Professional Data EngineerManaging and securing dataHard

A healthcare analytics startup is using BigQuery to store de-identified patient data. To comply with regional data residency requirements, they must ensure that all data for European patients is stored only in data centers located within the European Union, while data for North American patients must be stored only in North American data centers. The startup needs an automated and enforceable mechanism to prevent users from accidentally or intentionally creating datasets in non-compliant regions. Which Google Cloud feature should they implement?

  1. AManually review BigQuery dataset creation logs
  2. BBigQuery dataset location settings
  3. CCloud IAM conditions on dataset creation
  4. DOrganization Policy Service with 'Resource location restriction' constraint
Show answer & explanation

Correct answer: D. Organization Policy Service with 'Resource location restriction' constraint

The Organization Policy Service, specifically with the 'Resource location restriction' constraint, allows administrators to define allowed locations for resources across an entire organization, folders, or projects. This provides an automated and enforceable mechanism to prevent resource creation in non-compliant regions.

Why the other options are wrong

  • A. Manual review is reactive, not proactive, and does not prevent non-compliant resource creation.
  • B. BigQuery dataset location settings are configured by the user creating the dataset, which doesn't prevent accidental or intentional misconfiguration by others.
  • C. While IAM conditions can restrict actions, the 'Resource location restriction' constraint in Organization Policy Service is specifically designed and more robust for enforcing geographical placement policies across an organization.

Organization Policy Service (Resource Location)

A Google Cloud service that allows administrators to enforce programmatic restrictions on how resources are configured and deployed across an organization, including restricting where resources can be created (resource location restriction).

  • Enforces policies at the organization, folder, or project level.
  • Uses constraints to define allowed or disallowed behaviors.
  • The 'Resource location restriction' constraint specifically controls data residency.
  • Provides centralized, automated governance.

Memory trick: Organization Policy sets the borders, Resource Location constraint draws the line, so data stays where it's meant to shine.

More Managing and securing data questions