This is the Cloud Act-affected version. The US Clarifying Lawful Overseas Use of Data (CLOUD) Act compels US-parent cloud providers to disclose customer data on lawful request — including data stored outside the US. The controls documented across this page exist to keep the AES key, plaintext PII, and AI processing outside the custody of any US-parent-owned provider. The original DPIA Response is preserved unchanged so the impact of the CLOUD Act can be compared side-by-side. Full rationale: CLOUD Act Posture Guide.
MapFlow's responses to the council's Data Protection Impact Assessment questions
Thank you for the detailed questions. Please find below MapFlow's responses to each point, together with the requested data flow diagram, sub-processor register, and confirmation regarding Hillingdon data. We are happy to provide further technical or contractual evidence on request.
We trust these responses address the questions raised. We are available for a call or meeting to walk through any point in more detail, to provide additional technical or contractual evidence, and to support the council's risk assessment. We await the council's decision on whether the proposed processing activity may continue, whether additional controls are required, or whether alternative services should be considered. Please do not hesitate to contact us if you require clarification on any of the above.
Yours sincerely,
Victor, MapFlow