Professional Data EngineerEnsuring solution qualityMedium
A multinational financial services company is migrating its on-premises data warehouses to BigQuery. They have strict data residency requirements, meaning certain sensitive financial data must remain within specific geographic regions (e.g., EU, US). They need to design their BigQuery environment to ensure data is stored and processed exclusively within the designated regions, preventing any accidental cross-region data movement. Which BigQuery dataset configuration is essential to enforce these data residency requirements?
- ACreating a separate project for each geographic region
- BApplying row-level security policies to restrict data access
- CEncrypting the dataset with Customer-Managed Encryption Keys (CMEK)
- DSetting the dataset's location to a specific region or multi-region
Show answer & explanationAnswer & explanation
Correct answer: D. Setting the dataset's location to a specific region or multi-region
Setting the dataset's location to a specific region (e.g., `europe-west1`) or multi-region (e.g., `EU`) in BigQuery is the primary and essential way to enforce data residency. Once set, all data stored in that dataset and all processing performed on it will occur exclusively within the chosen geographic boundary, directly addressing the requirement to prevent cross-region data movement.
Why the other options are wrong
- A. While creating separate projects can help organize resources, it doesn't inherently enforce data residency at the dataset level if locations are not explicitly set.
- B. Row-level security restricts who can see data, but does not control the physical location where the data is stored or processed.
- C. CMEK provides control over encryption keys but does not dictate the physical geographic location where the encrypted data resides.
BigQuery Dataset Location
A configuration setting for a BigQuery dataset that determines the geographic location where the dataset's data is stored and processed.
- Can be set to a specific region (e.g., `us-east1`) or a multi-region (e.g., `US`, `EU`).
- Enforces data residency requirements.
- Cannot be changed after the dataset is created.
Memory trick: Location Limits Logic.