Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignHard
A global healthcare provider is designing a new cloud-based patient record system. The system must comply with diverse regional data privacy regulations (e.g., GDPR, HIPAA, local laws) that dictate where patient data can be stored and processed. The architect is particularly concerned about ensuring that patient data from specific regions never leaves those regions, even for backup or disaster recovery purposes. Which design principle is most critical to address this specific regulatory constraint?
- AData Locality
- BDecoupling
- CResource Tagging
- DMicroservices Architecture
Show answer & explanationAnswer & explanation
Correct answer: A. Data Locality
Data locality (or data residency) is the principle that dictates where data can be stored and processed, aligning directly with regulatory requirements that patient data from specific regions must not leave those regions. This is a critical design consideration for global compliance.
Why the other options are wrong
- B. Decoupling is an architectural principle for reducing dependencies, not directly for data location compliance.
- C. Resource tagging is for organizing and managing cloud resources, not a principle for enforcing data location.
- D. Microservices architecture is a way to structure applications, not a principle for enforcing data residency.
Data Locality (Data Residency)
The principle that data should be stored and processed within a specific geographic location or jurisdiction, often driven by legal or regulatory requirements.
- Crucial for compliance with data privacy laws (GDPR, HIPAA)
- Impacts cloud region selection and architecture
- Can affect disaster recovery and backup strategies
Memory trick: Data resides where the law decides.