ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium
A managed security service provider (MSSP) is onboarding a new client, a small startup. The client explicitly states that they do not want any user data to be stored outside of their primary cloud region in the European Union, even for backup or disaster recovery purposes, due to strict data residency laws they must adhere to. The MSSP proposes a backup solution that replicates data to a geographically distant data center within the same EU region. What is the primary legal principle guiding the client's requirement?
- AData minimization
- BData residency
- CRight to be forgotten
- DPurpose limitation
Show answer & explanationAnswer & explanation
Correct answer: B. Data residency
Data residency, also known as data sovereignty, is the legal and regulatory requirement that data be stored in a specific geographic location. The client's explicit demand that 'no user data be stored outside of their primary cloud region in the European Union' directly addresses this principle.
Why the other options are wrong
- A. Data minimization focuses on collecting and processing only necessary data, not its physical storage location.
- C. Right to be forgotten allows individuals to request deletion of their personal data, not location of storage.
- D. Purpose limitation means data should only be collected for specified, explicit, and legitimate purposes.
Data Residency
The legal and regulatory requirement that certain data must be stored within the borders of a specific country or jurisdiction.
- Also known as data sovereignty.
- Driven by national laws and regulations (e.g., GDPR, local privacy laws).
- Impacts cloud computing, backup strategies, and global data transfers.
Memory trick: Privacy protects, residency restricts, purpose limits.