Data Residency
What is Data Residency?
Legal or regulatory requirements that personal data must be stored and processed within a specific geographic boundary or jurisdiction. Data residency laws exist in countries including Russia, China, India, and several EU member states.
Terms that appear alongside data residency
Each of these is named in at least one of the same controls as data residency. The number is how many controls name both.
- gdpr 10 shared controls
- data protection 10 shared controls
- audit 10 shared controls
- nist 10 shared controls
- consent 9 shared controls
- compliance 8 shared controls
- encryption 7 shared controls
- iso 27001 7 shared controls
Frameworks that govern data residency
What the standards actually require on data residency
Requirements naming data residency across 6 standards, quoted from the control text.
ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) St...
ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS · ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM →Section 9.4 of IRS Publication 1075 establishes specific requirements for cloud services and addresses the prohibition on offshore processing of FTI.
IRSPub1075-Section94-Cloud-FedRAMP-Offshore-Prohibition-CSP-USRegion-PrivateGovCloud-AzureGov-AWSGov · IRS Pub 1075 Section 9.4 + Cloud Services + FedRAMP Authorisation Required + Offshore Prohibition + AWS GovCloud + Azure Government + Oracle US Federal + Google Workspace Federal + US-Region Data Residency →Data residency and sovereignty. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Data Protection in Cloud.
NIST190-13 · Data residency and sovereignty →Establish the scope of Singapore Multi-Tier Cloud Security Standard (MTCS) SS 584 - first issued 2013 (SS 584:2013 - world's first national cloud security standard) + revised 2015 + 2020 + current 2024 incorporating AI workload security + zero trust + data res...
MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification · MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification →Standard 8 per Section 27 + the Schedule of the Jamaica Data Protection Act 2020: Personal data shall not be transferred outside Jamaica unless adequate protection is provided.
JM-DPA2020-Standard8-Transfers-Outside-Jamaica-Sec27-Adequacy-Decisions-Standard-Contractual-Clauses-BCR-Derogations · Jamaica DPA 2020 Standard 8 - Transfers Outside Jamaica + Section 27 + Adequacy Decisions + Standard Contractual Clauses + Binding Corporate Rules + Derogations + Cross-Border Data Flows + Caribbean Community + International Data Privacy →Privacy (Puraibasii プライバシー) is the fourth of 10 Principles per Japan AI Guidelines for Business + intersects with APPI Act on Protection of Personal Information (2022 Amendment effective April 2023) + Copyright Act 2018 Amendment Article 30-4 (text and data mi...
JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection · Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle →Questions people ask about data residency
What is Data Residency?
Why is Data Residency important for compliance?
Which compliance frameworks address Data Residency?
Where can I learn more about Data Residency?
See how Data Residency applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.