Professional Cloud ArchitectDesign for security and complianceMedium

A multinational e-commerce company is expanding its operations into new regions. They need to ensure that customer data collected in a specific country (e.g., Germany) is stored and processed exclusively within that country's borders to comply with local data protection regulations. The company uses Cloud Storage for data lakes and BigQuery for analytics. How should they design their Google Cloud environment to guarantee this data residency requirement?

  1. AConfigure Cloud Storage buckets and BigQuery datasets with appropriate regional or multi-regional locations corresponding to the country's borders.
  2. BUtilize VPC Service Controls to create perimeters around resources in the desired regions, preventing data movement.
  3. CImplement Customer-Supplied Encryption Keys (CSEK) for all data, ensuring keys are managed within the country.
  4. DCreate separate Google Cloud projects for each country and use a single region within that country for all resources.
Show answer & explanation

Correct answer: A. Configure Cloud Storage buckets and BigQuery datasets with appropriate regional or multi-regional locations corresponding to the country's borders.

Google Cloud allows specifying the regional or multi-regional location for services like Cloud Storage buckets and BigQuery datasets. By configuring these resources to be created in regions or multi-regions that are geographically within the country's borders (e.g., europe-west3 for Germany), the company can ensure data residency for those specific services.

Why the other options are wrong

  • B. VPC Service Controls primarily prevents data exfiltration *across* perimeters, but it doesn't define the initial *location* where data is stored or processed within a perimeter, nor does it restrict resource creation to specific geographies.
  • C. CSEK provides customer control over encryption keys, but it does not dictate the physical location where the data itself or the processing occurs. A key managed within a country doesn't guarantee the data is too.
  • D. While creating separate projects is good practice for isolation, it doesn't automatically *enforce* that all resources *within* those projects are in the correct single region without explicit configuration of each resource's location.

Google Cloud Data Residency

Data residency refers to the physical location where data is stored and processed. Google Cloud allows users to specify regions and multi-regions to meet residency requirements.

  • Users choose specific regions/multi-regions for resource deployment.
  • Data at rest and in processing remains within the chosen location.
  • Different services offer different location options (e.g., regional, multi-regional, global).

Memory trick: For data residency, pick the right 'address' for your storage and processing.

More Design for security and compliance questions