A Frankfurt-based insurer runs its claims platform as a SaaS subscription. The provider stores personal data across public-cloud regions in Germany and the United States. A United States court issues a subpoena to the provider demanding claims records that include EU residents' personal data, and EU law restricts that transfer. What is the insurer's central legal risk in this situation?
- AVendor lock-in, because the SaaS provider controls the claims data format and the insurer cannot readily migrate to another platform
- BLoss of the availability of the claims records, since responding to the subpoena will take the SaaS platform offline for the insurer's users
- CConflicting international legislation, where complying with the foreign disclosure order would breach the data-protection law governing the same records Correct
- DWeak encryption of the claims data at rest, which would let the requesting court read the records without the insurer's cooperation
Why A is wrong: Lock-in is a real cloud concern about portability and exit, but the scenario turns on incompatible legal obligations across borders, not on the difficulty of switching providers.
Why B is wrong: Producing records for discovery does not require an outage, so availability is not the exposure; the harm is legal liability for whichever law the insurer ends up breaching.
Why C is correct: Correct: the defining cloud legal risk here is one jurisdiction compelling disclosure while another jurisdiction prohibits the transfer, forcing the controller into an unavoidable conflict of laws.
Why D is wrong: Encryption strength is a control question that a candidate may reach for, but a lawful subpoena compels the plaintext or the keys regardless, and the conflict is jurisdictional rather than cryptographic.