A global e-commerce company is deploying a new customer portal on Google Cloud. The company must comply with GDPR and CCPA regulations, which require that customer data (personally identifiable information - PII) is not persistently stored outside specific geographic regions. The portal uses Cloud Storage for user-uploaded content and Cloud SQL for customer profiles. How should you design the data storage to ensure compliance with data residency requirements?
- AConfigure Cloud Storage buckets as Regional and Cloud SQL instances as Regional in the required compliance zones.
- BUse Multi-Regional Cloud Storage buckets and Cloud SQL instances, relying on Google's global network for data residency.
- CStore all PII in a single global Cloud Storage bucket and use Cloud DLP to redact sensitive information before storage.
- DImplement Customer-Managed Encryption Keys (CMEK) for all data, allowing data to be stored anywhere globally.
Show answer & explanationAnswer & explanation
Correct answer: A. Configure Cloud Storage buckets as Regional and Cloud SQL instances as Regional in the required compliance zones.
To meet strict data residency requirements like GDPR and CCPA, data must be stored within specific geographic boundaries. For Google Cloud, this means using Regional storage options for both Cloud Storage and Cloud SQL. Multi-Regional storage can replicate data across multiple regions, potentially violating residency. Cloud DLP redacts data but doesn't control its physical storage location. CMEK encrypts data but doesn't dictate where the encrypted data resides.
Why the other options are wrong
- B. Multi-Regional storage replicates data across multiple regions within a continent, which does not guarantee data will remain in a single, specific geographic region required by regulations like GDPR and CCPA.
- C. Storing PII in a global bucket violates residency requirements. Cloud DLP redacts data but doesn't control the physical location of the stored data.
- D. CMEK encrypts data but does not control the physical location where the encrypted data is stored. Data residency is about physical location, not just encryption.
Google Cloud Data Residency
The ability to control the geographic location where your data is stored at rest within Google Cloud, crucial for regulatory compliance.
- Achieved by selecting specific regions for services.
- Regional resources ensure data stays within a chosen region.
- Important for regulations like GDPR, CCPA, etc.
Memory trick: Store it Local, Keep it Legal, For Data's Regional Appeal.