SlideShare una empresa de Scribd logo
1 de 24
Cloud
Is it legal or illegal to use American
cloud services in Europe?
PATRICIA AYODEJI
Dual qualified Lawyer, England & Spain
Member of The Law Society, London &
Ilustre Colegio de la Abogacía, Barcelona
Founding Lawyer E-PDP
payodeji@icab.cat
24th February 2016
www.e-pdp.es
Dropbox, Google Drive, Gmail.., Microsoft
Office 365.., Mailchimp & many others….
2016 E-PDP PROTECCIÓN DE DATOS PERSONALES
CLOUD DOES NOT…
Remove our responsibility for data protection,
data security, data integrity, data confidentiality
and business continuity .
We cannot entrust or delegate these to the
cloud provider. Contractual clause invalid!
Before & After
Mass-surveillance on
foreigners abroad
What you should know......
Not on a par......
Data is governed by a patchwork of state and federal laws, with new reforms added all the
time. Europe has a more harmonised regime – and there are big changes planned!
Privacy Act 1974
Guarantees three primary rights which federal agencies must abide by:
•The right to see records about oneself, subject to Privacy Act exemptions;
•The right to request the amendment of records that are not accurate, relevant, timely or
complete; and
•The right of individuals to be protected against unwarranted invasion of their privacy
resulting from the collection, maintenance, use, and disclosure of personal information.
Only applies to U.S CITIZENS OR non-U.S citizens who are permanent residents.
Judicial Redress Act 2015
Gives citizens from approved EU countries (“U.S.-allied countries”) the right to sue federal
agencies that mishandle their personal data in a similar way to rights Americans enjoy under
the Privacy Act. Americans already enjoy similar rights in Europe. The right to redress is
subject to the same restrictions U.S. citizens face under the Privacy Act, including broad
exemptions for national security.
Privacy
Security
Confidentiality
Data integrity
Business continuity
The European Approach
2016 E-PDP PROTECCIÓN DE DATOS PERSONALES
Charter of Fundamental Rights of the
European Union
Title II Freedoms
Article 8 Protection of Personal Data
1. Everyone has the right to the protection of personal data concerning
him or her.
2. Such data must be processed fairly and on the basis of the consent of the
person concerned or some other legitimate reason laid down by the law.
Everyone has the right of access to data which has been collected
concerning him or her, and the right to have it rectified.
3. Compliance with these rules shall be subject to control by an
independent authority.
Data Protection
Directive 95/46/EC -> L.OPD 15/1999
PROTECTS PERSONAL DATA OF EU CITIZENS AS USERS OF CLOUD
& WHEN IN CUSTODY OF A CLIENT OF CLOUD SERVICES.
In process of reform! New EU Data Protection Regulation.
Expected to be formally agreed shortly and in place in 2018. ONE
SINGLE LAW, which will enter into force after a transition period
of 2 years). Higher fines–up to 4% of turnover when companies
have violated the privacy of a European.
Extended territory includes all non-EU companies with
no establishment in EU who offer goods/services
(including free of charge) to EU citizens.
Ireland will cease to be a soft option for U.S
companies.
Some Data Protection questions
• Do they share data with third party subcontractors? Do you know who
they are & what services are outsourced? where their servers are
located?
WhatsApp, Gmail… involve the processing of data via undetermined
servers and companies throughout the world.
• Are you sure data not used for other purposes?
• In case of breach do they have the appropriate insurance?
If our cloud provider does not provide us with certain guarantees all
responsibility for the data lies with us!
JURISPRUDENCE & CLOUD
SOURCED DATA
2015 'annus horribilis' for Google,
Facebook, Apple Yahoo etc.
2016 E-PDP PROTECCIÓN DE DATOS PERSONALES
US Safe Harbour Scheme
Turning point in international transfers to
the US....The strike down of Safe Harbour!
6 October 2015, EU Court of Justice– Schrems vs. Facebook Judgment
C-362/14 (Facebook- mass-surveillance programs by NSA. Snowden’s NSA leaks
demonstrated that European data stored by US companies was not safe from the type of surveillance
which would be considered illegal in Europe) proclaims that the 15 year old Safe Harbour, the
legal framework that American companies have used to handle European citizens’ data does
not provide an adequate level of protection and does not provide guarantees equivalent to
those established in the European Union.
Judgment invalidated the legal basis for US-EU Safe Harbour.
If your company relying on Safe Harbour it is in an illegal situation and may face
enforcement proceedings depending on the DPAs in question!!
AGPD : Spanish Data Protection Authority’s response to
EU Court of Justice Schrems Judgment, Madrid, 29th October
2015
In exercise of its powers the AEPD, Spanish Data Protection Authority required that at the
earliest, and in any case before 29 January 2016, that all transfers of data from Spain to
the U.S be notified or modified in the General Data Protection Registry and, if necessary,
include details of their compliance with data protection legislation.
Failing to do so within this period, the Authority may initiate proceedings, if necessary,
to temporarily suspend such international transfers.
https://www.agpd.es/portalwebAGPD/canalresponsable/transferencias_internacionales/common/Comunicacion_r
esponsables_-_Puerto_Seguro.pdf
The US Government’s response to Schrems
U.S. Secretary of Commerce Penny Pritzker
“…..We are deeply disappointed in today’s decision from the
European Court of Justice, which creates significant uncertainty for
both U.S. and EU companies and consumers, and puts at risk the
thriving transatlantic digital economy. Among other things, the
decision does not credit the benefits to privacy and growth that
have been afforded by this Framework over the last 15 years….”
How do we use American cloud services in Europe without
running afoul of EU data protection law! Alternative
compliant data transfer mechanisms .....
Data localisation- actual whereabouts of data
Choose Spanish/EU provider e.g. migrate from Georgia based Mailchimp (Privacy
policy disclose personal information to comply with court orders and subpoenas) to
Madrid based Mailrelay (data centres in EU). Basic, but effective means to influence
jurisdiction. Option for large organisations.
EU model contractual clauses
For transfers to countries or territories that do not ensure an adequate level of
protection (which now includes the USA). In Spanish & English!
Binding Corporate Rules ( BCRs )
A set of legally enforceable internal rules ( such as a Code of Conduct ) regarding
data privacy and security, to ensure that transfers of personal data outside of the EU
take place in accordance with EU rules. A valid solution. Greater flexibility
THESE OPTIONS REMAIN FORMALLY EFFECTIVE & LEGAL
#FLISH FLASH Successor to Safe Harbour:
EU-US Privacy Shield
2nd February 2016
http://ec.europa.eu/avservices/video/player.cfm?ref=I115848&sitelang=en
EU Commission & US Dept. of Commerce
•New living framework for transatlantic data flows with continuous process of monitoring
by EU Commission & annual review which will look at all aspects of the agreement.
•Multiple channels for EU citizens to report any “misuse” of their personal data.
Companies will have deadlines in which to respond to complaints.
•EU citizens will benefit from legal redress for privacy violations .
•Severe restrictions on indiscriminate mass surveillance of European citizens by U.S
EU-US Privacy Shield
The situation has not
changed since Schrems
WP29, ( body of representatives of individual European Member States’ DPAs ) EU-
US data transfers won’t be blocked while Privacy Shield details are hammered out!
Is the arrangement robust enough? Not in fact certain that will pass scrutiny of the
WP29 (quality, content, legal consequences) or the ECJ (the ultimate authority on
enforceability of the new pact).
Plenty of questions remain & a deal is not really done yet!
Uncertainty likely to prevail for some time!
Security
Employees remain the weakest link within an organisation!
What security measures does it have in place and does it offer levels
of security equivalent to local access?
Preventative measures for viruses, hackers, spies?
Do they keep security copies?
ISO certification?
ISO/IEC 27018 (Aug. 2014 ) code of practice to ensure cloud service providers
offer suitable information security controls to protect PII processed in public cloud
ISO/IEC 27017 Cloud specific information security controls & advice for cloud
service customers and providers. Published end of 2015. Agreement with
information security roles & responsibilities of both parties.
http://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/
Data security breaches continue to climb
World's Biggest Data Breaches
Selected losses greater than 30,000 records
(updated 2nd October 2015)
www.informationisbeautiful.net
Confidentiality
Encryption?
Who holds the Access keys? How are they protected?
Usernames. Passwords. Password recovery.
Data integrity
• Measures taken by the provider to mitigate risks
of data being involuntarily compromised?
• Who can access data? What can they do with it?
• What happens when you want to change cloud
provider? Will critical data be inaccessible? For
how long ?
2016 E-PDP PROTECCIÓN DE DATOS PERSONALES
Continuity: Portability & Interoperability
Ability to retrieve and shift data & services between
different cloud systems.
Portability a new right under the new Regulation
designed especially for cloud services. i.e. ability to get
structured, legible information in a format compatible
with other systems!
Go for it but remember……
PATRICIA AYODEJI
IP/IT/Privacy
payodeji@icab.cat
www.e-pdp.es
Thank you!
Don’t panic.....
We protect your company data, digital products
and services in different legal jurisdictions.
• Information Security and Data Protection
• Copyright and Trade marks
• e-Legal proceedings
• International legal services

Más contenido relacionado

La actualidad más candente

US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataMark Aldrich
 
Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy Raymond Cunningham
 
[Privacy Webinar Slides] Global Enforcement Priorities
[Privacy Webinar Slides] Global Enforcement Priorities[Privacy Webinar Slides] Global Enforcement Priorities
[Privacy Webinar Slides] Global Enforcement PrioritiesTrustArc
 
Cours CyberSécurité - Privacy
Cours CyberSécurité - PrivacyCours CyberSécurité - Privacy
Cours CyberSécurité - PrivacyFranck Franchin
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
Privacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU DataPrivacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU DataSchellman & Company
 
International privacy with kevin haley
International privacy with kevin haleyInternational privacy with kevin haley
International privacy with kevin haleySarah Fletcher
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPRSpoon London
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyKate Chan
 
Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldParsons Behle & Latimer
 
Dai Davies - GDPR Presentation
Dai Davies - GDPR PresentationDai Davies - GDPR Presentation
Dai Davies - GDPR PresentationSagittarius
 
Should European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot ActShould European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot Actfrjennings
 
Data Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesData Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesAmazon Web Services
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowDavid Erdos
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinWhitmeyerTuffin
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India SadanandGahivare
 

La actualidad más candente (20)

US – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border DataUS – EU Safe Harbor for Cross-Border Data
US – EU Safe Harbor for Cross-Border Data
 
Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy Safe Harbor: A framework for US – EU data privacy
Safe Harbor: A framework for US – EU data privacy
 
[Privacy Webinar Slides] Global Enforcement Priorities
[Privacy Webinar Slides] Global Enforcement Priorities[Privacy Webinar Slides] Global Enforcement Priorities
[Privacy Webinar Slides] Global Enforcement Priorities
 
EU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection ChangesEU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection Changes
 
Cours CyberSécurité - Privacy
Cours CyberSécurité - PrivacyCours CyberSécurité - Privacy
Cours CyberSécurité - Privacy
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
Privacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU DataPrivacy shield: What You Need To Know About Storing EU Data
Privacy shield: What You Need To Know About Storing EU Data
 
International privacy with kevin haley
International privacy with kevin haleyInternational privacy with kevin haley
International privacy with kevin haley
 
Everything you need to know about the GDPR
Everything you need to know about the GDPREverything you need to know about the GDPR
Everything you need to know about the GDPR
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy Shield
 
Dai Davies - GDPR Presentation
Dai Davies - GDPR PresentationDai Davies - GDPR Presentation
Dai Davies - GDPR Presentation
 
Should European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot ActShould European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot Act
 
Evertio Schrems II
Evertio Schrems IIEvertio Schrems II
Evertio Schrems II
 
Data Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud ServicesData Privacy & Compliance Considerations on Using Cloud Services
Data Privacy & Compliance Considerations on Using Cloud Services
 
EU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information FlowEU General Data Protection Regulation & Transborder Information Flow
EU General Data Protection Regulation & Transborder Information Flow
 
Privacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffinPrivacy law-update-whitmeyer-tuffin
Privacy law-update-whitmeyer-tuffin
 
30-31 BB Nov_Dec14 (3)
30-31 BB Nov_Dec14 (3)30-31 BB Nov_Dec14 (3)
30-31 BB Nov_Dec14 (3)
 
Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India Data Privacy Protection & Advisory - EY India
Data Privacy Protection & Advisory - EY India
 
FINAL REPORT
FINAL REPORTFINAL REPORT
FINAL REPORT
 

Similar a Patricia Ayojedi V SCTC day Cloud 24 feb16

Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...John Nas
 
Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKSally Hunt
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborGayle Gorvett
 
Spain is responsible for 80% of European Data Protection fines. (on page 3)
Spain is responsible for 80% of European Data Protection fines. (on page 3)Spain is responsible for 80% of European Data Protection fines. (on page 3)
Spain is responsible for 80% of European Data Protection fines. (on page 3)Aurélie Pols
 
Companies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsCompanies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsThe Economist Media Businesses
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?Faidepro
 
ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...Ulf Mattsson
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingJes Breslaw
 
EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2Paul Richards
 
EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2Keith Purves
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...Symantec
 
GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!WEBBED STAR
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Lumension
 
IT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestIT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestLilian Edwards
 

Similar a Patricia Ayojedi V SCTC day Cloud 24 feb16 (20)

Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
Cloud4eu - WhitePaper - OnChallengeofAcceptanceofCloudSolutionsinEUPublicSect...
 
Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UK
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe Harbor
 
Spain is responsible for 80% of European Data Protection fines. (on page 3)
Spain is responsible for 80% of European Data Protection fines. (on page 3)Spain is responsible for 80% of European Data Protection fines. (on page 3)
Spain is responsible for 80% of European Data Protection fines. (on page 3)
 
Companies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsCompanies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next steps
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?
 
What is GDPR?
What is GDPR?What is GDPR?
What is GDPR?
 
ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...ISACA Houston - How to de-classify data and rethink transfer of data between ...
ISACA Houston - How to de-classify data and rethink transfer of data between ...
 
[REPORT PREVIEW] GDPR Beyond May 25, 2018
[REPORT PREVIEW] GDPR Beyond May 25, 2018[REPORT PREVIEW] GDPR Beyond May 25, 2018
[REPORT PREVIEW] GDPR Beyond May 25, 2018
 
delphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-maskingdelphix-wp-gdpr-for-data-masking
delphix-wp-gdpr-for-data-masking
 
EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2
 
EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2EveryCloud_GDPR_Whitepaper_v2
EveryCloud_GDPR_Whitepaper_v2
 
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...The Evolution of Data Privacy - A Symantec Information Security Perspective o...
The Evolution of Data Privacy - A Symantec Information Security Perspective o...
 
GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!
 
EU Data Protection Regulation Skyhigh Networks
EU Data Protection Regulation Skyhigh NetworksEU Data Protection Regulation Skyhigh Networks
EU Data Protection Regulation Skyhigh Networks
 
GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016
 
Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?Data Protection Rules are Changing: What Can You Do to Prepare?
Data Protection Rules are Changing: What Can You Do to Prepare?
 
PL&B _UK_80
PL&B _UK_80PL&B _UK_80
PL&B _UK_80
 
IT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestIT law : the middle kingdom between east and West
IT law : the middle kingdom between east and West
 

Más de Agustin Argelich Casals

AIRESS Resucitator: Emergency Ventilator
AIRESS Resucitator: Emergency VentilatorAIRESS Resucitator: Emergency Ventilator
AIRESS Resucitator: Emergency VentilatorAgustin Argelich Casals
 
Energy Transformation for a Greener Future
Energy Transformation for a Greener FutureEnergy Transformation for a Greener Future
Energy Transformation for a Greener FutureAgustin Argelich Casals
 
Observations of Telecom over the last 40 years
Observations of Telecom over the last 40 yearsObservations of Telecom over the last 40 years
Observations of Telecom over the last 40 yearsAgustin Argelich Casals
 
Healthcare digital transformation - How to lead it COMB def.pdf
Healthcare digital transformation - How to lead it COMB def.pdfHealthcare digital transformation - How to lead it COMB def.pdf
Healthcare digital transformation - How to lead it COMB def.pdfAgustin Argelich Casals
 
The 5+1 indicators of the Intelligent Community Forum methodology
The 5+1 indicators of the Intelligent Community Forum methodologyThe 5+1 indicators of the Intelligent Community Forum methodology
The 5+1 indicators of the Intelligent Community Forum methodologyAgustin Argelich Casals
 
Agustin Argelich - 5 key factors to lead innovation.pdf
Agustin Argelich - 5 key factors to lead innovation.pdfAgustin Argelich - 5 key factors to lead innovation.pdf
Agustin Argelich - 5 key factors to lead innovation.pdfAgustin Argelich Casals
 
Digital transformation: what does it mean for Vietnam, and how to lead it to ...
Digital transformation: what does it mean for Vietnam, and how to lead it to ...Digital transformation: what does it mean for Vietnam, and how to lead it to ...
Digital transformation: what does it mean for Vietnam, and how to lead it to ...Agustin Argelich Casals
 
A networked World. The power of collaboration
A networked World.  The power of collaborationA networked World.  The power of collaboration
A networked World. The power of collaborationAgustin Argelich Casals
 
The power of Collaboration in the Digital era
The power of Collaboration in the Digital eraThe power of Collaboration in the Digital era
The power of Collaboration in the Digital eraAgustin Argelich Casals
 
The new role of Governments in deregulated telecom markets. Who is responsibl...
The new role of Governments in deregulated telecom markets. Who is responsibl...The new role of Governments in deregulated telecom markets. Who is responsibl...
The new role of Governments in deregulated telecom markets. Who is responsibl...Agustin Argelich Casals
 
How digital technology is shaping the future of humanity
How digital technology is shaping the future of humanityHow digital technology is shaping the future of humanity
How digital technology is shaping the future of humanityAgustin Argelich Casals
 
US Enterprise Cellular Market Competing Against "Big Four"
US Enterprise Cellular Market Competing Against "Big Four"US Enterprise Cellular Market Competing Against "Big Four"
US Enterprise Cellular Market Competing Against "Big Four"Agustin Argelich Casals
 
UETS – Universal Ethernet Telecommunications Services
UETS – Universal Ethernet Telecommunications ServicesUETS – Universal Ethernet Telecommunications Services
UETS – Universal Ethernet Telecommunications ServicesAgustin Argelich Casals
 
Dave Mailer presentation at VI Telecom consultants day
Dave Mailer presentation at VI Telecom consultants dayDave Mailer presentation at VI Telecom consultants day
Dave Mailer presentation at VI Telecom consultants dayAgustin Argelich Casals
 
Communications Technology where we are? where are we going?
Communications Technology where we are? where are we  going?Communications Technology where we are? where are we  going?
Communications Technology where we are? where are we going?Agustin Argelich Casals
 
Tackling Crisis and Disparity - Integral to Economic Progress
Tackling Crisis and Disparity - Integral to Economic ProgressTackling Crisis and Disparity - Integral to Economic Progress
Tackling Crisis and Disparity - Integral to Economic ProgressAgustin Argelich Casals
 
AIRESS investment opportunity - executive summary -eg-01
AIRESS investment opportunity - executive summary -eg-01AIRESS investment opportunity - executive summary -eg-01
AIRESS investment opportunity - executive summary -eg-01Agustin Argelich Casals
 
Como gestionar una pandemia sin confinar a todo el pais.
Como gestionar una pandemia sin confinar a todo el pais.Como gestionar una pandemia sin confinar a todo el pais.
Como gestionar una pandemia sin confinar a todo el pais.Agustin Argelich Casals
 

Más de Agustin Argelich Casals (20)

AIRESS Resucitator: Emergency Ventilator
AIRESS Resucitator: Emergency VentilatorAIRESS Resucitator: Emergency Ventilator
AIRESS Resucitator: Emergency Ventilator
 
Energy Transformation for a Greener Future
Energy Transformation for a Greener FutureEnergy Transformation for a Greener Future
Energy Transformation for a Greener Future
 
Observations of Telecom over the last 40 years
Observations of Telecom over the last 40 yearsObservations of Telecom over the last 40 years
Observations of Telecom over the last 40 years
 
Healthcare digital transformation - How to lead it COMB def.pdf
Healthcare digital transformation - How to lead it COMB def.pdfHealthcare digital transformation - How to lead it COMB def.pdf
Healthcare digital transformation - How to lead it COMB def.pdf
 
The 5+1 indicators of the Intelligent Community Forum methodology
The 5+1 indicators of the Intelligent Community Forum methodologyThe 5+1 indicators of the Intelligent Community Forum methodology
The 5+1 indicators of the Intelligent Community Forum methodology
 
Agustin Argelich - 5 key factors to lead innovation.pdf
Agustin Argelich - 5 key factors to lead innovation.pdfAgustin Argelich - 5 key factors to lead innovation.pdf
Agustin Argelich - 5 key factors to lead innovation.pdf
 
Digital transformation: what does it mean for Vietnam, and how to lead it to ...
Digital transformation: what does it mean for Vietnam, and how to lead it to ...Digital transformation: what does it mean for Vietnam, and how to lead it to ...
Digital transformation: what does it mean for Vietnam, and how to lead it to ...
 
A networked World. The power of collaboration
A networked World.  The power of collaborationA networked World.  The power of collaboration
A networked World. The power of collaboration
 
The power of Collaboration in the Digital era
The power of Collaboration in the Digital eraThe power of Collaboration in the Digital era
The power of Collaboration in the Digital era
 
The new role of Governments in deregulated telecom markets. Who is responsibl...
The new role of Governments in deregulated telecom markets. Who is responsibl...The new role of Governments in deregulated telecom markets. Who is responsibl...
The new role of Governments in deregulated telecom markets. Who is responsibl...
 
An American Legal Perspective
An American Legal PerspectiveAn American Legal Perspective
An American Legal Perspective
 
How digital technology is shaping the future of humanity
How digital technology is shaping the future of humanityHow digital technology is shaping the future of humanity
How digital technology is shaping the future of humanity
 
US Enterprise Cellular Market Competing Against "Big Four"
US Enterprise Cellular Market Competing Against "Big Four"US Enterprise Cellular Market Competing Against "Big Four"
US Enterprise Cellular Market Competing Against "Big Four"
 
UETS – Universal Ethernet Telecommunications Services
UETS – Universal Ethernet Telecommunications ServicesUETS – Universal Ethernet Telecommunications Services
UETS – Universal Ethernet Telecommunications Services
 
Dave Mailer presentation at VI Telecom consultants day
Dave Mailer presentation at VI Telecom consultants dayDave Mailer presentation at VI Telecom consultants day
Dave Mailer presentation at VI Telecom consultants day
 
Communications Technology where we are? where are we going?
Communications Technology where we are? where are we  going?Communications Technology where we are? where are we  going?
Communications Technology where we are? where are we going?
 
Tackling Crisis and Disparity - Integral to Economic Progress
Tackling Crisis and Disparity - Integral to Economic ProgressTackling Crisis and Disparity - Integral to Economic Progress
Tackling Crisis and Disparity - Integral to Economic Progress
 
AIRESS investment opportunity - executive summary -eg-01
AIRESS investment opportunity - executive summary -eg-01AIRESS investment opportunity - executive summary -eg-01
AIRESS investment opportunity - executive summary -eg-01
 
AIRESS - Emergency Ventilator
AIRESS - Emergency VentilatorAIRESS - Emergency Ventilator
AIRESS - Emergency Ventilator
 
Como gestionar una pandemia sin confinar a todo el pais.
Como gestionar una pandemia sin confinar a todo el pais.Como gestionar una pandemia sin confinar a todo el pais.
Como gestionar una pandemia sin confinar a todo el pais.
 

Último

Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxDyna Gilbert
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书rnrncn29
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一z xss
 
NSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentationNSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentationMarko4394
 
Q4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptxQ4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptxeditsforyah
 
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作ys8omjxb
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predieusebiomeyer
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa494f574xmv
 
Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Sonam Pathan
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Sonam Pathan
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Paul Calvano
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhimiss dipika
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationLinaWolf1
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书rnrncn29
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书zdzoqco
 

Último (17)

Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptx
 
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Serviceyoung call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
 
NSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentationNSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentation
 
Q4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptxQ4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptx
 
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predi
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa
 
Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhi
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 Documentation
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
 
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
 

Patricia Ayojedi V SCTC day Cloud 24 feb16

  • 1. Cloud Is it legal or illegal to use American cloud services in Europe? PATRICIA AYODEJI Dual qualified Lawyer, England & Spain Member of The Law Society, London & Ilustre Colegio de la Abogacía, Barcelona Founding Lawyer E-PDP payodeji@icab.cat 24th February 2016 www.e-pdp.es
  • 2. Dropbox, Google Drive, Gmail.., Microsoft Office 365.., Mailchimp & many others….
  • 3. 2016 E-PDP PROTECCIÓN DE DATOS PERSONALES CLOUD DOES NOT… Remove our responsibility for data protection, data security, data integrity, data confidentiality and business continuity . We cannot entrust or delegate these to the cloud provider. Contractual clause invalid!
  • 4. Before & After Mass-surveillance on foreigners abroad
  • 5. What you should know...... Not on a par...... Data is governed by a patchwork of state and federal laws, with new reforms added all the time. Europe has a more harmonised regime – and there are big changes planned! Privacy Act 1974 Guarantees three primary rights which federal agencies must abide by: •The right to see records about oneself, subject to Privacy Act exemptions; •The right to request the amendment of records that are not accurate, relevant, timely or complete; and •The right of individuals to be protected against unwarranted invasion of their privacy resulting from the collection, maintenance, use, and disclosure of personal information. Only applies to U.S CITIZENS OR non-U.S citizens who are permanent residents. Judicial Redress Act 2015 Gives citizens from approved EU countries (“U.S.-allied countries”) the right to sue federal agencies that mishandle their personal data in a similar way to rights Americans enjoy under the Privacy Act. Americans already enjoy similar rights in Europe. The right to redress is subject to the same restrictions U.S. citizens face under the Privacy Act, including broad exemptions for national security.
  • 7. 2016 E-PDP PROTECCIÓN DE DATOS PERSONALES Charter of Fundamental Rights of the European Union Title II Freedoms Article 8 Protection of Personal Data 1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly and on the basis of the consent of the person concerned or some other legitimate reason laid down by the law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority.
  • 8.
  • 9. Data Protection Directive 95/46/EC -> L.OPD 15/1999 PROTECTS PERSONAL DATA OF EU CITIZENS AS USERS OF CLOUD & WHEN IN CUSTODY OF A CLIENT OF CLOUD SERVICES. In process of reform! New EU Data Protection Regulation. Expected to be formally agreed shortly and in place in 2018. ONE SINGLE LAW, which will enter into force after a transition period of 2 years). Higher fines–up to 4% of turnover when companies have violated the privacy of a European. Extended territory includes all non-EU companies with no establishment in EU who offer goods/services (including free of charge) to EU citizens. Ireland will cease to be a soft option for U.S companies.
  • 10. Some Data Protection questions • Do they share data with third party subcontractors? Do you know who they are & what services are outsourced? where their servers are located? WhatsApp, Gmail… involve the processing of data via undetermined servers and companies throughout the world. • Are you sure data not used for other purposes? • In case of breach do they have the appropriate insurance? If our cloud provider does not provide us with certain guarantees all responsibility for the data lies with us!
  • 11. JURISPRUDENCE & CLOUD SOURCED DATA 2015 'annus horribilis' for Google, Facebook, Apple Yahoo etc.
  • 12. 2016 E-PDP PROTECCIÓN DE DATOS PERSONALES US Safe Harbour Scheme Turning point in international transfers to the US....The strike down of Safe Harbour! 6 October 2015, EU Court of Justice– Schrems vs. Facebook Judgment C-362/14 (Facebook- mass-surveillance programs by NSA. Snowden’s NSA leaks demonstrated that European data stored by US companies was not safe from the type of surveillance which would be considered illegal in Europe) proclaims that the 15 year old Safe Harbour, the legal framework that American companies have used to handle European citizens’ data does not provide an adequate level of protection and does not provide guarantees equivalent to those established in the European Union. Judgment invalidated the legal basis for US-EU Safe Harbour. If your company relying on Safe Harbour it is in an illegal situation and may face enforcement proceedings depending on the DPAs in question!!
  • 13. AGPD : Spanish Data Protection Authority’s response to EU Court of Justice Schrems Judgment, Madrid, 29th October 2015 In exercise of its powers the AEPD, Spanish Data Protection Authority required that at the earliest, and in any case before 29 January 2016, that all transfers of data from Spain to the U.S be notified or modified in the General Data Protection Registry and, if necessary, include details of their compliance with data protection legislation. Failing to do so within this period, the Authority may initiate proceedings, if necessary, to temporarily suspend such international transfers. https://www.agpd.es/portalwebAGPD/canalresponsable/transferencias_internacionales/common/Comunicacion_r esponsables_-_Puerto_Seguro.pdf
  • 14. The US Government’s response to Schrems U.S. Secretary of Commerce Penny Pritzker “…..We are deeply disappointed in today’s decision from the European Court of Justice, which creates significant uncertainty for both U.S. and EU companies and consumers, and puts at risk the thriving transatlantic digital economy. Among other things, the decision does not credit the benefits to privacy and growth that have been afforded by this Framework over the last 15 years….”
  • 15. How do we use American cloud services in Europe without running afoul of EU data protection law! Alternative compliant data transfer mechanisms ..... Data localisation- actual whereabouts of data Choose Spanish/EU provider e.g. migrate from Georgia based Mailchimp (Privacy policy disclose personal information to comply with court orders and subpoenas) to Madrid based Mailrelay (data centres in EU). Basic, but effective means to influence jurisdiction. Option for large organisations. EU model contractual clauses For transfers to countries or territories that do not ensure an adequate level of protection (which now includes the USA). In Spanish & English! Binding Corporate Rules ( BCRs ) A set of legally enforceable internal rules ( such as a Code of Conduct ) regarding data privacy and security, to ensure that transfers of personal data outside of the EU take place in accordance with EU rules. A valid solution. Greater flexibility THESE OPTIONS REMAIN FORMALLY EFFECTIVE & LEGAL
  • 16. #FLISH FLASH Successor to Safe Harbour: EU-US Privacy Shield 2nd February 2016 http://ec.europa.eu/avservices/video/player.cfm?ref=I115848&sitelang=en EU Commission & US Dept. of Commerce •New living framework for transatlantic data flows with continuous process of monitoring by EU Commission & annual review which will look at all aspects of the agreement. •Multiple channels for EU citizens to report any “misuse” of their personal data. Companies will have deadlines in which to respond to complaints. •EU citizens will benefit from legal redress for privacy violations . •Severe restrictions on indiscriminate mass surveillance of European citizens by U.S
  • 17. EU-US Privacy Shield The situation has not changed since Schrems WP29, ( body of representatives of individual European Member States’ DPAs ) EU- US data transfers won’t be blocked while Privacy Shield details are hammered out! Is the arrangement robust enough? Not in fact certain that will pass scrutiny of the WP29 (quality, content, legal consequences) or the ECJ (the ultimate authority on enforceability of the new pact). Plenty of questions remain & a deal is not really done yet! Uncertainty likely to prevail for some time!
  • 18. Security Employees remain the weakest link within an organisation! What security measures does it have in place and does it offer levels of security equivalent to local access? Preventative measures for viruses, hackers, spies? Do they keep security copies? ISO certification? ISO/IEC 27018 (Aug. 2014 ) code of practice to ensure cloud service providers offer suitable information security controls to protect PII processed in public cloud ISO/IEC 27017 Cloud specific information security controls & advice for cloud service customers and providers. Published end of 2015. Agreement with information security roles & responsibilities of both parties.
  • 19. http://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/ Data security breaches continue to climb World's Biggest Data Breaches Selected losses greater than 30,000 records (updated 2nd October 2015) www.informationisbeautiful.net
  • 20. Confidentiality Encryption? Who holds the Access keys? How are they protected? Usernames. Passwords. Password recovery.
  • 21. Data integrity • Measures taken by the provider to mitigate risks of data being involuntarily compromised? • Who can access data? What can they do with it? • What happens when you want to change cloud provider? Will critical data be inaccessible? For how long ? 2016 E-PDP PROTECCIÓN DE DATOS PERSONALES
  • 22. Continuity: Portability & Interoperability Ability to retrieve and shift data & services between different cloud systems. Portability a new right under the new Regulation designed especially for cloud services. i.e. ability to get structured, legible information in a format compatible with other systems!
  • 23. Go for it but remember……
  • 24. PATRICIA AYODEJI IP/IT/Privacy payodeji@icab.cat www.e-pdp.es Thank you! Don’t panic..... We protect your company data, digital products and services in different legal jurisdictions. • Information Security and Data Protection • Copyright and Trade marks • e-Legal proceedings • International legal services