CompTIA DataSys+ (DS0-001)Data and Database SecurityMedium

A global technology company operates databases in multiple regions. Due to varying international regulations (e.g., GDPR, CCPA), the company must ensure that specific types of customer data originating from a particular geographic region are stored and processed only within that region. What concept does this requirement describe?

  1. AData masking
  2. BData replication
  3. CData sovereignty
  4. DData tokenization
Show answer & explanation

Correct answer: C. Data sovereignty

Data sovereignty refers to the idea that data is subject to the laws and governance structures of the country or region in which it is collected or processed. This often mandates that data originating from a specific region must remain within that region's physical borders.

Why the other options are wrong

  • A. Data masking obscures sensitive data for non-production environments but doesn't dictate physical location.
  • B. Data replication copies data for availability or performance, which could violate sovereignty if copies are in prohibited regions.
  • D. Data tokenization replaces sensitive data with non-sensitive tokens but doesn't manage geographic storage requirements.

Data Sovereignty

Data sovereignty is the concept that digital data is subject to the laws of the country in which it is stored. This often implies that data must physically reside within the borders of its originating country or region.

  • Data subject to local laws.
  • Often requires in-country storage.
  • Driven by national security, privacy, and economic concerns.

Memory trick: Sovereignty keeps data home.

More Data and Database Security questions