Back to privacy assessments

Privacy assessment

Transfer Processing Inventory

Public-safe inventory of confirmed and potential CIC transfer relationships, data categories, destinations, mechanisms, safeguards, and confirmation gaps.

Status
Draft for external legal and privacy review
Version
0.9
Classification
Public
Last reviewed
12 August 2026
Next review
12 November 2026
Effective date
Pending approval
Owner
Privacy and compliance owner - confirmation required
Approval
Executive owner and privacy counsel - pending
Supersedes
None - initial publication
Download PDF
Document controlValue
Document IDCIC-PIA-TIA-003
Version0.9
Superseded versionNone - initial publication
StatusDraft for external legal and privacy review
Publication classificationPublic
OwnerPrivacy and compliance owner - confirmation required
ApproverExecutive owner and privacy counsel - pending
Effective datePending approval
Last reviewed12 August 2026
Next review12 November 2026 or earlier after a material change

Inventory rules

This public-safe inventory distinguishes evidence of an integration from evidence that an international transfer is active. It does not publish account identifiers, private endpoints, credentials, contract copies, precise security architecture, or personal data.

Risk scale: Low, Medium, Medium-High, High. No transfer is marked Approved until provider, destination, mechanism, safeguards, and owner approvals are confirmed.

Transfer register

IDTransfer family and recipientsData and subjectsSource to destinationEvidence stateMechanism stateResidual risk
T-01Google Cloud application hostingAll member, organization, transaction, KYC, support, audit, and technical data processed by the hosted servicesGlobal users and CIC personnel to United States-hosted service; backup and support locations require confirmationHosting confirmed; exact product-region commitments require confirmationGoogle contract, DPA, applicable SCC/UK terms, and Nigerian safeguard require owner evidenceMedium-High
T-02Google Cloud object storageUploaded identity, support, recording, application, and public/private files depending bucket and workflowGlobal/Nigeria/UK/EEA/Canada users to selected cloud bucket region; support locations require confirmationStorage integration confirmed; active buckets and region controls require confirmationDPA and transfer terms require owner evidenceHigh for Restricted files
T-03MongoDB-compatible primary databasesAccounts, profiles, KYC, transactions, messages, support, audit, notification, and careers recordsGlobal users to database region and provider support locations not confirmedDatabase connectivity confirmed; provider and cluster location unconfirmedContract, DPA, transfer clauses, and subprocessor list not evidencedHigh
T-04Google OAuth and authentication servicesAccount identifier, email, profile, login, token, and security metadataUser jurisdiction to Google processing locationsIntegration evidenced; production use requires confirmationProvider terms and transfer scope require confirmationMedium
T-05CIC email and notification delivery providersEmail, name, preference, template content, security/workflow event, delivery and unsubscribe metadataCIC services to selected email provider and subprocessors; exact provider/location unconfirmedNotification delivery confirmed as a function; SendGrid, AWS SES, and Resend capabilities are evidencedActive provider, DPA, location, and mechanism require confirmationMedium-High
T-06Paystack payment processingIdentity/contact, amount, currency, payment reference, status, and transaction metadataUser/CIC to Paystack processing and banking partnersIntegration evidenced; production activation requires confirmationContract, DPA, onward recipients, and transfer basis require confirmationHigh
T-07Stripe payment and connected-account processingIdentity, business, payment, bank, transaction, webhook, and compliance dataUser/CIC to Stripe and subprocessors, potentially United States and global locationsIntegration evidenced; feature flags and production activation require confirmationDPA, SCC/DPF scope, account country, and onward transfer require confirmationHigh
T-08Embedly wallet and bank-transfer servicesIdentity, wallet, account, bank-transfer, inflow, transaction, and webhook dataCIC and Nigerian users to provider processing locationsIntegration evidenced; production use and provider entity require confirmationContract, DPA, location, and transfer basis require confirmationHigh
T-09Mono financial-data servicesIdentity, linked account, bank-data, transaction, and verification responsesCIC/user to provider and connected institutionsIntegration evidenced; production use requires confirmationContract, DPA, connected-bank roles, retention, and transfer basis require confirmationHigh
T-10Plaid financial-data servicesIdentity, account, balance, transaction, institution, token, and verification information depending enabled productsUser/CIC to Plaid and connected institutions, potentially United States and supported regionsIntegration evidenced; enabled products and countries require confirmationContract, DPA, transfer mechanism, and DPF status require confirmationHigh
T-11Google APIs and optional external media uploadAccount authorization, media, metadata, and operational logs depending featureCIC/user to Google service locationsIntegration capability evidenced; production activation and media categories require confirmationProvider terms and transfer scope require confirmationMedium-High
T-12Agora real-time video and cloud recordingUser identity, channel/session, voice, video, screen content, recording metadata, and filesGlobal participants to Agora routing/recording and cloud storage locationsIntegration and recording configuration evidenced; active routing and recording region require confirmationContract, DPA, consent, location, retention, and mechanism require confirmationHigh
T-13Electronic-signature providerNames, emails, agreements, signatures, audit trail, and webhook metadataCIC/user to selected provider locationGeneric provider integration capability evidenced; provider identity unconfirmedNo provider-specific contract or transfer evidence reviewedHigh until identified
T-14GitHub source control and ActionsSource, configuration, workflow logs, test fixtures, issue evidence, and contributor informationCIC contributors and CI to GitHub processing locationsUse confirmedOrganization terms, DPA, evidence classification, and transfer treatment require owner confirmationMedium
T-15Public-site careers processingApplicant identity/contact, resume, application, OAuth, security, and email metadataApplicants globally to Google Cloud, database, object storage, OAuth, and email servicesWorkflow and integrations confirmed; active provider locations require confirmationSame provider-specific mechanisms as T-01 to T-05Medium-High
T-16CIC personnel, contractors, reviewers, approvers, and support remote accessData visible within each authorized role, potentially including Restricted identity and transaction recordsHosted systems to workforce access countriesRole controls evidenced; workforce country inventory not reviewedEmployment/contractor terms, confidentiality, access location, and transfer treatment require confirmationHigh
T-17External counsel, auditors, assessors, or incident respondersSelected governance, user, transaction, security, incident, or evidence recordsCIC to recipient jurisdiction on a case-specific basisGovernance policies permit controlled sharing; no specific disclosure assessedCase-specific necessity, confidentiality, mechanism, minimization, and record requiredMedium-High to High
T-18Analytics, observability, error monitoring, and operational telemetryPseudonymous user or session reference, request, device, error, performance, security, and operational metadata; content must be excluded unless separately approvedCIC services to the selected telemetry provider and support locations, which are unconfirmedMonitoring and analytics capability is evidenced; active providers and payloads require confirmationProvider, location, DPA, transfer mechanism, retention, sampling, and redaction require confirmationMedium-High

Transfer operating characteristics

IDExporter, importer, and role stateFrequencyRetention stateAccountable owner roleReview state
T-01CIC controller/processor role and Google contracting entity require confirmationContinuous while hosted workflows are usedCIC and provider schedule requires confirmationCloud infrastructure ownerQuarterly while Draft; pending approval
T-02CIC and Google storage roles require confirmation per bucket and workflowEvent-driven uploads and retrievalFile-category and backup schedule requires confirmationCloud storage and records ownersQuarterly while Draft; pending approval
T-03CIC role, database provider, and importer role are unconfirmedContinuous application persistenceCollection-level, backup, and provider deletion schedule unconfirmedDatabase infrastructure ownerCritical closure review; pending approval
T-04CIC and Google identity roles depend on OAuth purpose and scopeAt registration, sign-in, refresh, and revocationToken, account, and security-log schedules require confirmationIdentity and access ownerQuarterly while Draft; pending approval
T-05CIC role and active communications provider/importer require channel reconciliationEvent-driven notifications and campaignsMessage, delivery, suppression, and provider-log schedules require confirmationCommunications ownerQuarterly while Draft; pending approval
T-06CIC, Paystack, and banking-partner roles require product confirmationPer initiated payment and webhookFinancial, dispute, legal, and provider schedules require confirmationPayments ownerPer active rail before approval
T-07CIC, Stripe, connected-account, and banking roles require product confirmationPer onboarding, payment, payout, and webhookFinancial, compliance, dispute, and provider schedules require confirmationPayments ownerPer active product before approval
T-08CIC, Embedly, and banking-partner roles require confirmationPer wallet creation, transfer, inflow, and webhookWallet, transaction, legal, and provider schedules require confirmationWallet operations ownerPer active product before approval
T-09CIC, Mono, and connected-institution roles require confirmationPer consent, link, verification, refresh, and retrievalConsent, token, bank-data, and provider schedules require confirmationBanking-data ownerPer active product before approval
T-10CIC, Plaid, and connected-institution roles require confirmationPer consent, link, verification, refresh, and retrievalProduct, token, bank-data, and provider schedules require confirmationBanking-data ownerPer active product before approval
T-11CIC and Google service roles depend on each enabled APIEvent-driven by enabled featureAuthorization, media, metadata, and log schedules require confirmationProduct integration ownerBefore each API activation
T-12CIC and Agora roles depend on routing and recording configurationDuring live sessions and recording jobsSession, recording, backup, and deletion schedules require confirmationCommunications product ownerCritical if active; pending approval
T-13CIC and electronic-signature provider roles are unconfirmedPer agreement and webhookAgreement, audit, legal, and provider schedules require confirmationLegal operations ownerProvider identification required
T-14CIC and GitHub roles depend on organization and Actions servicesContinuous source collaboration and CIRepository, issue, artifact, and log schedules require confirmationEngineering operations ownerAnnual and after material change
T-15CIC controller role and cloud/database/email processor roles require confirmationPer application and hiring workflow eventApplicant, attachment, communication, and legal schedules require confirmationPeople operations ownerQuarterly while Draft; pending approval
T-16CIC entity and personnel/contractor receiving roles require country and entity inventoryDuring authorized access sessionsAudit, support, and case schedules require confirmationPeople and security ownersCritical closure review; pending approval
T-17CIC and recipient roles are case specificExceptional or engagement basedMatter, audit, incident, legal-hold, and return/deletion terms applyLegal and governance ownersApproval before each material disclosure
T-18CIC and telemetry provider roles depend on selected service and payloadContinuous or sampled event deliveryEvent, log, trace, error, and provider schedules require confirmationMonitoring and security ownersProvider and payload review required

Required transfer details before approval

For every active row, the controlled provider register must record:

  • CIC legal entity and exporter role.
  • Provider legal entity and importer role.
  • Product and account owner.
  • Production activation state.
  • Data fields and data-subject categories.
  • Storage, processing, backup, support, and remote-access countries.
  • Subprocessors and change-notification method.
  • Contract, DPA, and security exhibit.
  • Adequacy or certification scope where relied upon.
  • SCC module, UK IDTA/Addendum, Nigerian safeguard, or other mechanism.
  • Provider government-request policy and relevant request history where available.
  • Encryption and key-control architecture.
  • Retention, deletion, return, portability, and incident terms.
  • Inherent and residual risk.
  • Privacy, security, business, and legal approvals.

Data minimization rules by transfer

Transfer typeMinimum rule
NotificationsDo not place full financial identifiers, identity documents, credentials, or unnecessary case details in message templates or provider metadata.
AnalyticsUse pseudonymous identifiers; exclude KYC documents, financial identifiers, message content, and precise location unless separately assessed.
PaymentsSend only fields required by the selected rail and legal obligations; do not duplicate provider data into logs.
RecordingsDefault recording off; require explicit consent where applicable; separate recording files from general public storage.
SupportShare the smallest record needed; use audited access and purpose-specific file requests.
Source and CINever use production personal data as fixtures; redact screenshots and logs before committing evidence.
Vendor supportUse time-limited access, masked evidence, and case-specific authorization where the provider supports it.

Onward transfers

Every active provider must have an approved subprocessor record. A provider's own public list is supporting evidence, not proof that CIC has subscribed to change notices, configured regional controls, or accepted current terms. CIC must evaluate material new subprocessors before the objection period expires where contractual rights exist.

Remote access

Remote access by a separate provider or workforce entity may constitute or contribute to an international transfer even when data remains stored in one region. CIC must inventory access countries for:

  • Cloud and database support.
  • Payment and verification provider support.
  • CIC employees and contractors.
  • Reviewers, approvers, support agents, and incident responders.
  • Vendor engineers using customer-authorized troubleshooting access.

Approval status

All rows are Pending factual and legal confirmation unless a controlled evidence record records otherwise. Publication of this inventory does not activate, authorize, or approve an integration.

Related reports

Limitation

This inventory was prepared with AI assistance from repository and governance evidence. Authorized owners must reconcile it against production consoles, contracts, invoices, vendor registers, and workforce records before approval.