Data residency
The physical or geographic location where data is stored and processed, usually chosen by the organisation for legal, contractual, performance or customer reasons.
Data residency refers to where data physically sits: the country, region or specific data centres that hold it. In cloud services it is typically set by choosing a provider region, and organisations often promise customers that their records will stay in a given region. Residency has to cover more than the primary copy: backups, replicas, disaster recovery sites, logs, caches, and support staff with remote access can all place data, or access to it, somewhere other than the region named in the contract.
Residency is the location. Data sovereignty is the legal consequence: data is subject to the laws of the jurisdictions where it resides. Data localisation is a legal requirement that certain data stay inside a country, which turns residency from a choice into an obligation. GDPR shows the difference: it does not itself require data to stay in the EU, but Chapter V restricts transfers of personal data outside the European Economic Area unless the destination has an adequacy decision, appropriate safeguards are in place, or a specific derogation applies. Residency terms are usually written into the cloud contract or the data processing agreement.
Exam relevance: a scenario is likely to describe a multinational choosing cloud regions or a customer demanding in-country storage. Candidates are expected to separate location (residency) from legal jurisdiction (sovereignty).