Professional Cloud ArchitectDesign for security and complianceHard

A global enterprise needs to ensure that all their Google Cloud resources adhere to specific data residency requirements, mandating that customer data for European users must physically reside and be processed only within the EU. They also need to restrict where new resources can be deployed to enforce these geographical constraints. Which Google Cloud service and configuration should they utilize to meet these compliance mandates?

  1. AVPC Service Controls configured with a perimeter in the EU region.
  2. BCustomer-managed encryption keys (CMEK) with keys stored in an EU-based Cloud KMS key ring.
  3. CCloud Storage bucket location set to 'EU' and BigQuery dataset location set to 'europe-west1'.
  4. DOrganization Policy Service with a 'Resource Location Restriction' constraint.
Show answer & explanation

Correct answer: D. Organization Policy Service with a 'Resource Location Restriction' constraint.

The Organization Policy Service, specifically with the 'Resource Location Restriction' constraint, allows an administrator to define which geographic locations (regions/multi-regions) users can create new resources in. This provides a strong, organization-wide enforcement mechanism for data residency requirements by preventing the creation of resources outside the specified EU locations.

Why the other options are wrong

  • A. VPC Service Controls helps prevent data exfiltration, but it doesn't *restrict where new resources can be deployed* to enforce data residency at the creation stage.
  • B. CMEK helps manage encryption keys and their location, but it doesn't *restrict where the data itself or other resources are deployed* to enforce overall data residency.
  • C. Setting individual resource locations (like for Cloud Storage and BigQuery) is necessary, but it's a manual process per resource. Organization Policy Service provides the *enforcement* to ensure *all* relevant resources are created in the correct locations, preventing errors or non-compliance.

Resource Location Restriction (Organization Policy)

An Organization Policy constraint that restricts the geographic locations (regions, multi-regions) where Google Cloud resources can be created.

  • Enforces data residency requirements at an organizational level.
  • Prevents creation of resources outside allowed locations.
  • Applies to various resource types (Compute Engine, Storage, BigQuery, etc.).

Memory trick: Organization Policy is the 'border patrol' for where your cloud resources can live.

More Design for security and compliance questions