Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceMedium
A cloud service provider (CSP) is offering a new 'data analytics as a service' (DAaaS) solution. As part of their due diligence, the legal team is reviewing the terms of service to ensure compliance with global data privacy regulations. Which of the following is the MOST critical legal requirement for the CSP to address regarding data residency and cross-border data transfers?
- AImplementing advanced encryption at rest and in transit for all customer data.
- BEnsuring the service level agreement (SLA) guarantees 99.999% uptime for data processing.
- CProviding comprehensive audit logs to customers for all data access and modification events.
- DClearly defining data processing locations and mechanisms for obtaining user consent for international transfers.
Show answer & explanationAnswer & explanation
Correct answer: D. Clearly defining data processing locations and mechanisms for obtaining user consent for international transfers.
Data residency and cross-border data transfers are highly scrutinized under global data privacy regulations like GDPR. Clearly defining where data is processed and obtaining explicit consent or demonstrating legal grounds for international transfers are paramount to legal compliance.
Why the other options are wrong
- A. Encryption is a critical security measure, but it doesn't, by itself, fulfill legal requirements for data residency or consent for transfers.
- B. While important for service reliability, SLA uptime is not a primary legal requirement for data residency or cross-border transfers.
- C. Audit logs are important for accountability and compliance, but they do not directly address the legal obligations related to where data is stored or how it's transferred across borders.
Data Residency
Data residency refers to the physical or geographic location where an organization stores its data. It is a critical aspect of legal and regulatory compliance, especially with international data protection laws.
- Dictated by legal and regulatory frameworks (e.g., GDPR, CCPA).
- Impacts where data can be stored and processed.
- Often requires explicit consent for cross-border transfers.
Memory trick: Cloud data travels, but its home matters legally.