Google Cloud Data Boundary is the sovereignty option that works inside the public cloud. It targets organizations that need data residency and control over administrative access without moving to dedicated or separately operated infrastructure.
What is Google Cloud Data Boundary?
On the Sovereign Cloud overview page, Google describes Data Boundary as a way to customize your data residency and access controls within the public cloud environment. Core customer data is stored in your chosen region and cannot move.
The second building block concerns administrative access: it is logged, audited, and controlled by conditions you predefine. You can also specify which personnel may access the respective region.
The third building block is key management. Customers manage and control their encryption keys themselves, including external storage of those keys. Optionally, a partner can provide supervision for key management and audits, tailoring security to specific needs.
Data Boundary is therefore the least invasive of the options within Sovereign Cloud from Google: you stay in the public cloud and add residency, access, and key controls to it. Google addresses further-reaching requirements through Google Cloud Dedicated and Google Distributed Cloud.
No separate price model is published on the overview page; clarify terms and regional details with Google Cloud.
Core Features
- Data residency: Core customer data is stored in your chosen region and cannot move.
- Controlled administrative access: Access is logged, audited, and tied to predefined conditions.
- Your own key management: You manage and control encryption keys, including external storage.
- Personnel-level access control: Specify which personnel may access your region.
- Optional partner supervision: A partner can supervise key management and audits.
Typical Use Cases
Data residency for regulated data
An organization must demonstrate that core data does not leave a defined region and uses the residency controls of Data Boundary for that.
Evidence of administrative access
For audits, the organization evidences that administrative access is logged and only possible under predefined conditions.
External key storage
An organization stores encryption keys outside Google’s infrastructure and retains control over decryption.
Supervision by a partner
For additional independence, a partner supervises key management and audits.
Entry point into a sovereignty program
An organization starts with controls inside the public cloud and evaluates further-reaching options later.
Benefits
- Sovereignty without a platform change: Controls apply within the familiar public cloud environment.
- Traceable access: Logging and auditing of administrative access.
- Key control: Your own key management including external storage.
- Adjustable depth: Optional partner supervision for additional independence.
- Part of a graduated offering: Further options are available as requirements grow.
Integration with innFactory
As a certified Google Cloud Partner, innFactory supports you with Google Cloud Data Boundary: deriving your residency and access requirements, designing key management, preparing evidence for audits, and distinguishing it from further-reaching sovereignty options. We describe the additional questions that apply to professionals bound by confidentiality obligations in our article on professional secrecy under section 203 of the German Criminal Code in the public cloud.
Contact us for a consultation on Google Cloud Data Boundary.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Google Cloud Data Boundary?
Google Cloud Data Boundary is one of the options within Sovereign Cloud from Google. According to the official overview page, it lets you customize your data residency and access controls within the public cloud environment: core customer data is stored in your chosen region and cannot move.
How is administrative access controlled?
Google describes that administrative access is logged, audited, and controlled by your predefined conditions. You can also specify which personnel may access your region.
Who manages the encryption keys?
According to the overview page, you manage and control your encryption keys, including external storage of those keys.
Can a partner be involved?
Yes. Google describes that an optional partner can provide supervision for key management and audits, tailoring security to your specific needs.
How does Data Boundary differ from Google Cloud Dedicated?
Data Boundary operates within the public cloud environment and works through residency, access, and key controls. Google Cloud Dedicated instead relies on dedicated, isolated infrastructure with independent operations delivered by a local partner. Both are options within Sovereign Cloud from Google.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
