CCSP Legal, Risk, and Compliance Practice Question
A cloud customer stores data in a SaaS application that replicates across multiple jurisdictions. The customer's legal team must respond to a subpoena for data stored in a specific region. Which concept determines the legal authority over the data?
⚠ Common exam trap
The trap here is equating data residency with data sovereignty; residency is about physical location, while sovereignty is about which laws apply.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data sovereignty
Data sovereignty is the legal principle that data is governed by the laws of the country where it resides. When data is replicated across regions, each copy may fall under different sovereign laws. A subpoena from one jurisdiction may not be enforceable in another, and the cloud provider may be caught between conflicting legal demands. Understanding sovereignty helps legal teams navigate cross-border data requests and design compliance strategies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data residency
Why it's wrong here
Data residency refers to the physical location where data is stored, often chosen for compliance or performance. While related, it does not by itself determine legal authority; sovereignty is the legal principle. The scenario emphasizes legal authority, so residency alone is insufficient to answer the question.
- ✗
Data localization
Why it's wrong here
Data localization is a requirement to keep data within a specific country's borders. It is a regulatory mandate, not the concept that determines legal authority over data in a cross-border subpoena. The scenario involves multiple jurisdictions, and localization laws may not apply uniformly, so this is not the primary determinant.
- ✓
Data sovereignty
Why this is correct
Data sovereignty refers to the principle that data is subject to the laws and regulations of the country in which it is stored. In this scenario, the replication across jurisdictions means the data may be subject to multiple legal authorities. The subpoena's enforceability depends on which jurisdiction has sovereignty over the data at the time of the request, making this the key concept.
- ✗
Data portability
Why it's wrong here
Data portability is the right to transfer data between service providers, often under GDPR. It concerns consumer rights and interoperability, not legal authority over data in a subpoena. Thus, it is irrelevant to determining which jurisdiction's laws apply to the data.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.