| EU GDPR / German DSGVO | Personal-data protection and transfers outside the EEA. Lawful transfer mechanisms can include adequacy decisions or appropriate safeguards; this is not a general Germany-only storage rule. | Classify sensitive fields, redact values before recording, and use application-supplied tokens to reduce identifying information in telemetry. Local investigation can avoid sending logs to a remote service. | Determine lawful processing and transfer grounds, recipient access, contracts, retention, and any required transfer assessment. Tokens do not automatically make data anonymous. |
|---|
| Germany: BDSG and sector-specific rules | The BDSG supplements the applicable data-protection framework. Sector rules can add location conditions: SGB X section 80 restricts where commissioned processing of social data may occur, while allowing specified locations outside Germany. | Use local logs and matching catalogs, developer-declared sensitive-field policies, and separately controlled artifacts to design a deployment around the permitted processing boundary. | Identify the actual sector and contract requirements. Verify hosting, support access, backups, and all hierarchy nodes. Sarvalekha does not determine a server country or enforce German legal eligibility. |
|---|
| UK GDPR international transfers | Restricted transfers to separate organisations outside the UK need an applicable transfer mechanism. Making data accessible can matter even without moving its storage location. | Reduce recorded identifiers through classification and redaction. Keep token mappings separately controlled and choose local investigation where remote access is unnecessary. | Assess the recipient and processing arrangement, applicable adequacy or safeguards, and transfer risk. Pseudonymised data may still be personal data. |
|---|
| US DoD: DFARS 252.239-7010 | For covered cloud-service contracts, Government data outside DoD premises must be maintained in the United States or outlying areas unless the contracting officer authorizes another location in writing. | Local capture, an optional uploader, explicit server configuration, and separate artifact access provide building blocks for an approved deployment. Redact unnecessary sensitive fields at capture. | Qualify the complete hosting environment, locations, access, incident handling, and contract controls. Destination labels are not country-level enforcement and redaction does not waive contract obligations. |
|---|
| US ITAR export controls | Controlled technical data is broader than PII. Releasing it to a foreign person can be an export even inside the United States, subject to the applicable regulatory exceptions. | Remove logging-only descriptions from shipped executables, retain catalogs separately, and omit sensitive runtime values. Local investigation can reduce unnecessary artifact distribution. | Determine export classification, recipients, authorizations, and applicable exceptions. Catalogs, source, symbols, dumps, and logs may themselves be controlled; metadata removal does not authorize an export. |
|---|
| US federal and defense: FedRAMP / CMMC | FedRAMP addresses assessment and authorization of in-scope federal cloud services. CMMC assesses protection of federal contract information and controlled unclassified information in the defense supply chain. | Sensitive-field minimization and scoped server access can contribute to a system security design. Preserve exact build artifacts to explain the telemetry being collected. | Assess the complete system and required controls. These features do not establish FedRAMP or CMMC certification, authorization, or satisfaction of NIST requirements. Agency and contract conditions define the deployment scope. |
|---|
| US DOJ Data Security Program / EO 14117 | Prohibits or restricts certain transactions giving countries of concern or covered persons access to government-related data or bulk US sensitive personal data. It is not a blanket ban on all international transfers. | Avoid recording unnecessary sensitive fields and limit who receives retained logs and related artifacts. Redaction reduces the original values captured in events. | Evaluate data categories, thresholds, recipients, transactions, and program duties. The bulk-data definition can cover anonymized, pseudonymized, de-identified, or encrypted data; transformation alone is not an exemption. |
|---|
| US healthcare: HIPAA | Protects health information in covered arrangements. HIPAA does not categorically forbid overseas cloud storage; applicable agreements and privacy/security obligations still apply. | Classify health-related fields and redact unnecessary identifiers to reduce sensitive diagnostic content. Restrict log and artifact access within the chosen deployment. | Address applicable business associate agreements, risk analysis, safeguards, and retention. Field redaction alone does not establish HIPAA de-identification under Safe Harbor or Expert Determination. |
|---|