Azure GDPR Data Residency: EU Regions and Contractual Commitments
An organization needs to meet GDPR data residency requirements ensuring personal data of EU residents is stored only within the EU. How does Azure support this?
Quick Answer
The answer is that Azure supports GDPR data residency through dedicated EU data center regions and binding contractual commitments in the Microsoft Online Services Terms. This works because Azure physically operates regions like West Europe, North Europe, and France Central, where customer data is stored and processed exclusively within EU boundaries, and the contractual terms legally guarantee that data will not be transferred outside the chosen region. On the AZ-900 exam, this concept tests your understanding that Azure’s compliance is a shared responsibility—Microsoft provides the infrastructure and legal framework, but customers must actively select EU regions during deployment and can use Azure Policy to enforce restrictions. A common trap is assuming Azure automatically enforces data residency; in reality, it requires explicit customer action. Memory tip: think “EU region + contract = residency protection,” where the region is the physical lock and the contract is the legal key.
⚠ Common exam trap
It's easy for candidates to assume Azure automatically handles GDPR data residency without customer action, but the exam tests that customers must actively select EU regions and configure policies to enforce residency, and that Azure's US corporate status does not prevent GDPR compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure provides EU regions and contractual commitments enabling customers to keep EU data within EU boundaries
Azure supports GDPR data residency by offering data center regions within the EU (e.g., West Europe, North Europe, France Central) and including contractual commitments in the Microsoft Online Services Terms that guarantee customer data remains stored in the chosen EU region. Customers must explicitly select these regions during resource deployment and can use Azure Policy to enforce region restrictions, but the core support comes from Azure's physical infrastructure and legal agreements, not automatic enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure automatically stores all EU customer data in EU regions without configuration
Why it's wrong here
Customers must choose EU regions when deploying resources; Azure doesn't automatically route data to regional locations.
- ✓
Azure provides EU regions and contractual commitments enabling customers to keep EU data within EU boundaries
Why this is correct
Azure offers EU-specific regions and DPA (Data Processing Agreement) commitments to support GDPR data residency requirements.
- ✗
Azure cannot support GDPR data residency as it's a US company
Why it's wrong here
Azure has extensive compliance certifications including GDPR compliance and EU-specific regions and contractual commitments.
- ✗
Data residency is automatically enforced by Azure Policy without customer configuration
Why it's wrong here
Customers must configure 'Allowed locations' Azure Policy; Azure doesn't enforce residency automatically.
Go deeper
Related to this question
Learn chapter
Service Level Agreements (SLAs) in Azure
Key term
Data residency
Data residency is the physical or geographical location where an organization's data is stored and processed, often subject to local laws.
Key term
Azure Policy
Azure Policy is a service in Microsoft Azure that lets you create, assign, and manage rules to ensure your resources stay compliant with your company standards and service-level agreements.
About these practice questions
One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A hospital is subject to strict data residency laws that require patient data to remain within the country's borders. They are considering using a public cloud provider. Which cloud deployment model would best meet this compliance requirement?
medium- A.Public cloud
- ✓ B.Private cloud
- C.Hybrid cloud
- D.Community cloud
Why B: A private cloud is dedicated to a single organization, allowing the hospital to deploy and manage infrastructure within its own data center or a colocation facility located within the country's borders. This ensures full control over data storage and processing, directly satisfying data residency laws that prohibit patient data from leaving the country. In contrast, public cloud providers may have data centers in multiple regions, making it harder to guarantee data never crosses borders.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.