Cloud Act version — DPIA Response

After
Original retained

This is the Cloud Act-affected version. The US Clarifying Lawful Overseas Use of Data (CLOUD) Act compels US-parent cloud providers to disclose customer data on lawful request — including data stored outside the US. The controls documented across this page exist to keep the AES key, plaintext PII, and AI processing outside the custody of any US-parent-owned provider. The original DPIA Response is preserved unchanged so the impact of the CLOUD Act can be compared side-by-side. Full rationale: CLOUD Act Posture Guide.

DPIA Response

MapFlow's responses to the council's Data Protection Impact Assessment questions

Document ID: MF-DPIA-01Version: 1.3Last Reviewed: August 2026Status: Published (Factual Baseline)
To: InfoSec Officer, London Borough of Hillingdon
Date: 31 August 2026
Re: Data Protection Impact Assessment — MapFlow Responses

Thank you for the detailed questions. Please find below MapFlow's responses to each point, together with the requested data flow diagram, sub-processor register, and confirmation regarding Hillingdon data. We are happy to provide further technical or contractual evidence on request.

We trust these responses address the questions raised. We are available for a call or meeting to walk through any point in more detail, to provide additional technical or contractual evidence, and to support the council's risk assessment. We await the council's decision on whether the proposed processing activity may continue, whether additional controls are required, or whether alternative services should be considered. Please do not hesitate to contact us if you require clarification on any of the above.

Yours sincerely,

Victor, MapFlow

The compliance models, regulatory briefs, and legislative interpretations provided on this site are for informational purposes only and do not constitute formal legal counsel. Data controllers retain sole responsibility for completing their independent statutory risk assessments under UK GDPR Article 35.