Legal Intelligence & Assurance

    Change Impact & Cross-Border Conflict

    Institutions are not short of regulatory news. They are short of the sentence that follows it: which obligation moved, which control now has to be retested, which entity is in scope, and by when. Watching the change is not the work. Resolving it into work is the work.

    The same discipline applies where two jurisdictions ask for opposite things. A position exists whether or not anyone recorded it. Recording it, with a signature against it, is the control.

    Change resolved into work

    Each event below is an amendment, an application date, a judgment or a published enforcement action. Open one to see the obligations that move, the controls to retest, the entities in scope and the evidence gap as it actually stands — including where the position is recorded as failed rather than presented as green.

    ESA technical standards on subcontracting of critical ICT services · Operative for the current register cycle

    The permissible position on subcontracting critical or important functions is narrowed, and the entity must be able to identify the chain rather than the immediate provider alone.

    Obligations that move

    • Every ICT arrangement is registered and classified against the critical-or-important test.

      Scope widens from the contracting provider to the subcontracted chain supporting the same function.

    • Each critical arrangement contains the prescribed clause set.

      Subcontracting consent and notification move from desirable to load-bearing, because the chain map depends on them.

    Controls to retest

    • C11 · Third-party and outsourcing risk

      Register completeness now tested against the chain, not the counterparty.

    • C25 · Legal risk and contractual enforceability

      Legacy contracts without a notification right cannot produce the chain map.

    Entities in scope

    Irish designated activity company; UK public limited company (group policy alignment)

    Evidence gap as it stands

    Chain maps exist for cloud and market data. Screening services stop at the third party, and the contract carries no notification right to go further.

    Accountable

    Head of Third-Party Risk, with Group General Counsel on clause remediation

    Institutional deadline

    Chain maps complete one full cycle before the first register examination

    Where jurisdictions collide

    An institution operating across regimes will meet duties that cannot both be satisfied. The failure mode is not the conflict; it is resolving the same conflict three different ways in three business units and discovering it during an examination.

    Customer records held by a processor outside the approved region

    European Union

    Do not export personal data absent an assessment that the importing regime affords essentially equivalent protection.

    United States

    Produce records in response to lawful process, wherever the data is held.

    Where they collide

    Compliance with production can constitute an unlawful transfer; refusal can constitute contempt. Both duties bind the same records at the same moment.

    Position taken

    Customer records supporting EU business are held in-region with no permitted export. Production requests are answered from the in-region copy through a defined channel, with each request logged and assessed before any disclosure.

    Signed by Group General Counsel and Data Protection Officer, jointly.

    Residual exposure

    A request reaching the US branch for records it does not hold. The channel is the mitigation; it has been rehearsed once and should be rehearsed annually.

    C08 · Data privacy and protectionC26 · Regulatory engagement and examination responseC25 · Legal risk and contractual enforceability

    Demonstration positions drawn from public instruments and published actions. Nothing here is legal advice; a client's positions are taken by that institution's counsel and held in its own graph with the signature that authorised them.