• cattywampus@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    Very fair point. I still have personal doubts about data on foreign servers. Is there a third party actually verifying they are obeying the law?

    • remotelove@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 day ago

      Compliance audits are usually handled by a third party and I am only familiar with SOC2, SOX, PCI and ISO27001. GDPR is a beast, from what understand. I do suspect it’s also ran by a third party during an audit period.

      Most of the above compliance programs require network architecture reviews and checks to ensure that their policies actually match how their internal processes and software actually works. This typically includes compliance enforcement mechanisms, such as what we were discussing.