[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-18。"],[],[],null,["# About data residency and regional secrets\n\nThis page provides an overview of data residency and achieving compliance with\ndata residency regulations using regional secrets.\n\nOverview of data residency\n--------------------------\n\n[Data residency](/architecture/framework/security/meet-regulatory-compliance-and-privacy-needs#control_data_residency)\nis the concept of keeping data within specific geographical boundaries due to legal, regulatory,\nor organizational requirements. Data residency isn't just a preference for some\nbusinesses; it's a legal and operational necessity. Data residency is essential to\ncomply with regulations like [GDPR](/privacy/gdpr),\n[HIPAA](/security/compliance/hipaa-compliance), or [PIPEDA](/security/compliance/pipeda-canada),\nand to mitigate the risk of fines or legal action.\n\nTo learn more about data residency in Google Cloud, see the following\nIdentity and Security blog post:\n[Understanding your options for data residency, operational transparency, and privacy controls on\nGoogle Cloud](https://cloud.google.com/blog/products/identity-security/meet-data-residency-requirements-with-google-cloud/).\n\nEnforce data residency using regional secrets\n---------------------------------------------\n\nIn Secret Manager, you can enforce data residency by choosing the\n[regional service](/secret-manager/regional-secrets/global-regionalized-service-comparison)\nand creating regional secrets that ensure that your sensitive data is stored and\nprocessed within a specific location. With regional secrets, your secret data remains\nwithin the chosen location at all times, whether it's at rest, in use, or in transit.\n\nRegional secrets work in the following manner:\n\n- When you create a regional secret, you specify the location where you want it to be stored. The Secret Manager service ensures that the secret data stays within that location's infrastructure.\n- Regional secrets can only be accessed by applications or services running within the same location. This adds an extra layer of security by limiting access to authorized entities within the designated region.\n- Unlike [global secrets](/secret-manager/docs/create-secret-quickstart), which are often replicated across multiple locations for high availability, regional secrets are not automatically replicated. This ensures strict data residency.\n\nWhat's next\n-----------\n\n- [Enable the Secret Manager API](/secret-manager/regional-secrets/config-sm-rs)\n- [Create a regional secret](/secret-manager/regional-secrets/create-regional-secret)\n- [Add a regional secret version](/secret-manager/regional-secrets/add-secret-version-rs)"]]