Products Intelligence Pricing Methodology Contact
FINANCIAL & CAPITAL MARKETS

Cross-border data transfer compliance

Cross-border data transfer compliance in Financial & Capital Markets is now a multi-jurisdictional enforcement problem, not a policy planning exercise. The European Data Protection Board has issued binding guidance affecting how financial institutions route client data between EU and non-EU entities, while the U.S. Securities and Exchange Commission's expanded data governance expectations under Regulation S-P and the Monetary Authority of Singapore's outsourcing and data residency notices are pulling compliance teams in competing directions. Firms with cross-listed operations or third-party data processors in more than one jurisdiction are currently auditing their contractual transfer mechanisms against at least two of these frameworks simultaneously.

Watch

  • EU-U.S. Data Privacy Framework adequacy decision: annual review pressure building in Brussels
  • Regulation S-P amendments: expanded breach notification scope now covers third-party processors
  • Monetary Authority of Singapore Technology Risk Management Guidelines revision expected; watch outsourcing addendum
  • Standard Contractual Clauses enforcement actions against financial sector data importers in EU member states

Recent material activity in Financial & Capital Markets

Active monitoring in place across Financial & Capital Markets. Material developments related to cross-border data transfer compliance will appear here as they are published.