Skip to content
AWP v1alpha1 (draft)
Draft - v1alpha1. Fields and semantics may change before v1beta1.

EU data residency

eu-data-residency.policy.yaml
# Example: a reusable policy that keeps personal data inside the EU.
apiVersion: awp.agenticworkflowprotocol.org/v1alpha1
kind: Policy
metadata:
name: eu-data-residency
version: 1.0.0
owner:
team: data-protection
spec:
rules:
- id: personal-data-stays-in-eu
when:
data.classification:
in:
- personal
- sensitive
destination.region:
notIn:
- EU
effect: deny
message: Personal and sensitive data must not leave the EU.

The rule matches operations whose data class is personal or sensitive and whose destination region is not EU, and denies them. If the region cannot be determined the operation is denied as well (fail closed). Region identifiers are organizational strings.

See Policy-as-Code.

AWP provides machine-readable governance primitives that can help organizations implement and enforce their own compliance requirements. Compliance depends on the implementation, organizational controls and applicable regulatory requirements.