Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

TRUST CENTER

Data Residency

Data Residency explains the supported user journey, operating responsibility and verifiable service status.

Scope verifiedDeployment boundary disclosed

Purpose and operational value

PAINFragmented, hard-to-trace integration
TRUSTED CAREOne governed flow
DAILY BENEFITFewer repeats, clear status
TRUST BOUNDARYAuthorization, consent and audit

Business flow

  1. Use case
  2. Identity & authorization
  3. Data / resource
  4. Workflow
  5. Testing
  6. Production boundary
  7. Evidence
Public status reflects evidenced capability; integrations remain configuration-dependent.

Responsibility boundary

Responsibility boundary
Layer Responsibility Status
Trusted Care Initiation, orchestration, role mapping, audit Available
Mobile-ID Identity Layer Identity linking, assurance, evidence Integration-dependent
RAR / VNeID Transaction authentication or information sharing Per approved integration

Evidence and support

Every production claim must be reconciled with the integration register and publication approval. No certification or clinical outcome is implied.

DATA SCOPE

Residency is evaluated by data class, not a single database location

A residency statement must distinguish clinical/personal content from operational metadata, security logs, backups and cryptographic material. Each class can have a different storage or support boundary.

01

Clinical & personal data

Patient records, observations, documents and other regulated content follow the selected deployment/tenant data boundary.

02

Metadata & audit

Identifiers, operational metadata and audit/security logs need an explicit location/retention decision; they are not assumed to follow the same path automatically.

03

Backup & DR

Backup copies and disaster-recovery replicas are part of the residency decision and must be disclosed with primary storage.

04

Keys & support access

Key-control location and privileged support access are separate controls; residency alone does not prove who can decrypt or administer data.

DEPLOYMENT DECISION

Resolve residency before production activation

Trusted Care should not publish a blanket country/region claim without the corresponding deployment evidence.

Select deploymentChoose cloud/on-premise/tenant model and intended primary region/location.
Classify dataMap clinical data, personal data, metadata, logs, backups and key material to storage/processing components.
Review transfersIdentify replication, support, integration and subprocessor flows that could cross the intended boundary.
Set controlsApply encryption/key, access, backup/DR, export and support-session controls for the selected model.
Evidence configurationRecord region/tenant configuration, backup/DR location, approved subprocessors and privileged-access path.
Change governanceRe-review residency when region, provider, DR design, integration or support model changes.
CUSTOMER QUESTIONS

What a buyer should be able to verify

The Trust Center should answer these items for the actual deployment rather than relying on a generic “data stays local” statement.

01

Primary location

Where is each relevant data class stored and processed in normal operation?

02

Resilience location

Where do backups and DR replicas reside, and what restore path is approved?

03

Cross-border path

Which integrations, subprocessors or support actions can move/access data outside the intended region?

04

Evidence

Which configuration record, contract schedule, subprocessor list and access log support the published residency statement?

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access