> Whatever we say to our customers about how Cronofy approaches data privacy and controls, corresponding enforcement will not follow. (...) We can make our protestations about ISO certifications, data management controls, segmented data hosting. However, prospective customers won’t necessarily get that far because we’ll be discounted based on our location. I don’t blame them. Data protection is fraught and complicated. Why even entertain the risk of going with a provider from outside the EU.
Yet. Because you're still on compliance and procurement whitelists. If UK's regulation are no longer up to EU's standards, UK drops out of the whitelist and any supplier there jumps off the fast-track into the slow lane of "compliance audit". Spoiler: that's the point at which the contracting manager drops you for your far less able competitor that's hosted in Dublin or Amsterdam.
If UK law would require backdoors in a way that conflicts with GDPR, how could they remain compliant?
Snowed proved that the US used backdoors in Microsoft products to access calendar entries snd emails to give Boeing an edge during negotiations.