Rss Link

The Legal I: Location, location, location

Posted by David Naylor | 25 Jun 2009

Cloud computing may be the latest buzzword in IT, but it pays to know where your data is drifting

Cloud computing may be the latest buzzword in IT, but it pays to know where your data is drifting

Cloud computing creates a new compliance headache for organisations. Cloud-based services are, by their very nature, highly distributed and accessible from multiple locations, often by multiple users and - sometimes - by multiple third-party service providers. The data of many customers may be located on the same servers, and may be hosted, cached or backed-up dynamically, on the basis of usage patterns.

As Google's chief privacy counsel, Peter Fleischer, recently put it, "It's very hard to answer the apparently simple question: 'Where's my data?'. You can't pin-point the location of clouds, but you can still talk to them."

Uncharted territory

Unfortunately, the world's legal systems are based on territorial boundaries and data protection laws still require businesses to know where their data is. There is no single data protection booklet for the global, cloud-based service provider or user.

For many CIOs, enterprise information security is difficult enough, but the new cloud-computing data protection compliance burden will be an extra challenge their employers may also expect them to manage.

Sam Johnston, a strategic consultant in cloud computing, warned in his blog on CircleID: "A well configured cloud computing architecture is a hacker's worst nightmare. Conversely, a poorly configured cloud computing architecture is a hacker's best dream."

Companies must bear in mind that most jurisdictions with data protection laws impose stringent obligations on them to ensure the security of information. This is a core requirement of the EU Data Protection Directive, which demands that personal data is kept secure from unauthorised or unlawful processing, accidental loss, destruction or damage. Failure to do so may lead to regulatory sanction, and civil and criminal liability.

Growing responsibilities

As a result, when a business provides access to its data to a cloud-based service provider, the law requires the business to ensure the provider offers adequate levels of security for the data, too. The data controller must ensure that appropriate security commitments are agreed, in a binding contract, with the service provider.

Show full article Hide full article

Print this page Bookmark and Share

No comments to this article.

Leave a comment All fields are mandatory

Latest news

Dow at Highest Since May 2008

europe.wsj.com: Sat, 04 Feb 2012 22:46:27 +0000

The blue-chip stock index rose 156.82 points to its highest level since May 2008, several months before the financial crisis, as better economic news encouraged investors to set aside their fears and focus on fundamentals. The Nasdaq hit its highest close since December 2000.

...more

Russia, China Veto U.N. Move on Syria

europe.wsj.com: Sat, 04 Feb 2012 22:30:00 +0000

Russia and China vetoed a U.N. call on Syria's Assad to step aside after reports of a government massacre in Homs prompted a push for a vote despite Moscow's objections.

...more

Why French Parents Are Superior

europe.wsj.com: Sat, 04 Feb 2012 21:28:03 +0000

While Americans fret over modern parenthood, the French are raising happy, well-behaved children without all the anxiety. Pamela Druckerman on the Gallic secrets for avoiding tantrums, teaching patience and saying"non"with authority.

...more

Read all