Question 12
Domain 1: Cloud Architecture, Governance, and Risk ManagementA company is considering using a cloud service where data may be stored in multiple countries. Which legal consideration is MOST important to address?
Correct answer: A
Explanation
Data stored in multiple countries can be subject to the laws of each location, so the company must address "data sovereignty" and which "applicable jurisdiction" can compel access or disclosure. This determines how legal requests, privacy rules, and government demands are handled across borders.
Why each option is right or wrong
A. Data sovereignty and applicable jurisdiction for legal requests
Cross-border cloud storage raises immediate conflict-of-laws issues because data can be subject to the privacy, disclosure, and government-access rules of every country where it is stored or replicated. Under frameworks such as the EU GDPR (Articles 44–49 on international transfers) and laws like the U.S. CLOUD Act, the company must know which jurisdiction can lawfully compel production and whether any transfer restrictions, localization rules, or lawful-access procedures apply before placing data in multiple countries.
B. The color scheme of the cloud provider's website
C. Employee dress code at the provider
D. Office furniture quality