A GDPR-regulated SaaS platform stores user data in multiple EU regions for performance reasons. What must be documented to remain compliant?
-
A
Only the primary storage location needs documentation
-
B
All storage locations must be listed in the Records of Processing Activities (RoPA)
-
C
Multi-region storage is automatically compliant and requires no documentation
-
D
Only cross-border transfers outside the EU need to be recorded