CAS-003 · Question #835
Which of the following risks does expanding business into a foreign country carry?
The correct answer is C. Data ownership might revert to the regulatory entities in the new country. Expanding into a foreign country introduces the risk that local data sovereignty and ownership laws may legally transfer control or ownership of data to that country's regulatory bodies, creating unexpected liability.
Question
Which of the following risks does expanding business into a foreign country carry?
Options
- AData sovereignty laws could result in unexpected liability
- BExport controls might decrease software costs
- CData ownership might revert to the regulatory entities in the new country
- DSome security tools might be monitored by legal authorities
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- C88% (29)
- D6% (2)
Why each option
Expanding into a foreign country introduces the risk that local data sovereignty and ownership laws may legally transfer control or ownership of data to that country's regulatory bodies, creating unexpected liability.
While data sovereignty laws can create liability, the specific claim that they result in unexpected liability is accurate but less precise than C - C directly identifies the mechanism (ownership reverting) rather than the general consequence.
Export controls restrict the movement of certain technologies and data out of a country, which typically increases costs and compliance burden rather than decreasing software costs.
Many jurisdictions have data localization or sovereignty laws that require data generated or stored within their borders to remain under the jurisdiction of local authorities, and in some cases those authorities may assert ownership or the right to access that data. This means a company could lose effective control of its own data to a foreign regulatory entity, which is a significant and often overlooked legal and business risk when entering new markets.
While some governments do monitor network traffic or require backdoors, security tools themselves are not typically the monitored entity - the concern is data access and sovereignty, not surveillance of tooling.
Concept tested: Data sovereignty and regulatory ownership risks in international expansion
Source: https://www.enisa.europa.eu/topics/data-protection/data-sovereignty
Topics
Community Discussion
No community discussion yet for this question.