Data residency is not automatic security
Keeping data in a particular country says something about jurisdiction and very little about protection.
Badly secured data in the right region is still badly secured. Residency requirements are frequently satisfied to the letter while the actual controls, who can access it and from where, remain unchanged. It is a legal and contractual property that is often sold and bought as if it were a security one.
More on Data security
- Classification should change handlingThe label throws the points
- Tokenisation changes what systems need to holdHand over the ticket, not the coat
- Data lineage explains where sensitive data travelsFollow the dye
- Retention is a security controlWhat you no longer hold
- Data access logs need object contextRead a record. Which one?
- DLP can match data patterns but cannot reliably infer the business purpose of a transferIt reads the shape, not the reason
