Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| dido:99_annexes:annex-b-terms-and-definitions:d:data_residency [2026/07/11 11:14] – removed - external edit (Unknown date) 127.0.0.1 | dido:99_annexes:annex-b-terms-and-definitions:d:data_residency [2026/07/18 12:33] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== Data Residency ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Discussion ===== | ||
| + | |||
| + | Data residency addresses the location of data and metadata, the movement of data and metadata across geographies and jurisdictions, | ||
| + | |||
| + | OMG established a Data Residency Working Group in 2015 to explore issues and practices related to how laws and regulations affect data location and migration. OMG describes the working group' | ||
| + | |||
| + | OMG and the Cloud Standards Customer Council describe data residency challenges as arising when laws and regulations dictate where data transfers, storage, sharing, and protection occur across geographic boundaries. : | ||
| + | |||
| + | Data residency differs from data location alone. Data location identifies where data resides. Data residency encompasses the issues, practices, rules, risks, and controls associated with where data resides, where it moves, which jurisdiction governs that movement, and how systems protect data against location-related risks. | ||
| + | |||
| + | Data residency also differs from data sovereignty and data localisation. Data sovereignty focuses on the legal authority that applies to data based on jurisdiction. Data localisation focuses on actions that keep or place data within a specified jurisdiction. Data residency focuses on the location, movement, and protection practices that arise from geographic and jurisdictional constraints. | ||
| + | |||
| + | Data residency semantic content includes: | ||
| + | |||
| + | * Data location | ||
| + | * Metadata location | ||
| + | * Geographic location | ||
| + | * Jurisdiction | ||
| + | * Cross-border movement | ||
| + | * Data transfer | ||
| + | * Data storage | ||
| + | * Data processing | ||
| + | * Data access | ||
| + | * Location-related risk | ||
| + | * Regulatory constraint | ||
| + | * Policy constraint | ||
| + | * Protection requirement | ||
| + | * Monitoring requirement | ||
| + | * Governance responsibility | ||
| + | * Traceability to residency rules and policies | ||
| + | |||
| + | ===== Definition ===== | ||
| + | |||
| + | //issues and practices related to the location of data and metadata, the movement of data and metadata across geographies and jurisdictions, | ||
| + | |||
| + | ===== Source ===== | ||
| + | |||
| + | OMG Data Residency Working Group and OMG/Cloud Standards Customer Council Data Residency Challenges material, specialized for use in the FX Demo Reference Architecture. | ||
| + | |||
| + | ===== Note ===== | ||
| + | |||
| + | Data residency does not apply only to data at rest. OMG's definition includes location, movement, geographies, | ||
| + | |||
| + | ===== Example ===== | ||
| + | |||
| + | An FX reporting node processes trade data for a trade subject to an EU reporting jurisdiction. A data residency rule requires raw counterparty data and validation evidence to remain within an approved EU processing environment. The architecture routes only report evidence to non-EU nodes and records the policy decision, location, jurisdiction, | ||
| + | |||
| + | In this example, data residency concerns more than the physical storage location. It also governs movement, processing, access, metadata, routing, and protection against location-related risks. | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||