CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A global healthcare provider is deploying a new patient management system across multiple countries. Due to strict regulatory requirements (e.g., GDPR, HIPAA, local data protection laws), patient data collected in one country must remain physically stored and processed within that country's borders. The security architect needs to design the data architecture to comply with these regulations. Which data security principle is paramount in this scenario?

  1. AData Masking
  2. BData Tokenization
  3. CData Localization (Data Residency)
  4. DData Minimization
Show answer & explanation

Correct answer: C. Data Localization (Data Residency)

Data localization, also known as data residency, is the principle that certain data must be stored and processed within the physical borders of a specific country or jurisdiction. This directly addresses the regulatory requirement for patient data to remain within the country of origin.

Why the other options are wrong

  • A. Data masking replaces sensitive data with structurally similar but inauthentic data, typically for testing or non-production environments, not for enforcing geographical storage.
  • B. Data tokenization replaces sensitive data with a non-sensitive equivalent (token), primarily for reducing the scope of compliance (e.g., PCI DSS), but it doesn't dictate the physical storage location of the actual data.
  • D. Data minimization focuses on collecting and processing only the necessary amount of data, which is a good practice but doesn't address the geographical storage requirement.

Data Localization (Data Residency)

Data localization, or data residency, is a regulatory requirement or organizational policy that mandates that certain data must be stored and processed within the physical borders of a specific country or jurisdiction. This is often driven by national data protection laws.

  • Mandates data storage and processing within a specific geographical area.
  • Driven by regulatory compliance (e.g., GDPR, HIPAA, national laws).
  • Can impact cloud deployment strategies and global data flows.
  • Requires careful architectural planning for multi-country operations.

Memory trick: Local Laws Limit Location, Ensuring Data Stays Safe.

More Security Architecture questions