Not a vulnerabilityA fault in a measurement, not in a system. Nothing was attacked and no party misbehaved; the conclusion about where data went is simply not supported by the source it was drawn from.
What it is
A finding states that data left for a particular country. The country came from a lookup table mapping addresses to locations. Such tables are snapshots: address blocks are reassigned, providers move ranges between regions, and hosting shifts between sites. A table built before the measurement can place a current address in a country it left, in either direction.
Why it is a separate entry
The transfer question is the one most likely to be contested, and it is the one where a wrong answer is easiest to demonstrate. A single misplaced address lets the other party dismiss the whole measurement without addressing the rest of it.
How it arises
a lookup database shipped with a tool and never updated
the country of the operating company used instead of the destination of the traffic
a content delivery front end resolved to one country while the origin sits elsewhere
the country recorded at analysis time rather than at capture time, with the reassignment in between
Not to be confused with
Genuinely sending data to a third country is a fault of the system, and the transfer provisions address it. This entry is about the claim: the destination attributed may not be where the data went.
How to establish it
Resolving the same addresses again with a lookup source built after the measurement date yields a different country for at least one host in the finding. Alternatively, the build date of the source used precedes the measurement date.
method differentialQoD 90
Requirements on the measurement
record the addresses as resolved at capture time, not only the host names; a name resolves differently later
record the build date and version of the lookup source, and publish it with the finding
resolve from the same country the capture ran in, since resolution is frequently location-dependent
keep the routing evidence for any host on which the transfer claim rests
What would refute it
automatedThe lookup source was built after the measurement and re-resolution yields the same country.finding falls
by handThe destination is established by routing or by a statement from the party rather than by a lookup table.finding falls
by handThe finding does not depend on the country at all.Many findings stand regardless of destination. Where the country is decoration, remove it rather than defend it.finding falls
automatedOnly hosts irrelevant to the claim changed country on re-resolution.weakens
Where this plugs into existing processes
The one question that surfaces itWhich database told you that this address is in that country, and when was it built?
In a DPIA, verify this
Verify how the destination country in a supporting measurement was established, and with a source of which date.
As a procurement clause
Any transfer statement is supported by addresses resolved at the stated date, with the version of the lookup source named.
With a complaint, hand over
The addresses as resolved at capture time, the version and build date of the lookup source, and the routing evidence for the hosts the claim rests on.
Reproduction
METHOD.md · by hand · no dedicated reproduction exists yet; follow the general method and the indicator above
Legal framing
eu-gdpr-44
eu-gdpr-5-2
Objections, and the answer
“The tool said so.”
The tool consulted a table with a build date. Publish that date, and re-resolve if it precedes the measurement.
“The company is American, so the data goes to America.”
Where a company is based says nothing about where the traffic lands, and the reverse holds too. The destination is measurable; the origin of the company is not the measurement.
“It resolves to that country from here.”
Then say from where and when you resolved it. That is a fact about your measurement, and stating it is what makes it checkable.
What this does not establish
harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
unlawfulness; that is for a supervisory authority or a court
intent; a fault is usually a build decision, not a plan
absence: not finding it in one capture is not evidence that it is not there
DPE Catalogue. DPE-2026-0027: Country attributed from a stale database. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0027
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0027, established under DPE Measurement Method 1.0”
Identifiers are permanent and are never
reused. An entry that is deprecated keeps its number and its address, with the reason attached, because
references to it exist elsewhere.