Certified Cloud Security Professional (CCSP)Cloud Data SecurityMedium

A multinational corporation is using a cloud-based email service. To comply with various global data residency and privacy regulations, they need to ensure that their email data is stored only in specific geographic regions and is not moved outside those regions without explicit authorization. Which aspect of cloud data security is primarily addressed by this requirement?

  1. AData jurisdiction
  2. BData locality
  3. CData sovereignty
  4. DData residency
Show answer & explanation

Correct answer: D. Data residency

Data residency specifically refers to the physical location where data is stored. The requirement to store email data only in specific geographic regions and prevent its movement outside those regions directly addresses data residency compliance.

Why the other options are wrong

  • A. Data jurisdiction refers to the legal authority over data, often linked to where data is processed or stored, similar to sovereignty but less direct for physical location.
  • B. Data locality is a technical concept referring to the proximity of data to compute resources to reduce latency, not primarily a regulatory one.
  • C. Data sovereignty refers to data being subject to the laws and governance of the nation where it is collected, which is a broader legal concept.

Data Residency

Data residency refers to the physical or geographical location where an organization's data is stored and processed. It is often a critical compliance requirement, mandating that certain types of data remain within specific borders to adhere to local laws and regulations.

  • Physical location of data storage and processing.
  • Driven by legal and regulatory compliance (e.g., GDPR, HIPAA).
  • Impacts cloud deployment models and provider selection.
  • Distinct from data sovereignty, which is about legal jurisdiction.

Memory trick: Residency: Data's Resting Place.

More Cloud Data Security questions