CompTIA Cloud+ (CV0-004)SecurityEasy

A global organization is implementing a cloud-based data analytics platform that processes sensitive customer data from various regions. Due to strict regulatory requirements in Europe, all data originating from European citizens must be processed and stored exclusively within the European Union. Which compliance concept primarily addresses this requirement?

  1. AData Sovereignty
  2. BData Minimization
  3. CData Portability
  4. DData Encryption
Show answer & explanation

Correct answer: A. Data Sovereignty

Data sovereignty refers to the concept that digital data is subject to the laws of the country in which it is stored. The requirement to process and store data exclusively within the EU for European citizens directly relates to data sovereignty.

Why the other options are wrong

  • B. Data minimization is the principle of collecting only the necessary amount of data, not about its geographical location.
  • C. Data portability is the right to obtain and reuse personal data for one's own purposes across different services, not about where data must reside.
  • D. Data encryption protects data confidentiality and integrity but does not dictate its geographical storage location.

Data Sovereignty

Data sovereignty is the concept that digital data is subject to the laws and regulations of the country in which it is stored or processed.

  • Impacts where data can be physically located.
  • Driven by national laws and international regulations (e.g., GDPR).
  • Requires cloud providers to offer regional data centers.

Memory trick: Sovereignty means data stays in its own land.

More Security questions