Rss Link

The Legal I: Location, location, location

Posted by David Naylor | 25 Jun 2009

Cloud computing may be the latest buzzword in IT, but it pays to know where your data is drifting

Cloud computing may be the latest buzzword in IT, but it pays to know where your data is drifting

Cloud computing creates a new compliance headache for organisations. Cloud-based services are, by their very nature, highly distributed and accessible from multiple locations, often by multiple users and - sometimes - by multiple third-party service providers. The data of many customers may be located on the same servers, and may be hosted, cached or backed-up dynamically, on the basis of usage patterns.

As Google's chief privacy counsel, Peter Fleischer, recently put it, "It's very hard to answer the apparently simple question: 'Where's my data?'. You can't pin-point the location of clouds, but you can still talk to them."

Uncharted territory

Unfortunately, the world's legal systems are based on territorial boundaries and data protection laws still require businesses to know where their data is. There is no single data protection booklet for the global, cloud-based service provider or user.

For many CIOs, enterprise information security is difficult enough, but the new cloud-computing data protection compliance burden will be an extra challenge their employers may also expect them to manage.

Sam Johnston, a strategic consultant in cloud computing, warned in his blog on CircleID: "A well configured cloud computing architecture is a hacker's worst nightmare. Conversely, a poorly configured cloud computing architecture is a hacker's best dream."

Companies must bear in mind that most jurisdictions with data protection laws impose stringent obligations on them to ensure the security of information. This is a core requirement of the EU Data Protection Directive, which demands that personal data is kept secure from unauthorised or unlawful processing, accidental loss, destruction or damage. Failure to do so may lead to regulatory sanction, and civil and criminal liability.

Growing responsibilities

As a result, when a business provides access to its data to a cloud-based service provider, the law requires the business to ensure the provider offers adequate levels of security for the data, too. The data controller must ensure that appropriate security commitments are agreed, in a binding contract, with the service provider.

Show full article Hide full article

Print this page Bookmark and Share

No comments to this article.

Leave a comment All fields are mandatory

Latest news

Personal Details Exposed Via Biggest U.S. Websites

europe.wsj.com: Sat, 31 Jul 2010 22:07:50 +0000

The largest U.S. websites are installing new and intrusive consumer-tracking technologies on the computers of people visiting their sites—in some cases, more than 100 tracking tools at a time—a Wall Street Journal investigation has found.

...more

How to Avoid Prying Eyes

europe.wsj.com: Sat, 31 Jul 2010 21:51:38 +0000

The Internet is rife with surveillance technology, but you can protect your privacy by following these steps.

...more

The Web's New Gold Mine: Your Secrets

europe.wsj.com: Sat, 31 Jul 2010 21:20:51 +0000

A Wall Street Journal investigation finds that one of the fastest growing businesses on the Internet is the business of spying on American consumers. First in a series.

...more

Read all