Purpose owner
Record who decides why each category of personal data is used and the business process it supports.
Buyer worksheet 06 · system geography
Map every place where Magento or Adobe Commerce code, customer data, logs, backups and support access may be processed. Record the legal entity, technical system, access role and country separately. A UK office, UK account manager or UK hosting region does not answer the whole data-location question.
UK buyer guide. Not affiliated with Adobe Inc. Not legal or tax advice.
Check 01
Start with the planned architecture and delivery workflow. Different records may use different systems, regions, suppliers and retention periods.
| Record or system | Examples to map | Buyer question |
|---|---|---|
| Storefront and commerce | Catalogue, account, basket, quote, order and customer records | Which service and region stores each dataset? |
| Integrations | ERP, PIM, OMS, WMS, CRM, payments, tax and delivery messages | Where are payloads queued, logged, retried or archived? |
| Engineering | Source code, commits, CI/CD, artefacts, secrets and environments | Which supplier and named users can reach each system? |
| Operations | Logs, traces, alerts, tickets, recordings and support exports | Can production or personal data appear in these tools? |
| Resilience | Backups, replicas, snapshots, recovery copies and archives | Which regions and retention rules apply to every copy? |
| Analytics | Web analytics, session tools, data warehouse and reporting extracts | Which identifiers are sent, and to which entities and regions? |
Check 02
Do not assign a legal role from a job title or hosting diagram. Give the actual purposes, instructions, entities and access paths to privacy counsel.
Record who decides why each category of personal data is used and the business process it supports.
Record each entity that handles data under another party’s documented instructions.
Ask whether any supplier uses data for its own purpose and how that changes the contract record.
Map each delivery role to the minimum systems, permissions and data fields required.
Identify separate entities that may process data for a contracted processor.
Name the buyer’s privacy, security and system owners who validate the completed map.
Use the ICO controller–processor contract guidance as an official starting point, then obtain advice for the planned arrangement.
Check 03
A region shown in a cloud console is one evidence item. It does not describe every replica, backup, support path or connected platform.
Record production, staging, development and preview service regions separately.
Record primary, replica, failover, search, cache and queue regions.
Map media, exports, imports, invoices, documents and generated reports.
Record backup, snapshot, archive and disaster-recovery locations and restore controls.
Map every ERP, PIM, payment, tax, delivery and analytics platform separately.
Check 04
Delivery tools can contain customer information, credentials, production exports or screenshots even when the main store database stays in a chosen region.
Check 05
Hosting geography and access geography are separate. Connect the named roster to each system permission and review the result when a person or country changes.
| Field | Evidence | Control question |
|---|---|---|
| Person and entity | Named user, employer or subcontractor | Is access tied to a current approved roster entry? |
| Connection country | Normal and permitted access countries | What happens before access from a new country? |
| System and data | Role, environment, dataset and privilege | Is the permission the minimum needed for the task? |
| Authentication | Identity provider, MFA, device and privileged-access controls | Who approves, reviews and revokes access? |
| Time limit | Start, expiry and review date | Does access end with role, assignment or engagement? |
| Evidence | Access log, review record and removal confirmation | How can the buyer inspect the control? |
Check 06
Record the factual chain first. Ask privacy counsel to decide whether a restricted transfer exists and which documentation or safeguard is required for the exact parties, countries and access.
Exact subprocessor name, company country and service supplied.
Processing purpose, data categories, data subjects and systems touched.
Primary, replica, backup and recovery countries or regions.
Countries from which support or administration may reach the service.
Authorisation route, notification period, objection process and flow-down duties.
Required assessment, transfer document, supplementary measure or recorded exception.
A London office does not prove that Magento data, source code, logs, backups or support access stay in the UK. A UK hosting region does not prove that every connected system or remote administrator is in the UK.
Buyer action: ask counsel to assess the completed map against current ICO international-transfer guidance. This fieldbook does not select a transfer mechanism.
Check 07
State the lifecycle for each record type and every copy. A general deletion promise may not explain backups, logs, legal holds or recovery media.
Record the purpose, period, trigger, owner and exception for each data class.
Define deletion timing, method, system coverage and evidence available to the buyer.
Record immutable periods, expiry, restoration behaviour and treatment of deleted records.
Specify export format, encryption, transfer route, completeness check and delivery date.
Set access removal, subprocessor closure, account transfer and final evidence duties.
Check 08
Ask for the actual artifact, scope, covered entity, period, exceptions and remediation record. Do not turn a provider statement into third-party assurance.
Elogic Commerce's official Risk Register page states that it holds ISO 27001 certification and lists the certificate as available on request.
Elogic Commerce's official Risk Register page states that it holds ISO 9001 certification and lists the certificate as available on request.
Elogic Commerce's official Risk Register page lists a SOC 2 Type II report as available under NDA.
Read the Elogic Commerce Risk Register source for all three statements.
The artifacts have not been independently inspected. A SOC 2 Type II report is a report, not a certification. Keep the three statements separate.
Do not infer: ISO 27001 does not by itself prove UK data residency or GDPR compliance. Ask for scope, entity, sites, dates and exceptions, then have the buyer’s specialists assess relevance.
Check 09
Approve one joined record that connects every system to its data, entities, storage, access, transfer decision, retention and exit controls.
| Record group | Minimum fields | Approval owner |
|---|---|---|
| System | Owner, service, purpose, data, production and recovery regions | Architecture / service owner |
| Entity | Supplier or subprocessor, role, company country, contract link | Procurement / privacy |
| Access | Named role, person or controlled group, country, permission, expiry | Security / system owner |
| Transfer question | Countries, access type, adviser decision and required documents | Privacy counsel |
| Lifecycle | Retention, backup, restore, return, deletion and evidence | Data owner / operations |
| Incident | Notification, response contacts, audit access and evidence route | Security / legal |
Do not claim UK-only residency while a connected service, backup, subprocessor or remote-access country remains unknown.
Boundary: this is a technical procurement worksheet, not legal advice. Counsel should determine the required transfer mechanism and contract wording.
Connect the records
The residency schedule is reliable only when the counterparty and roster records use the same legal entities, people, countries and change controls.