A healthcare analytics startup is using BigQuery to store de-identified patient data. They need to ensure that data is stored in the EU region to comply with GDPR, and that all data transfers between Google Cloud services within their project also remain within the EU region. How can they enforce this data residency requirement?
- AConfigure Cloud DNS to resolve Google Cloud service endpoints to EU regional IPs only.
- BCreate all BigQuery datasets and other resources in an EU region and rely on default Google Cloud networking.
- CImplement an Organization Policy Constraint (Resource Location Restriction) to limit resource creation to EU regions.
- DUse a VPC Service Controls perimeter encompassing all EU-based resources.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement an Organization Policy Constraint (Resource Location Restriction) to limit resource creation to EU regions.
An Organization Policy Constraint, specifically the 'Resource Location Restriction' (constraints/gcp.resourceLocations), is designed to enforce data residency by preventing the creation of new resources outside specified regions. This is the most effective and scalable way to enforce a project-wide data residency policy.
Why the other options are wrong
- A. Cloud DNS resolves domain names to IP addresses. While it influences routing, it doesn't enforce data residency for resource creation or guarantee that all internal service-to-service communication stays within a specific region if resources are allowed to be created elsewhere.
- B. Manually creating resources in an EU region is good practice, but it's not an enforcement mechanism. Users could still accidentally or intentionally create resources outside the EU.
- D. VPC Service Controls create security perimeters to prevent data exfiltration and protect against unauthorized access, but they do not primarily enforce *where* data is stored or *where* resources are created. They control *access* to and *movement* of data across boundaries.
Organization Policy Constraints (Resource Location)
Organization Policy Constraints are rules that apply across a Google Cloud organization, folders, or projects to enforce specific behaviors, such as restricting where resources can be created (Resource Location Restriction).
- Enforced at the organization, folder, or project level.
- Prevents creation of resources in non-compliant locations.
- Crucial for data residency and compliance (e.g., GDPR, HIPAA).
- Overrides individual user permissions for resource creation.
Memory trick: Organization Policy's Constraint, keeps your data's location without taint!