DPE-2026-0027

Country attributed from a stale database

A transfer claim rests on an address-to-country lookup that no longer matches the assignment.

In het NederlandsLand bepaald met een verouderde databaseWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Method webappIoTfirmware status active
Not a vulnerabilityA fault in a measurement, not in a system. Nothing was attacked and no party misbehaved; the conclusion about where data went is simply not supported by the source it was drawn from.

What it is

A finding states that data left for a particular country. The country came from a lookup table mapping addresses to locations. Such tables are snapshots: address blocks are reassigned, providers move ranges between regions, and hosting shifts between sites. A table built before the measurement can place a current address in a country it left, in either direction.

Why it is a separate entry

The transfer question is the one most likely to be contested, and it is the one where a wrong answer is easiest to demonstrate. A single misplaced address lets the other party dismiss the whole measurement without addressing the rest of it.

How it arises

Not to be confused with

Genuinely sending data to a third country is a fault of the system, and the transfer provisions address it. This entry is about the claim: the destination attributed may not be where the data went.

How to establish it

Resolving the same addresses again with a lookup source built after the measurement date yields a different country for at least one host in the finding. Alternatively, the build date of the source used precedes the measurement date.

method differentialQoD 90

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itWhich database told you that this address is in that country, and when was it built?
In a DPIA, verify this

Verify how the destination country in a supporting measurement was established, and with a source of which date.

As a procurement clause

Any transfer statement is supported by addresses resolved at the stated date, with the version of the lookup source named.

With a complaint, hand over

The addresses as resolved at capture time, the version and build date of the lookup source, and the routing evidence for the hosts the claim rests on.

Reproduction

Legal framing

Objections, and the answer

“The tool said so.”

The tool consulted a table with a build date. Publish that date, and re-resolve if it precedes the measurement.

“The company is American, so the data goes to America.”

Where a company is based says nothing about where the traffic lands, and the reverse holds too. The destination is measurable; the origin of the company is not the measurement.

“It resolves to that country from here.”

Then say from where and when you resolved it. That is a fact about your measurement, and stating it is what makes it checkable.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0027 (Country attributed from a stale database)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0027
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0027/index.json
Full
DPE Catalogue. DPE-2026-0027: Country attributed from a stale database. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0027
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0027, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.