Important notice
The Classic Experience will be sunset on
Aug. 1.
If you have questions, contact your Customer Success and Implementation Manager,
Account Manager, or
support@trustarc.com.
Risk Profile uses TrustArc's Data Transfer Risk Algorithm to calculate control effectiveness and residual data transfer risk directly from your assessment responses. To take advantage of this, your international data transfer assessment needs to be prepared with the correct labeling before it can generate dynamic data transfer risk reporting.
This article covers how to prepare your international data transfer assessment for technical validation, the rules TrustArc uses to validate your labels, and the steps to replace the TrustArc International Data Transfer Assessment with your own custom assessment in Risk Profile.
What you can do
✓Label question responses so Risk Profile can calculate control effectiveness and residual data transfer risk
✓Validate that your data transfer risk and control effectiveness calculations work correctly before rollout
✓Replace the TrustArc International Data Transfer Assessment with your own custom assessment in Risk Profile
Prerequisites
✓Active TrustArc account with access to Risk Profile and Assessment Manager
✓An assessment published and completed at least once in Assessment Manager
Preparing Your Assessment
To ensure your assessment can leverage the full capabilities of Risk Profile — including TrustArc's Data Transfer Risk Algorithm and dynamic data transfer risk reporting — you must first prepare your international data transfer risk assessment for technical validation.
TrustArc uses labels on question responses to calculate control effectiveness and residual data transfer risk, and to break down the effectiveness of the data transfer mechanisms used by originating jurisdictions (where the data is exported from).
Labels must be correctly implemented on your assessment to ensure the risk and control effectiveness calculations in your risk reports are accurate. TrustArc's validation and technical testing verifies that the data transfer risk algorithm and calculations are working properly, giving you confidence that everything works as expected before you roll your configured international data transfer risk assessment out across your organization.
📋 Note: The Validation Rules section below outlines exactly which labels are required on which question responses.
Validation Rules
Your assessment, and any associated child assessments, are all validated and tested at the same time.
•Questions used to determine control effectiveness must have both a control effectiveness label and a Risk Mitigation Category label on each response, so Risk Profile can calculate control effectiveness and residual risk. The only recognized risk mitigation category label for the International Data Transfer Risk Assessment is "Intl Data Transfer." Additional labels on a response are fine — they don't affect the calculations.
Figure 1.0
•Questions used only to gather information about the business process, system, or third party being assessed — or to determine a fact and whether a control applies — do not require labels.
•Questions used to determine which countries personal information is being transferred from (the exporting country) need both the two-letter country code and a Rule Number label for the exporting country to be listed in the report.
📋 Example: Your assessment might ask a Yes/No question to determine whether personal information is disclosed to third parties. This question is used to determine a fact — whether third party management control questions need to be asked — so it does not require Control Effectiveness or Intl Data Transfer labels.
Figure 2.0
•Rule Number labels can contain any numeric value greater than zero, configured as Rule=<numeric value> — for example, Rule=4.
Questions used to determine whether appropriate data transfer mechanisms are in place to transfer personal information from the exporting country must have a Rule Number label on the data transfer mechanism responses, in addition to a Control Effectiveness label and an Intl Data Transfer label. This displays the exporting country and its data transfer mechanism in the Data Transfer Risk Report, and factors into the overall data transfer risk score. The Rule Number label on the transfer mechanism must match the Rule Number on the exporting country.
📋 Note: In the screenshot below, the listed countries share the same Rule Number label as the corresponding data transfer mechanism, so the country and mechanism display correctly together in the report. The countries are labeled Rule=4 along with their two-letter country codes, and the transfer mechanisms listed as answer options share that same Rule=4 label. Each transfer mechanism also carries a Control Effectiveness label and an Intl Data Transfer label, so that information feeds into the overall data transfer control effectiveness calculation.
Figure 3.0
•Questions used to identify what safeguards are in place to protect personal information transferred internationally must have both a Safeguards label and a Control Effectiveness label for the safeguards to be listed under the appropriate categories in the data transfer report.
Figure 4.0
Rules and Error Messages
The table below lists the rules your assessment is tested against, and the error messages returned if a rule is implemented incorrectly.
Rule
Error message returned
Supported Control Effectiveness values are 0, 1, 2, 3, or 4. Any Control Effectiveness label with a value greater than 4 will return an error.
Control Effectiveness cannot be greater than 4
Each answer can have only zero or one Control Effectiveness label. More than one on a single response will return an error.
Only one Control Effectiveness is allowed per answer
Every Control Effectiveness label must be paired with an Intl Data Transfer label. A Control Effectiveness label without one will return an error.
Control Effectiveness exists but Mitigated Category is undefined
The presence of two or more Risk Mitigated Category labels on a single response will return an error.
Only one Mitigated Category is allowed per answer
All responses for a single question must share the same Risk Mitigated Category label. A mismatched response will return an error.
Only one Mitigated Category is allowed per question
The assessment must contain at least one question with a defined Control Effectiveness and Risk Mitigated Category. If none exist, an error is returned.
Template has no risk label defined
Each answer can have only zero or one Rule Number label. More than one on a single response will return an error.
Only one Rule Number label is allowed per answer
Every Rule Number label must be paired with either a Control Effectiveness label or a two-letter country code. One without the other will return an error.
Rule Number exists but Control Effectiveness or two letter country code is undefined
Each answer can have only zero or one Safeguards label. More than one will return an error.
Only one Safeguards label is allowed per answer
Every Safeguards label must be paired with a Control Effectiveness label. A Safeguards label without one will return an error.
Safeguards label exists but Control Effectiveness is undefined
Table 1.0
Valid Control Effectiveness Labels
These are the Control Effectiveness labels recognized by TrustArc's platform intelligence to calculate control effectiveness and risk when generating your risk report.
•"Control Effectiveness = 0"
•"Control Effectiveness = 1"
•"Control Effectiveness = 2"
•"Control Effectiveness = 3"
•"Control Effectiveness = 4"
Table 2.0
Valid Risk Mitigated Category Labels
This is the Risk Mitigated Category label recognized by TrustArc's platform intelligence to calculate control effectiveness by control category and data transfer risk when generating your risk report.
•"Intl Data Transfer"
Table 3.0
Valid Safeguards Labels
These are the Safeguards labels recognized by TrustArc's platform intelligence to calculate the control effectiveness of the safeguards in place.
•"Safeguards=Security"
•"Safeguards=Organizational"
•"Safeguards=Contractual"
•"Safeguards=Other"
•"Safeguards=None"
Table 4.0
Replacing the TrustArc International Data Transfer Assessment
To replace the TrustArc International Data Transfer Assessment with one of your own, follow these steps:
1
Publish the assessment you want to use as a replacement, and complete it at least once in Assessment Manager. This makes it available in the right-hand column of the Configure Assessment screen, where you indicate that you want to replace the International Data Transfer Assessment.
Figure 5.0
📋 Note: Publishing a replacement assessment does not impact your organization's Risk Profile calculations. The assessment created in Assessment Manager can be deleted later if needed.
2
On the Configure Assessment screen, indicate that you want to replace the International Data Transfer Assessment with your own.
3
TrustArc conducts testing to confirm your labels are properly implemented, that the risk and control effectiveness calculations work correctly, and that information populates correctly in the Data Transfer Risk Report.
4
TrustArc notifies you once your assessment is approved. It will then appear on the Assessment Details page in Assessment Manager when you click Start Assessment from Risk Profile under the Data Transfer Assessment column.
Figure 6.0
Removing a Custom Assessment
If you choose at a later time to remove your approved custom assessment, click the trash can icon next to it. A confirmation message appears asking whether you'd like to delete the assessment template you used to replace a TrustArc assessment.
Figure 7.0
TrustArc Trust Center · Preparing Your International Data Transfer Assessment for Risk Profile · support.trustarc.com