Reference

AI cross-border requirements: a scannable checklist

How to use it: each row is a guarantee, the SOC 2 criterion it falls under, and the evidence a reviewer will ask for. SOC 2 is a procedural assessment of how an organisation operates, reported by an independent CPA firm — not a certification of a product or a database. The full definition, and why AI transport widens its scope, is in The AI ladder, §7 "SOC 2: what AI transport puts in scope".


1. Data governance

GuaranteeSOC 2 criterionEvidence to show
Know what personal data exists and where it livesConfidentiality C1.1Data inventory per system; the country each store is in
Consent before processing, per jurisdictionPrivacy P2–P3Jurisdiction resolved from location (not language); one consent event per grant, with the wording version
Collect only what the purpose needsPrivacy P3Field list per form; free text treated as personal data
Retention limits enforced by a job, not only a policyConfidentiality C1.2 · Privacy P4The scheduled job, its period, its last successful run
Erasure reaches every copy — including AI storesPrivacy P4A deletion request traced through database, files, vector index, agent memory, prompt logs, ad platforms
Data-subject access on requestPrivacy P5A lookup that finds a person's rows without exposing others
Subprocessors named, with where each processesPrivacy P6 · CC9.2The published list; each provider's own report

2. Transport

GuaranteeSOC 2 criterionEvidence to show
Encryption in transit everywhereCC6.7HTTPS-only configuration; no plaintext endpoints
Field-level encryption, keys held apart from the dataCC6.1The database holds ciphertext; the key lives elsewhere
Keys rotated, never passed aroundCC6.1Rotation record by fingerprint — never the value
Secrets never written to logsCC6.1 · CC7.2Request logging off where a secret or key crosses the wire
Every cross-border flow named and switchablePrivacy P6An itemised disclosure per flow, and a way to suspend one flow without stopping the site
Where data lives is a setting of the deployment, not codeCC8.1Per-instance configuration; a changed residency changes who is asked to consent

3. Horizontal scaling and availability

GuaranteeSOC 2 criterionEvidence to show
No single point of failure in the answer pathAvailability A1.1A second path that answers when the primary is down
Writes survive a component outageAvailability A1.2Buffered writes replayed in order after recovery
Retries never double-charge or double-orderProcessing Integrity PI1.3Idempotency keys; payment replay guards
Capacity measured, not assumedAvailability A1.1A load test, or recorded limits per provider and region
Failures detected and alertedCC7.2Logged reasons for every refusal; an alert that someone receives
Changes pass a test gateCC8.1The release gate; deploys tagged to a commit

4. AI-specific

GuaranteeEvidence to show
The model provider does not train on your dataThe provider's terms for the product and plan used
Inference runs where the data is allowed to goRegion per model; personal data never sent to a global endpoint
The agent cannot decide permissionsPermission checked in the endpoint; the agent acts only under a signed, capped, revocable mandate
Prompt, output and memory logs follow the same retention and erasureA period per AI store, and erasure proven against each
Wrong answers are caught, escalated and correctedA score threshold that refuses weak answers; a human escalation path with tiers
Model, prompt and adapter changes are controlledVersioned, reviewed, gated like code

5. Rules on the server vs rules in the theme

An AI agent has no browser. Anything decided in theme code — a Liquid condition, a script, a hard-coded attribute — is invisible to an agent, a scheduled job and a webhook, and editable by anyone who can reach the page. So permissions, data updates and every value an agent or a feed will read must be decided server-side from rules and data, and only displayed by the theme.

Permissions and data updates

ConcernRules-based, server-side (capabilities · claims · extras)Hard-coded in the front-end themeWhat goes wrong with hard codeSOC 2 criterion
Who may do whatResolved per request from the subject's claims and capability rowsif conditions in theme scripts or templatesVisible in the page source and bypassed by calling the API directlyCC6.1
An agent updating dataThe agent calls an endpoint that checks the capability and a signed mandate, then the server writesThe agent fills in forms or replays page requestsNo check applies to a caller without a browser; nothing records who actedCC6.1 · PI1.2
Revoking accessOne row changes; effective on the next requestA theme redeploy, plus cached pages that keep the old ruleAccess outlives the decision to remove itCC6.2
Preferences and extras (language, market, consent flags)Stored as claims/extras; read by every caller the same wayHeld in theme variables or cookiesThe page, the agent and the batch job each see a different answerP2 · CC6.1
ConsentDecided at the edge from where the visitor is, before anything loadsA banner that hides and shows elementsTags already fired; no evidence of what was grantedP2–P3
Change controlRules are data with a version and a test gateEdits to theme files, often outside reviewA rule change ships without a recordCC8.1
AuditEvery grant and refusal logged with its reasonNothing"Who allowed this?" has no answerCC7.2

Values that must be codes, not text

ValueServer-side (declared, coded)Hard-coded theme textWhat goes wrong
Language and region (hreflang)Generated from the market registry as ISO 639-1 language + ISO 3166-1 country (ko-KR, en-US) plus x-defaultHand-written values such as korean, en alone, or one list pasted into every themeSearch engines ignore invalid values; adding a market means editing every theme; pages point at each other inconsistently
Country and jurisdictionISO 3166-1 / 3166-2 (KR, US-CA) resolved from location, never from languageInferred from the page language or a dropdownA Korean speaker in California gets Korean consent rules — the wrong law
CurrencyISO 4217 (KRW, USD); one canonical currency stored, display convertedA currency symbol typed into the theme"₩" and "$" rendered from the wrong base; rounding and tax on the wrong amount
Weights and measurementsValue with a declared unit (e.g. 1.5 kg, 60 mm), from one product recordA bare number in a template (1.5)Carriers rate the wrong parcel; feeds reject or misread it; net content is a legal declaration
Area and regional unitsCanonical unit stored (m²); regional units (평, ft²) derived for displayEach market's page with its own typed numberThe same floor priced three ways

State management

StateServer-sideFront-end onlyWhat goes wrong
Cart, order, payment statusServer records keyed by a server id; the page only displays themlocalStorage or theme variablesLost on another device; forgeable; invisible to agents and support
Consent and preferencesAn append-only log plus current claimsA cookie the theme readsNo evidence; cleared cookies silently reset a legal choice
Loyalty points and tierDerived from a ledger on readA number stored in the page or a customer tagBalances drift; a tier outlives the points that earned it
Rate limits and retriesServer keys and idempotencyDisabled buttonsDouble orders when the button is re-enabled or bypassed

What server-side costs: a service that must be running, a network round trip per decision, and rules someone has to maintain as data. The theme stays fast because it only displays; the trade is that every rule has exactly one home, and it is not the page.


6. Cross-channel: the same rules on every channel

Mobile, browser, household, point of sale and desktop each capture data differently, but a channel is not a permission. Every channel sends inputs to the same server, which applies the same consent, capability and mandate rules — so what an AI can see or do never depends on which door the data came through.

ChannelIdentity and consent capturedWhere state livesTransport to the serverWhat an AI may see or doSecurity mandate
Mobile (installable web app, native shell)Signed-in subject; consent asked by jurisdiction on first useServer; the device caches only the app shell, never consent or ordersHTTPS; offline actions queued and replayed idempotentlyOnly what the subject's claims allow; nothing cached on the device is authoritativeNo secrets in the app; no cached consent answers
BrowserSame as mobile; bot check on every submissionServer; cookies hold a session reference, not decisionsHTTPS; field-level encryption before storageSame as mobileConsent decided before any tag loads; no permission logic in page code
Household (shared device, shared account, family members)Per person, not per device — each member's consent and claims are their ownServer, keyed to the person, with the household as a relationshipSame as browserRecommendations may use household context only where each member's consent allowsOne member's grant never covers another; erasure is per person
Point of sale (store terminal)Staff identity for the terminal; customer identity only when the customer offers itServer; the terminal holds a scoped key, not customer dataScoped event keys — e.g. a terminal may read consent, not write product dataMay read whether a customer consented to a purpose; may not export or enrichKeys scoped per terminal and revocable on the next request
Desktop (installed app)Same as browser — the app shows the hosted pageServer; the app stores nothing sensitiveHTTPS to the same endpointsSame as browserSigned installer; no native access granted to remote content
Agent (AI acting for a subject)The subject's claims, passed for one step, never stored by the agentServerTool calls to the same endpoints, each checkedOnly under a signed, capped, scoped, time-boxed, revocable mandateEvery grant and refusal logged; no standing credential
Rule that holds across channelsWhy
Consent follows the person and their location, not the device or channelA household tablet and a store terminal must not widen what one person agreed to
The server is the only place a decision is madeA channel that decides for itself becomes the weakest channel
Every channel's data carries the same codes (ISO country, language, currency, units)Otherwise the same customer is a different record per channel
AI visibility is granted per purpose, not per channel"The agent can see POS data" is not a rule; "the agent may read consent status for purpose X" is
Erasure reaches every channel's copiesIncluding terminal logs, device caches, agent memory and ad platforms

7. US integration-platform (ERP/CRM middleware) fees

Only MuleSoft's entry price and Boomi's pay-as-you-go are published by the vendors; every other figure is a third-party estimate. Get a quote.

PlatformPublished / reported pricingModel
MuleSoft (Salesforce)From $2,000/month, billed annually (official). 2026 packages priced by Mule flows and messages; legacy vCore plans reported at ~$1,250–$1,750 per vCore per month; premium connectors ~$10k–$15k each per year (Automation Atlas, Integrate.io)Quote above entry
BoomiPay-as-you-go $99/month + $0.05 per message (official); committed editions quote-only, reported $50k–$190k+/year, total cost often 2–3× licence (Automation Atlas)Per message, or annual contract
CeligoNo list price; reported ~$1,000–$1,500/month small, $5,000+/month enterprise (~$12.8k–$73k/year by company size) (Vendr, Integrate.io)Quote, by flows and endpoints

What the fee does not include: the controls in §1–§6. A middleware platform moves data; the consent, retention, erasure and residency evidence is still the organisation's to produce.


SystemWhat to checkWhy it matters
Email / SMS marketing platform (e.g. Klaviyo)Whether it offers a retention period per data type; how deletion treats suppression lists; where exports are keptOld events keep powering segments and retargeting unless something purges them
CRM (e.g. Salesforce)Deleted records stay in the Recycle Bin 15 days; field history is kept 18–24 months (longer is an add-on); whether marketing data extensions carry a retention settingConsent recorded in one cloud does not stop a send or sync in another unless it is enforced there too
Agent runtimes (e.g. Google ADK / Agent Engine)Whether sessions and memory are reached by your erasure processAn erased customer's words can survive in agent memory
Google Ads / Merchant CenterCustomer Match needs consented data; EEA traffic needs Consent Mode v2 (ad_user_data, ad_personalization); the Merchant loyalty member API takes unhashed email and phone; YouTube affiliate reporting must not be joined with personal or CRM dataPolicy breaches lead to account suspension
RetargetingCross-context behavioural advertising is "sharing" under CCPA/CPRA: honour Global Privacy Control and "Do Not Sell or Share"$2,663 per violation; $7,988 intentional or involving under-16s (2025 figures, CPPA), assessed per consumer; breach private actions $107–$799 per consumer. Sephora paid $1.2M (2022)
Video pagesAd pixels on pages that play video can trigger the Video Privacy Protection ActUse a privacy-enhanced player and keep ad pixels off video pages without consent

9. The one-line summary per section

SectionIf you remember one thing
GovernanceErasure must reach AI stores, not only the database
TransportWhere data lives is a deployment setting, and it decides who must consent
ScalingA second answer path and idempotent retries, or availability is a hope
AI-specificThe agent never decides what it may do
Rules vs themeDecide on the server from rules and ISO codes; the theme only displays
Cross-channelA channel is not a permission; every channel meets the same server rules
Middleware feesThe fee moves data; it does not produce the compliance evidence
PenaltiesRetargeting without honouring opt-out is priced per consumer