaire about processing locations, that is the gap that will be found. Second, the "we did not know where people were" position is weaker here than almost anywhere else, because an authoritative external record exists. Residency, sponsorship and immigration systems in Gulf states hold entry and exit data, and a regulator, an auditor, a court or a counterparty can obtain evidence of who was physically outside the country and for how long. That is not true in most markets, where location is genuinely difficult to establish after the fact. Assume the factual record can be produced, and write your compliance position against the facts rather than against the org chart. Third, intra-group work moves here by instruction rather than by agreement. When one entity's team was closed or short-staffed, another entity's team absorbed the work, frequently across borders, with no addendum, no processing terms and no notification to anyone. That is an ungoverned transfer even when it stays within the group and inside the region, and it becomes a harder problem where sector rules apply: bank and health records that must remain accessible only within a jurisdiction do not stop being restricted because the person opening the file is a colleague in a sister company. Fourth, watch the devices themselves. Laptops left on what was intended to be a short trip and stayed away for months, transiting countries whose authorities may inspect or image devices at the border, and ending up in homes where recovery depends entirely on goodwill. A device you cannot compel the return of, in a country where you have no entity, holding local copies of customer data, is the practical worst case in this whole discussion, and it is considerably more common in this region than anyone's risk register suggests.

The objection worth taking seriously

The strongest objection is that this is an abstraction being treated as a harm. No data subject has suffered because an accountant opened a receivables ledger from her parents' house in another country during a pandemic. Classifying that as an international transfer requiring an assessment, clauses and supplementary measures stretches a concept designed for outsourcing arrangements until it covers ordinary human circumstance, and it generates a great deal of documentation that protects nobody. Compliance functions that spent this year chasing individual laptops were, on this view, performing paperwork while the actual risks sat elsewhere. There is real force in that, and the proportionate response is not to pretend otherwise. Two exposures survive the objection, and neither is about surveillance. The first is contractual. Many organisations have told customers in writing where their data is processed and by whom. If that statement is now false, the consequence is not an abstract regulatory risk; it is a misrepresentation that surfaces during a customer audit and costs a renewal. The second is recoverability. Copies of data on endpoints in countries where you have no entity, no legal presence and no practical means of enforcing return or deletion are a genuine loss of control, and that risk materialises most often not through espionage but through an ordinary resignation, a dispute, or a stolen laptop. Which argues for exactly the proportionate posture: approve a broad list of countries rather than fighting each case, control the endpoint so copies do not accumulate, keep a short exception register for the genuinely sensitive work, and stop treating the register itself as the control.

Common Questions

Is an employee working abroad really an international transfer?

On the prevailing view, remote access from another country is treated as a transfer to that country. Whether that is sensible is arguable; it is nonetheless the basis on which your customers and their regulators will assess you.

Do we need clauses for our own employees?

Between your own entities in different countries, usually yes in some form, because the entities are separate controllers or processors. Within a single legal entity it is not a transfer between parties, but the access, security and local law questions still apply.

How do we handle someone who simply will not come back?

As a location change, not an exception: update the record, check whether the work may lawfully be performed there, fix the access controls, and deal with the employment and tax consequences through the proper channel rather than by ignoring them.

What should we expect over the next twelve months?

Expect the UK position to dominate January, whatever is or is not agreed in the next fortnight. Expect "work from anywhere" policies to be announced by employers during 2021 with the compliance and tax analysis performed afterwards, as it was this year. Expect rapid growth in employer-of-record arrangements as companies discover that hiring in a country is easier than explaining why they did not. And expect customer contracts to start naming permitted locations for personnel, not only for data centres, which will make the workforce map a commercial document rather than a compliance one.


Workforce Location Compliance Review — we reconcile where your people actually work with what your contracts and records say, and put controls in place that survive the next relocation.

Continue reading

Talk to OPS

Start with the operating problem.