A multinational firm plans a single global data lake for cost efficiency. Regional teams process citizen data under differing privacy regimes, and design approval is due next week. What should the security architect do FIRST?
A. Validate jurisdictional data sovereignty requirements before design approval
B. Segment the lake to enforce regional residency boundaries
C. Apply tokenization to sensitive fields before global replication
D. Escalate the cost-versus-compliance conflict to the risk committee
(Explain your answer for more points in the comments!)