A global e-commerce company uses Azure Cosmos DB to store customer profiles and order history. To comply with GDPR and other data privacy regulations, the company needs to ensure that personally identifiable information (PII) within Cosmos DB documents is encrypted before it leaves the client application, and only authorized client applications can decrypt it. Which data encryption strategy should they implement?
- AAzure Disk Encryption on the Cosmos DB underlying storage
- BAzure Cosmos DB client-side encryption
- CAzure Cosmos DB server-side encryption with customer-managed keys
- DAzure SQL Always Encrypted for Cosmos DB
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Cosmos DB client-side encryption
Azure Cosmos DB client-side encryption allows the client application to encrypt sensitive data fields before they are sent to Cosmos DB. This ensures that the data is encrypted 'in transit' and 'at rest' from the perspective of the Cosmos DB service itself, and decryption keys remain with the client application, meeting the requirement for PII protection before it leaves the client.
Why the other options are wrong
- A. Azure Disk Encryption encrypts the underlying physical disks where Cosmos DB stores data, but it does not protect data from the Cosmos DB service itself or ensure client-side encryption.
- C. Server-side encryption with customer-managed keys encrypts data at rest within Cosmos DB, but the data is unencrypted when it reaches the Cosmos DB service from the client.
- D. Azure SQL Always Encrypted is a feature for Azure SQL Database, not directly applicable to Azure Cosmos DB.
Cosmos DB Client-Side Encryption
An encryption method where sensitive data fields within Cosmos DB documents are encrypted by the client application before being sent to the database, ensuring data is encrypted before it leaves the client and only authorized clients can decrypt it.
- Encryption occurs on the client application side.
- Keys are managed by the client application, not the database service.
- Protects data in transit and at rest from the database perspective.
- Ideal for strong PII protection and regulatory compliance (e.g., GDPR).
Memory trick: Client-side encryption: Your app locks before it sends.