Skip to main content

How do I request compliance documentation?

Short answer: Contact the Data Protection Officer at dpo@cybercrucible.com. Available documentation includes Standard Contractual Clauses, the Transfer Risk Assessment, Data Processing Agreements, and the data governance policy — provided subject to reasonable confidentiality measures.

What you can request

  • Standard Contractual Clauses — including the SDAIA pre-approved clauses for Saudi transfers.
  • Transfer Risk Assessment — the completed TRA covering data flows, destination legal regime, controls, and mitigations.
  • Data Processing Agreement — defining scope of processing, security terms, confidentiality, and breach notification.
  • Data governance and sharing policy — collection limits, transit protections, and third-party non-sharing commitments.

What to include in your request

It speeds things up considerably to state your jurisdiction, whether you are acting as controller, which deployment model you are evaluating (air-gapped, regional, or hybrid), and what your own regulator or auditor requires.

For jurisdictions not covered here

The regimes described in this book are those most frequently asked about. If yours is not listed, the underlying answers are usually the same — minimal collection, local processing, and in-country deployment options. Contact the DPO with the specific requirement and it can be addressed directly.