Skip to content

Data Residency

What is Data Residency?

Legal or regulatory requirements that personal data must be stored and processed within a specific geographic boundary or jurisdiction. Data residency laws exist in countries including Russia, China, India, and several EU member states.

Privacy

Each of these is named in at least one of the same controls as data residency. The number is how many controls name both.

What the standards actually require on data residency

Requirements naming data residency across 6 standards, quoted from the control text.

ISMAP (Japan)4 controls

ISMAP Data Protection establishes comprehensive data lifecycle controls. (1) Data Classification: customer government data must be classified per Japanese government data classification scheme + including (a) General + (b) Sensitive + (c) Confidential + (d) St...

ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS · ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYPTREC + KMS HSM

Data residency and sovereignty. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Data Protection in Cloud.

NIST190-13 · Data residency and sovereignty

Establish the scope of Singapore Multi-Tier Cloud Security Standard (MTCS) SS 584 - first issued 2013 (SS 584:2013 - world's first national cloud security standard) + revised 2015 + 2020 + current 2024 incorporating AI workload security + zero trust + data res...

MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification · MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification

Privacy (Puraibasii プライバシー) is the fourth of 10 Principles per Japan AI Guidelines for Business + intersects with APPI Act on Protection of Personal Information (2022 Amendment effective April 2023) + Copyright Act 2018 Amendment Article 30-4 (text and data mi...

JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection · Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle

Questions people ask about data residency

What is Data Residency?
Legal or regulatory requirements that personal data must be stored and processed within a specific geographic boundary or jurisdiction. Data residency laws exist in countries including Russia, China, India, and several EU member states.
Why is Data Residency important for compliance?
Data Residency is a key concept in Privacy. Understanding data residency helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data Residency?
Data Residency appears in the requirement text of ISMAP (Japan), IRS Publication 1075, NIST SP 800-190, MTCS (Singapore), Jamaica Data Protection Act 2020. Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data Residency?
Explore our compliance framework pages to see how data residency applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data Residency applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.