Own your compliance data: the case for in-country screening

Ask a compliance team where their customers' most sensitive data lives, and the honest answer may be: "in a vendor's cloud, in another country." Names, national IDs, dates of birth, risk ratings, adverse findings — the whole due-diligence file — sitting in a…

Illustration for “Own your compliance data: the case for in-country screening”

Ask a compliance team where their customers’ most sensitive data lives, and the honest answer may be: “in a vendor’s cloud, in another country.” Names, national IDs, dates of birth, risk ratings, adverse findings — the whole due-diligence file — sitting in a multi-tenant SaaS platform, subject to that provider’s jurisdiction, retention and access model.

Whether that is acceptable is a question every institution should answer deliberately, not by default.

What the law says about data leaving the country

It pays to be precise here, because this debate attracts overstatement. The two data-protection laws below do not ban sending personal data abroad. They put conditions on it.

  • The EU’s General Data Protection Regulation (GDPR) allows a transfer to a third country that the European Commission has decided ensures an adequate level of protection, and such a transfer does not require any specific authorisation (Article 45). Without an adequacy decision, a controller or processor may transfer personal data if it has provided appropriate safeguards, on condition that enforceable data-subject rights and effective legal remedies are available (Article 46).
  • Mauritius’s Data Protection Act 2017 lets a controller or processor transfer personal data to another country on the grounds listed in section 36. They include providing the Data Protection Commissioner with proof of appropriate safeguards, and the data subject’s explicit consent after being informed of the possible risks.

Hard in-country storage rules do exist in some sector regulation. One example: the Central Bank of the UAE’s Retail Payment Services and Card Schemes Regulation (in force since June 2021), which sets the licensing rules for retail payment services, states that personal and payment data shall be stored and maintained in the State.

So the accurate framing is not “data residency is mandatory”. It is: know which rules apply to your data, and be able to show where it is and who can reach it. Handing the hosting to a vendor does not hand over the responsibility. Under the GDPR, a controller that has processing carried out on its behalf must use only processors providing sufficient guarantees to implement appropriate technical and organisational measures (Article 28).

Cloud SaaS also concentrates risk you don’t control: an outage, a breach, a policy change or a price change at the vendor becomes your compliance incident, on someone else’s timeline.

Cloud convenience without the cross-border trade-off

The reflex is that keeping data in-country means going back to something old and clunky. It doesn’t have to.

This section describes SonarPulse’s own product.

SonarPulse is delivered as an in-country cloud service: the polish of a modern web application, hosted in a cloud region or data centre inside your own jurisdiction, where one is available, rather than a foreign, multi-tenant one. Customer PII, screening results and risk records stay in your jurisdiction, behind your access controls. For institutions with a hard mandate, the same platform can be deployed in a private data centre or on-premises.

Control extends beyond location:

  • Risk scoring is yours to tune. Weights and thresholds are configured per tenant and business line — a transparent, auditable model, not a vendor black box.
  • Sources are yours to choose. Official regulator lists, open datasets, court and enforcement records, local press and a localised PEP database — aggregated, not rented from a single feed.
  • Tenancy is yours to segment. Multi-tenant and business-unit isolation with role-based access, so each team sees only its own customers.
  • Pricing is flexible. Our pricing model is designed so that compliance is a capability you own, not a meter that runs faster as you grow.

Questions to put to any screening vendor

  • In which country, and in which data centre, are our customers’ records stored and backed up?
  • If any data leaves the country, which legal basis covers the transfer, and could we show it to our data-protection authority?
  • Does a sector rule that applies to us require local storage?
  • How does the price change as our customer numbers and re-screening volumes grow?

The bottom line

Global cloud SaaS asked institutions to trade control for convenience. The GDPR and the Mauritius Data Protection Act let data travel abroad under conditions; a sector rule such as the UAE’s payment-data requirement does not. Either way, the institution has to be able to show where the file is and who can reach it — and that is simplest when the answer is here.

> You wouldn’t outsource your core banking ledger to a black box in another country. Your customers’ due-diligence file deserves the same standard.

SonarPulse is delivered as an in-country cloud platform (private-data-centre or on-premises where mandated), with a compliance workflow and risk engine you fully control. [Learn more / request a demo].


Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu