EU privacy watchdog the European Data Protection Supervisor (EDPS) has started examining whether the bloc's top institutions and agenciesare effectively protecting citizens' personal data when using Amazon's AWS and Microsoft's Azure cloud services.
In a separate investigation, the EDPS will also probe whether the European Commission's use of Microsoft Office 365 is compliant with data protection laws.
The EDPS announced the launch of both inquiries in relation to the Schrems II ruling that occurred last summer and which introduced new obstacles to the transfer of personal data between the US where Amazon and Microsoft are based and the EU.
SEE: IT Data Center Green Energy Policy (TechRepublic Premium)
In the ruling, the EU Court of Justice concluded thatnational laws in the US did not match the stringent data protection requirements established by the bloc's General Data Protection Regulation (GDPR), meaning that without additional safeguards, the personal data of EU citizens cannot be safely processed across the Atlantic.
For example, under the Clarifying Lawful Overseas Use of Data Act (CLOUD), US authorities are allowed to require national storage providers to give them access to information held on their servers, even if that data is located overseas.
An EU-based organization using a US-based cloud provider like AWS or Azure, therefore, might find that some of their data including personal data about customers or employees, for example can potentially be made available for US authorities to snoop on.
This is why the EU's Court of Justice invalidated the scheme that was in place to enable personal data to flow freely between the bloc and the US, called the Privacy Shield, and ruled that instead, organizations will have to implement new privacy-protecting contracts, called Standard Contractual Clauses (SCCs) for each data transfer.
In some cases where even SCCs are insufficient, the data exchange can be suspended.
The EDPS, an independent organization that monitors the processing of personal data by EU institutions, has been closely watching the impact of Schrems II on some of the contracts that tie European offices and agencies to tech companies in the US.
"We identified certain types of contracts that require particular attention and this is why we have decided to launch these two investigations," said Wojciech Wiewirowski, the European Data Protection Supervisor.
"We acknowledge that EUIs (European Union Institutions) like other entities in the EU/EEA are dependent on a limited number of large providers. With these investigations, the EDPS aims to help EUIs to improve their data protection compliance when negotiating contracts with their service provider."
In particular, the privacy watchdog will be looking at so-called "Cloud II" contracts agreed between the EU and Microsoft or Amazon for the use of their cloud services.
SEE: Cloud computing: Microsoft sets out new data storage options for European customers
When EUIs use Azure and AWS, in effect, individuals' personal information can be sent outside of the EU and to the US, and unless appropriate GDPR-compliant measures are taken to protect the data transfer, there is a risk of surveillance from the authorities.
In other words, the EDPS will now be checking whether these GDPR-compliant measures are being taken by institutions in the bloc.
"We will actively support the EU institutions to answer questions raised by the European Data Protection Supervisor and are confident to address any concerns swiftly," a Microsoft spokesperson told ZDNet. "We remain committed to responding to guidance from regulators and will continuously seek to strengthen customer privacy protections." AWS did not respond to a request for comment.
The privacy threats posed by the reliance on foreign ICT providers' cloud services have long been flagged by the EDPS: as early as 2018, the privacy watchdogpublished guidelines for EU institutions that highlighted EUIs' responsibility in ensuring the protection of personal datain cloud infrastructure.
The message has not gone unheard. Recently, the European Data Protection Boardvalidated the use of a new "EU Cloud Code of Conduct", which acts as a standard certifying that a given cloud service provider is GDPR-compliant. Microsoft Azure and Google Cloud, among others, have already declared adherence to the code of conduct.
What's more: since the Schrems II ruling, cloud providers have come forward to announce changes to their policy to better comply with GDPR restrictions. BothMicrosoftandAmazonhave promised to contest government requests for access to customer data when they are able to. When required by law, Amazon also committed to disclose the minimum amount necessary of information, while Microsoft said that it would provide monetary compensation to the customers affected.
Microsoft has even gone one step further bypledging to enable EU customers to store and process most of their data within the EU by the end of 2022, meaning that personal data wouldn't even need to be sent to the US anymore.
Wiewirowski recognized that both companies have made amends, but nevertheless said that the announced measures might not be sufficient to ensure full compliance with EU data protection law, and still require a proper investigation.
"It's not just about law it's also about ethics. There are many social and economic issues that come with relying on only a handful of corporations for your critical infrastructure. If they don't comply to the rules, then your privacy will never be protected," Subhajit Basu, associate professor of information technology law at the University of Leeds, told ZDNet.
But there is also a political dimension to the new investigations, according to Basu. The EU is increasingly keen to re-assert the bloc's "digital sovereignty", especially when it comes to data infrastructure and cloud services.
The majority of the European cloud market, in effect, is controlled by non-European hyperscalers, with recent research showing that more than half of decision makers on the continentuse AWS, Microsoft Azure, IBM Cloud and Google Cloud.
SEE: GDPR: Fines increased by 40% last year, and they're about to get a lot bigger
In an attempt to re-gain control over the bloc's digital infrastructure, EU leaders are trying to develop a homegrown cloud initiative called GAIA-X, which will adhere to European principles of data protection and transparency but the project is stalling, and still remains far behind US-based cloud behemoths.
"This is about the future of cloud services, and making sure that the EU has its share in the pie of cloud business," says Basu. "The whole world is in the cloud nowadays, showing the importance of having a cloud infrastructure."
In addition to probing EUIs' use of US-based cloud services, the EDPS is also investigating the European Commission's use of Microsoft Office 365 another sticking point for the privacy watchdog, given that over 45,000 staff of EU institutions are users of the Redmond giant's products and services.
Last year, the EDPS published afirst set of recommendations related to the use of Microsoft's suite, including the imperative of knowing exactly where data is located, what information is transferred out of the EU and whether it is protected by proper safeguards.
For Basu, the move falls in line with both the primary objective of better protecting EU citizens' privacy, and the underlying goal of re-establishing the bloc's digital sovereignty and control over the personal data of its residents.
"What surprises me is it's taken the EDPS this long to launch an investigation," says Basu. "This is good for EU citizens, but it was needed and it should have been done before."
Read more here:
GDPR: EU privacy watchdog probing the use of AWS and Azure cloud services - ZDNet
- Open source cloud computing slow to catch on, survey finds [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle CFO: no acquisitions needed to compete in cloud [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- IDC Survey: U.S. Corporations Aim to Tackle IT Challenges with Cloud Computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Where does the ICO's new cloud guidance take you? [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- ChinaSoft International Signs Strategic Cooperation Agreement with Alibaba Cloud Computing to Develop PaaS Platform [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- IT Leaders Forum: Shedding light on cloud computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle Public Cloud Computing [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Oracle Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing 101 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Lenovo Gets Into Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing Certification Training | Cloud Computing Training By Simplilearn - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Succeeding or Failing with Cloud Computing - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Demystifying the Cloud - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- N: Cloud Computing, Syria PM Defects, US to Clean Agent Orange and MORE! - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Cloud Computing - Tv9 - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- AWS 101 Cloud Computing Seminar-Bangalore - Video [Last Updated On: October 5th, 2012] [Originally Added On: October 5th, 2012]
- Trust - The Key to Cloud Computing Growth in Europe [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Cloud Computing Saves Health Care Industry Time And Money [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Synnex CEO Kevin Murai: Tablets, Mobile, Cloud Computing (p3) - Video [Last Updated On: October 6th, 2012] [Originally Added On: October 6th, 2012]
- Enterprise computing IS the cloud [Last Updated On: October 8th, 2012] [Originally Added On: October 8th, 2012]
- 44 Percent Of US Execs To Tackle IT Challenges Through Cloud [Last Updated On: October 8th, 2012] [Originally Added On: October 8th, 2012]
- ZapThink Announces Expansion of Cloud Computing for Architects Course [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Euro Zone Eyes Cloud Computing to Kick Start Economy [Last Updated On: October 9th, 2012] [Originally Added On: October 9th, 2012]
- Advantages, challenges of cloud computing discussed Oct. 10 at NJIT [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- Dell Expands Cloud Client Computing Solutions for VMware View®, Desktop as a Service and Channel Offerings to Europe [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- Cloud West to Focus on Entertainment Delivery, Network Infrastructure, and Investment, More at Nov. 8-9th Forum [Last Updated On: October 10th, 2012] [Originally Added On: October 10th, 2012]
- IBM, AT&T Offer Secure Passage to the Cloud [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing company hits new fundraising heights [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing firm hits new fundraising heights [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Cloud computing: here we go again [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- Chinese Want to Put Computer 'Brains' in the Cloud [Last Updated On: October 11th, 2012] [Originally Added On: October 11th, 2012]
- CenturyLink Unveils Cloud Product [Last Updated On: October 12th, 2012] [Originally Added On: October 12th, 2012]
- Cloud Security Evolves in Wellington [Last Updated On: October 14th, 2012] [Originally Added On: October 14th, 2012]
- 2X ApplicationServer XG Joins the Intel AppUp SMB Service Hybrid Cloud [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- Piston Cloud to Exhibit and Present at the 2012 OpenStack Summit in San Diego [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- How to get your first cloud computing job [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- DreamHost Adds Public Cloud Computing Service: DreamCompute [Last Updated On: October 15th, 2012] [Originally Added On: October 15th, 2012]
- Aryaka Receives 2012 Cloud Computing Excellence Award [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Making a Europe fit for the cloud [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Cisco Execs Plumb The Limits Of Cloud Computing [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Cloud firm invests in new network [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- AirWatch Receives 2012 Cloud Computing Excellence Award [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Dell Extends Cloud Client Computing Portfolio with New Solutions Validated by Citrix [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Pano Logic and Alliance InfoSystems Join Forces to Deliver Zero Client Computing [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- 5 Cloud Business Benefits [Last Updated On: October 17th, 2012] [Originally Added On: October 17th, 2012]
- Alteva Receives 2012 Cloud Computing Excellence Award [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Open Text profit beats estimates on cloud services [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing improves nurse call system [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing: Top five tax considerations for your business [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- OKI and ISID to Provide Chemical Information System as Cloud Computing Services [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- As Mobile Grows, So Does Cloud Computing [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- IBM Analytical Decision Management SaaS - IBM Cloud TechTalk October 2012 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- JAX London 2012: Achieving genuine elastic multitenancy with Waratek Cloud VM for Java - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Microsoft 2020 technology future vision - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Infinity Cloud Point of Sale and Complete Retail Suite.mp4 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Small Business IT Support, Computer Support, Web Design Atlanta - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing - Simplified - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- How Allied Valve Used the Cloud to Expand in Bakken Oilfield - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing in the Public Sector - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing | Sacramento | Data Protection | IT Consulting | Symmetry Managed Servces - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- The Business Value of Cloud Computing - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- GYMNAZO Owner/Coach Michael Hughes is excited about edufii - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Automation in the age of cloud computing - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud Computing.mp4 - Video [Last Updated On: November 1st, 2012] [Originally Added On: November 1st, 2012]
- Cloud computing in 2013: a conversation with Appcore's CEO [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Cloud adoption growing in India: study [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Eastday-Microsoft picks city for cloud computing [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Towards a blue sky: How SMEs can avoid Cloud Computing confusion [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Consultancy Services - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Axxis Solutions Sponsors FIBA Technical Seminar on Cloud Computing - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- RightScale Webinar: 451 Research Webinar: Cloud Dos and Don'ts - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Apple Technology (Vishwa Bandhu Gupta) - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Mind Tree Ltd. - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- BIM Cloud Computing [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Entreda discusses cloud services for small and medium businesses - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Austin IT Company | Computer Networking [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- Cloud Computing and Services - After Effects Template - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- FieldStorm App Tour - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]
- The Hon Brendan O'Connor's speech: AccountRight Live launch event - Video [Last Updated On: November 3rd, 2012] [Originally Added On: November 3rd, 2012]