How Data Sanitisation Helps Where Law and Contracts Can’t

27 Reasons your data isn’t safe

How Data Sanitisation Helps Where Law and Contracts Can’t

The Problem Landscape

Across 27 LinkedIn posts in three series, we have documented a comprehensive picture of why sensitive data — personal data, intellectual property, trade secrets, competitive intelligence, and corporate strategy — is fundamentally at risk when it leaves an organisation’s control and enters the infrastructure of a foreign-jurisdiction provider.

The conclusions are uncomfortable. They apply to every organisation using AI APIs, cloud services, or any external provider subject to foreign government data access laws. And they apply regardless of which flag flies over that provider.

Series 1: The Wisdom of Foolishness

9 posts — Cybersecurity ideas the establishment got wrong

This series established a historical pattern: every significant advance in cybersecurity was initially dismissed by the establishment as impractical, dangerous, or unnecessary. Public-key cryptography was called a fool’s errand. Strong civilian encryption was classified as a weapon of war. Zero Trust was dismissed as neat but impractical. Full disclosure was branded information anarchy. Penetration testing was a boardroom joke. Bug bounties meant paying strangers to hack you. MFA was too inconvenient. Open-source security was giving attackers the blueprint.

The pattern: An outsider proposes something contrarian. The establishment dismisses it. Reality forces the issue. The “stupid” idea becomes standard practice — often mandated by the very people who fought it.

The conclusion: AI data loss prevention, outbound API inspection, data sovereignty enforcement, and ephemeral processing architectures are today where zero trust was a decade ago. The ideas being dismissed now will be standard practice within years. CattleGrid already does it, don’t make best practice something you do in 10 years. The question is, how much damage will be done in terms of cost and brand before you do?

Series 2: The Article 7 Paradox

9 posts — Chinese law obligations and the impossible compliance position for UK/European companies

This series documented the interlocking cage of seven Chinese laws — the National Intelligence Law, Cybersecurity Law, Data Security Law, PIPL, Cryptography Law, Counter-Espionage Law, and National Security Law — that collectively make every Chinese company an instrument of state intelligence. Article 7’s seven words (“support, assist, and cooperate with national intelligence”) create personal obligations on individual Chinese citizens, not just corporate entities, with mandatory secrecy, no judicial oversight, no warrant requirement, and no mechanism to challenge.

The enforcement precedent: The Irish DPC fined TikTok €530 million for transferring European data to China. Italy banned DeepSeek within weeks of launch. These are not theoretical risks.

The PIPL paradox: China’s “GDPR-equivalent” protects citizens from companies but explicitly exempts the government. The Cryptography Law gives the State Cryptography Administration access to commercial encryption keys. Even end-to-end encryption provides no protection against a state that holds the keys.

The conclusion: Chinese AI providers represent an unmitigable compliance risk. Standard Contractual Clauses cannot override Article 7. Transfer Risk Assessments cannot demonstrate adequate protection. The risk is not theoretical — it is structural and legal.

Series 3: Whose Flag Protects You?

9 posts — US law vs Chinese law — and the kicker few know about

This series compared US and Chinese data access frameworks honestly — acknowledging the US system’s genuine constitutional constraints, independent courts, transparency reporting, and adequacy framework — before demonstrating that neither system is compatible with genuine European data sovereignty. The CLOUD Act compels US companies to produce European data regardless of where it’s stored. FISA Section 702 authorises warrantless surveillance of non-US persons. Executive Order 14086 can be revoked by any future president.

The kicker: Post 8 revealed the case that blows everything up. On 25 September 2025, an Ontario court ordered OVHcloud — a French company, storing data on servers in France — to hand over customer data to Canadian police. Not through a treaty. Not through diplomatic channels. Directly. The judge’s reasoning: OVH has a “virtual presence” in Canada because it offers services there. That was sufficient. OVH now faces criminal liability in both countries.

The Microsoft testimony: In June 2025, Microsoft France’s legal director testified under oath before the French Senate. Asked whether he could guarantee French citizen data in EU data centres would not be handed to US authorities, his reply was unequivocal: “No, I cannot guarantee that.”

The conclusion: No flag protects you. No adequacy decision prevents a warrant from being served. No Standard Contractual Clause overrides a foreign intelligence law. No data residency guarantee survives a “virtual presence” ruling. The entire debate about which country is safer is a distraction from the only question that matters: does sensitive data leave your control?

The Common Thread

Strip away the jurisdictional detail, the specific laws, and the individual enforcement actions, and all 27 posts arrive at the same place:

Once sensitive data leaves your infrastructure in readable form, you have lost control of it.

It does not matter whether the provider is American, Chinese, Canadian, or any other nationality. It does not matter whether the data is stored in London, Frankfurt, or Paris. It does not matter what your contract says, what adequacy framework applies, or what Standard Contractual Clauses you have signed. If a foreign government serves a legal demand on a provider with a corporate presence in their jurisdiction, that provider must comply — or face the consequences.

The only protection that works regardless of jurisdiction is ensuring sensitive data never reaches a provider in a form that can be exploited. That means controlling what is sent, not where it is stored.

Five Problems, One Root Cause

ProblemIdentified InRoot Cause
Chinese state access to data via Article 7 and six supporting lawsArticle 7 Paradox (Posts 1–7)Sensitive data sent to Chinese-jurisdiction provider in plaintext
US government access via CLOUD Act warrantsWhose Flag (Posts 2–3)Sensitive data accessible to US-jurisdiction provider
FISA Section 702 warrantless surveillance of non-US personsWhose Flag (Post 3)Sensitive data transiting US-jurisdiction infrastructure
Canadian “virtual presence” doctrine reaching French dataWhose Flag (Post 8)Any corporate presence in any jurisdiction creates exposure
Encryption useless for AI APIs (models require plaintext)Whose Flag (Post 7), Article 7 (Post 2)AI workloads require data in readable form

Common root cause: Sensitive data leaves the organisation’s infrastructure in a form that can be read, intercepted, or compelled.

How CattleGrid Solves This

CattleGrid is an enterprise API security gateway that sits between an organisation’s applications and AI providers. It intercepts outbound API requests, inspects them for sensitive data, and either sanitises or blocks them before they reach any external provider. It is the data sanitisation layer that every series concluded was the only universal answer.

The Core Principle: Control What Leaves, Not Where It Goes

Every post across all three series arrives at the same conclusion: data residency is insufficient, contracts are unenforceable against sovereign power, and encryption cannot protect data that AI models must process in plaintext. The only reliable protection is ensuring sensitive data never leaves your infrastructure in a form that can be exploited.

CattleGrid implements exactly this. It operates as a transparent proxy: organisations point their AI API calls at CattleGrid instead of directly at the provider. CattleGrid inspects outbound requests using configurable rules and customer-specific AI agents, removes or blocks sensitive content, and forwards the sanitised request to the upstream provider. AI responses flow back directly to the customer — CattleGrid never sees, stores, or processes them.

Mapping Series Conclusions to CattleGrid Capabilities

Chinese Law Risks (Article 7 Paradox)

Risk IdentifiedCattleGrid Mitigation
Article 7 compels Chinese providers to hand data to the state on demandSensitive data is sanitised before reaching any provider. Even if data is compelled, it contains no exploitable information.
Seven interlocking laws create overlapping state access rightsProvider-agnostic protection. CattleGrid applies the same sanitisation regardless of which AI provider is downstream.
Cryptography Law gives state access to encryption keysData sanitisation operates before encryption. Even if keys are compromised, the sensitive content was never in the request.
No judicial oversight, no ability to challenge or discloseIrrelevant if data reaching the provider has already been stripped of sensitive content. Prevention beats process.
TikTok €530m fine for inadequate data transfer protectionsCattleGrid provides auditable evidence that sensitive data was removed before transfer. Compliance logging records every sanitisation event.

US and Canadian Law Risks (Whose Flag Protects You?)

Risk IdentifiedCattleGrid Mitigation
CLOUD Act warrants reach European data regardless of storage locationData sanitised before reaching US-jurisdiction providers. A CLOUD Act warrant produces sanitised content only.
FISA 702 warrantless surveillance of non-US personsSurveillance captures sanitised API traffic, not raw sensitive data.
DPF/adequacy framework fragile (third attempt, executive order not legislation)CattleGrid provides supplementary technical measures recommended by the EDPB for data transfers. Protection does not depend on adequacy frameworks surviving legal challenge.
OVH “virtual presence” ruling — any jurisdiction can reach data through corporate presenceJurisdiction-agnostic protection. CattleGrid sanitises data regardless of where the provider operates or has subsidiaries.
Encryption useless for AI APIs (models require plaintext)Data sanitisation works where encryption cannot. Removes sensitive content before sending to any AI model that must process plaintext.
Microsoft France testimony: cannot guarantee data sovereigntyRemoves dependence on provider guarantees. Protection is applied by the customer’s own infrastructure, not promised by the provider.

Historical Pattern (Wisdom of Foolishness)

Pattern IdentifiedCattleGrid Position
Every critical security tool was initially dismissed as unnecessary or impracticalAI data loss prevention is following the identical adoption curve. Outbound API inspection will be standard practice within years, just as zero trust, MFA, and open-source security became mandatory.
The establishment resists until breaches, fines, or regulation force adoptionThe TikTok €530m fine, the OVH ruling, and Microsoft’s testimony are the forcing events. Organisations that adopt data sanitisation now avoid the damage that forces laggards to adopt later.
Zero Trust moved from “neat but impractical” to Presidential Executive OrderCattleGrid applies Zero Trust principles to AI API traffic: never trust that outbound requests are clean, always verify, always inspect.

Why CattleGrid Specifically

Data sanitisation is the answer every series arrived at. But not all sanitisation is equal. CattleGrid’s architecture was designed from the ground up to address the specific risks documented across these 27 posts.

Jurisdiction Is Irrelevant When There’s Nothing to Compel

Every post in these three series documents the same threat: a foreign government compelling a provider to hand over data. The CLOUD Act, Article 7, FISA Section 702, the OVH “virtual presence” ruling — all of them assume one thing: that the provider holds the data.

CattleGrid doesn’t. Customer data is processed entirely in memory. It is never written to disk. It is never logged. It is never retained. The moment inspection completes, the data ceases to exist. There is nothing to seize, nothing to compel, nothing to hand over. A warrant served on CattleGrid’s infrastructure — regardless of where that infrastructure sits or what jurisdiction claims authority over it — produces nothing, because there is nothing to produce.

This is not a policy. It is an architectural guarantee. The platform was designed from the ground up around ephemeral processing precisely because of the geopolitical reality these series document. The entire debate about which jurisdiction is safe, which adequacy framework will survive, which flag protects you — none of it applies to data that doesn’t exist.

This also eliminates the irreconcilable GDPR conflict that the Article 7 series documented: once data enters an AI model’s training data, it cannot be meaningfully deleted without complete retraining, creating an automatic right-to-erasure breach. CattleGrid’s ephemeral architecture means there is no retention to conflict with. The data retention risks that drove the TikTok €530 million fine do not arise because there is no data retention.

The platform itself has no hard dependency on any specific cloud provider, AI model vendor, or infrastructure platform. CattleGrid may run on Scaleway today and OVH tomorrow. It could run on bare metal or a rack of Raspberry Pis. That architectural independence matters — not because customers choose where the SaaS platform is hosted, but because no single vendor’s jurisdictional exposure can ever become a structural risk to the platform. And for organisations that need total control, the same platform can be deployed on their own infrastructure, on-premises.

Customer-Specific Intelligence

Generic detection rules cannot distinguish between sensitive and non-sensitive data in context. A pharmaceutical company’s internal compound code looks identical to a routine product identifier. CattleGrid deploys dedicated, customer-specific AI agents trained on each customer’s own data classifications. Each customer teaches CattleGrid what is sensitive in their specific context: intellectual property, trade secrets, competitive intelligence, not just personal data. Training data is deleted immediately after fine-tuning.

Outbound-Only Inspection

CattleGrid inspects only the outbound request to AI providers. AI responses flow directly back to the customer without inspection. This privacy-first architecture means CattleGrid never sees AI-generated content, eliminating an entire category of processing risk.

Provider Agnostic

The Whose Flag Protects You? series demonstrated that no single jurisdiction is safe. The problem is not the US. It is not China. It is not Canada. It is any jurisdiction with the power to compel data access. CattleGrid’s provider-agnostic architecture applies the same protection regardless of which AI provider is downstream. New providers are added through configuration, not code changes. The same sanitisation rules protect data whether it’s heading to Anthropic, OpenAI, Google, or any future provider, regardless of their jurisdiction.

Compliance Evidence

The ICO requires Transfer Risk Assessments for international data transfers. The TikTok decision turned on the inability to demonstrate adequate protection. CattleGrid provides auditable, timestamped evidence of every sanitisation event: what was detected, what was removed, which rules triggered, and which regulations applied. This evidence supports TRA completion and demonstrates the “supplementary technical measures” the EDPB recommends for transfers to jurisdictions without adequate protection.

Zero-Friction Integration

The Wisdom of Foolishness series documented how security tools that create friction get bypassed. CattleGrid mirrors AI provider APIs exactly. Organisations change a single environment variable — the API base URL — and all existing code works unchanged. No SDK changes. No application rewrites. No workflow disruption. This is the lesson from MFA adoption: if security creates friction, people disable it.

Conclusion

Twenty-seven posts. Three series. One conclusion.

The history of cybersecurity tells us that every critical protection was dismissed before it was adopted. The legal landscape tells us that no foreign jurisdiction’s framework is compatible with genuine European data sovereignty — not the US, not China, and as we now know, not Canada or any other country with the appetite to assert jurisdiction over European data.

The fixation on US versus China is taking everyone’s eye off the ball. The question was never “which flag is safer?” It was always “does sensitive data leave your control?”

If it does, you are depending on a foreign legal system to protect it. And foreign legal systems protect their own interests, not yours.

CattleGrid ensures sensitive data never reaches any provider in a form that a foreign government request could exploit. And because it stores no customer data of any kind, the jurisdictional risks documented across all three series simply do not apply to it. There is nothing to compel. There is nothing to seize. The geopolitical chaos currently engulfing international data flows passes straight through CattleGrid without finding anything to grab hold of.

Whose flag protects you? Your own. If you take the right steps to make that mean something.

For more information about CattleGrid, contact Rob Harrison.

rob@cattlegrid.uk

Related Posts