SlideShare ist ein Scribd-Unternehmen logo
1 von 24
Downloaden Sie, um offline zu lesen
Cloud Computing
Legal issues


                      Patrick Van Eecke
               Partner, DLA Piper Brussels
           Professor Universiteit Antwerpen
Cloud computing & the law


Infrastructure as a Service
    Data storage
    e.g. Amazon S3


Platform as a Service
    Application development
    e.g. Google App Engine


Software as a Service
    Applications              Legal impact?
    e.g. Zoho.com
Cloud computing: legal challenges




               Liability
                                      Applicable law


                    Data protection
  Compliance



                                       Data portability
           Copyright
Current EU legal framework




                             © DLA Piper
1. Personal
data protection
Privacy and data protection



    Applicable laws
       EU Directive 95/46/EC
       National transpositions
          e.g., the Belgian Act of 8 December 1992
       Adopted in pre-Internet area, when centralised
       and limited processing was the rule
    EU rules are substantially more restrictive than
    rules from other countries (particularly US)

                                                        6
Privacy and data protection


  Cloud computing exposes the age, formality and complex
  application of the current laws


    Many legal issues are not yet resolved
    Reform of the current rules in the pipeline, but not for tomorrow


  Three examples of problems:
    Who is controller?
    Which law is applicable?
    Transfer outside of EU?




                                                                        7
“Data controllers” and “data
processors”

  Legislation makes fundamental distinction between:
    data controller: party that defines the purpose and the means of
    the processing
    data processor: “dumb performer”

  Distinction is crucial to know who is responsible
  Data controller is liable towards the “data subjects”
  Data controller must choose appropriate data processors, and
  must seek adequate contractual protection from them




                                                                       8
Data protection issues in the cloud


  Severe issues when applied in cloud computing context:
    both customer and — particularly — the hosting provider define
    the “means” of the processing
    statutory assumption that the controller is entirely in control of the
    processing
    cloud computing is all about reducing the level of direct control,
    while EU legislation is all about keeping control of data
    what about “sub-processors”?




                                                                             9
Applicable data protection law


  An EU Member State’s national law will apply when:
    establishment of EU-based controller located in its territory
    processes personal data
    controller outside EU uses “equipment” within territory

  Applied to cloud computing:
    using EU-based data centre = becoming subject to the very strict
    EU data protection rules?
    most authorities interpret “equipment” in an extremely broad way
    (even browser cookies)




                                                                       10
Transfer of data outside EU


  Principle: no transfer of data to countries outside the EU that
  do not offer an “adequate level of protection”
    only Switzerland, Argentinia and Canada
  Exceptions:
    ask permission from every “data subject” involved
    if transfer is necessary to execute contract with the data subjects
    for US: subscribing to “safe harbour list”
    “Binding Corporate Rules”
    European Commission’s model agreement




                                                                          11
Transfer of data outside EU


  In practice:
    only use cloud provider with data centre within EU
       e.g. Amazon EC2: choice of location (US East, US West or Ireland)
    or make sure that model agreement is concluded with the cloud
    provider




                                                                           12
2. Contracting issues
Small contract, big liability?



        Cloud computing services offer low barrier to entry and
        easy scaling possibilities
           “click-wrap agreements” are legally enforceable!
        Many publicly available cloud computing contracts limit
        liability of hosting provider to a level that is not in line
        with the potential risk
        Cloud computing contracts resemble typical software
        licenses, although potential risk is much higher




                                                                       14
Example



     We and our licensors shall not be responsible for
     any service interruptions, including, without
     limitation, power outages, system failures or other
     interruptions, including those that affect the receipt,
     processing, acceptance, completion or settlement of
     any payment services. (...)

     Neither we nor any of our licensors shall be liable to
     you for any direct, indirect, incidental, special,
     consequential or exemplary damages, including,
     but not limited to, damages for loss of profits,
     goodwill, use, data or other losses (...)

                                                               15
Other contractual issues



       Vendor lock-in
          There is no general legal requirement for a
          vendor to provide you with data export facilities.
          Everything depends on your contractual
          agreement.
       Unilateral termination possibilities
          Cloud provider often reserves the right to
          unilaterally terminate its service provision
       Involvement of multiple parties
          no single point of contact

                                                               16
Other contractual issues



       Auditing requirements
          many contracts impose auditing possibilities that
          include physical inspection
          how can these auditing requirements be
          complied with when geographically
          decentralised cloud services are used?
       Applicable law & competent court
          if outside own country, any litigation can
          become prohibitively expensive
       What happens in case of bankruptcy of the
       provider?
                                                              17
Service Level Agreement



       Important in any service contract, crucial in a cloud
       computing context
       Points of attention:
          How is the availability calculated by the provider?
              e.g. 10 outages of 6 minutes versus 1 outage of 1 hour
          Independent measurement of performance?
          Are service credits the “sole remedy”?




                                                                       18
3. Liability for illegal
data
Liability of cloud provider for illegal content



        In many jurisdictions, cloud providers can be held liable
        for the illegal data they may be hosting
        eCommerce Directive (2000/31/EC) introduced special
        liability protection for hosting providers:
           no liability for services that “consist of” the storage
           of electronic information
           under the condition that the provider has no
           knowledge or awareness of illegal nature...
           ...and removes or blocks illegal data when it does
           gain knowledge or become aware of illegal nature
           (“notice and takedown”)

                                                                     20
Liability of cloud provider for illegal content



        Issues:
           special protection is focused on storage, and does
           not take into account processing activities
           significant amount of (particularly French) case law
           does not offer protection when services do not
           consist exclusively of storage activities
           liability protection does not prevent so-called
           injunctions, which can be as costly and time-
           consuming
           no standard notice-and-takedown procedure
        Reform in the pipeline?
                                                                  21
4. Compliance issues
Compliance issues


 IaS
   Data retention obligations
   Tax related storage requirements
   Labour law related storage requirements
   etc.


 SaaS
   electronic invoicing legislation
   ecommerce legislation
   electronic signature legislation
   etc.
Contact

patrick.van.eecke@dlapiper.com

Weitere ähnliche Inhalte

Was ist angesagt?

Was ist angesagt? (20)

Cloud computing ppt
Cloud computing pptCloud computing ppt
Cloud computing ppt
 
Microsoft Azure Cloud Services
Microsoft Azure Cloud ServicesMicrosoft Azure Cloud Services
Microsoft Azure Cloud Services
 
cloud computing architecture.pptx
cloud computing architecture.pptxcloud computing architecture.pptx
cloud computing architecture.pptx
 
Identity and access management
Identity and access managementIdentity and access management
Identity and access management
 
Identity and Access Management
Identity and Access ManagementIdentity and Access Management
Identity and Access Management
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Cloud Computing Security
Cloud Computing SecurityCloud Computing Security
Cloud Computing Security
 
Cloud storage
Cloud storageCloud storage
Cloud storage
 
Azure security and Compliance
Azure security and ComplianceAzure security and Compliance
Azure security and Compliance
 
Cloud Computing
Cloud ComputingCloud Computing
Cloud Computing
 
Azure Security Center- Zero to Hero
Azure Security Center-  Zero to HeroAzure Security Center-  Zero to Hero
Azure Security Center- Zero to Hero
 
Data Center Security
Data Center SecurityData Center Security
Data Center Security
 
Cloud computing presentation
Cloud computing presentationCloud computing presentation
Cloud computing presentation
 
01-Chapter 01-Introduction to CASB and Netskope.pptx
01-Chapter 01-Introduction to CASB and Netskope.pptx01-Chapter 01-Introduction to CASB and Netskope.pptx
01-Chapter 01-Introduction to CASB and Netskope.pptx
 
Chap 3 infrastructure as a service(iaas)
Chap 3 infrastructure as a service(iaas)Chap 3 infrastructure as a service(iaas)
Chap 3 infrastructure as a service(iaas)
 
Presentation cloud management
Presentation   cloud managementPresentation   cloud management
Presentation cloud management
 
Legal ethics & cloud computing
Legal ethics & cloud computingLegal ethics & cloud computing
Legal ethics & cloud computing
 
Meraki overview sales deck inside sales
Meraki overview sales deck inside salesMeraki overview sales deck inside sales
Meraki overview sales deck inside sales
 
Cloud security and security architecture
Cloud security and security architectureCloud security and security architecture
Cloud security and security architecture
 
Cloud computing: Legal and ethical issues in library and information services
Cloud computing: Legal and ethical issues in library and information servicesCloud computing: Legal and ethical issues in library and information services
Cloud computing: Legal and ethical issues in library and information services
 

Andere mochten auch

Cloud Computing - a legal view from Bird & Bird
Cloud Computing - a legal view from Bird & BirdCloud Computing - a legal view from Bird & Bird
Cloud Computing - a legal view from Bird & Bird
Eduserv
 

Andere mochten auch (20)

Cloud Computing Legal Issues
Cloud Computing Legal IssuesCloud Computing Legal Issues
Cloud Computing Legal Issues
 
Cloud Computing Legal Risks And Best Practices
Cloud Computing Legal Risks And Best PracticesCloud Computing Legal Risks And Best Practices
Cloud Computing Legal Risks And Best Practices
 
Alexis Bolin Negotiating Contract To Close
Alexis Bolin Negotiating Contract To CloseAlexis Bolin Negotiating Contract To Close
Alexis Bolin Negotiating Contract To Close
 
Ian Hempseed, Hempsons
Ian Hempseed, HempsonsIan Hempseed, Hempsons
Ian Hempseed, Hempsons
 
Contract Drafting Under English Law
Contract Drafting Under English LawContract Drafting Under English Law
Contract Drafting Under English Law
 
The Benefits Of International Arbitration
The Benefits Of International ArbitrationThe Benefits Of International Arbitration
The Benefits Of International Arbitration
 
International Arbitration Overview
International Arbitration OverviewInternational Arbitration Overview
International Arbitration Overview
 
Drafting Game Rules to Minimize Litigation
Drafting Game Rules to Minimize LitigationDrafting Game Rules to Minimize Litigation
Drafting Game Rules to Minimize Litigation
 
Power Negotiation
Power NegotiationPower Negotiation
Power Negotiation
 
Cloud Computing - a legal view from Bird & Bird
Cloud Computing - a legal view from Bird & BirdCloud Computing - a legal view from Bird & Bird
Cloud Computing - a legal view from Bird & Bird
 
Negotiating Employment Contracts in the Year of the Dragon
Negotiating Employment Contracts in the Year of the DragonNegotiating Employment Contracts in the Year of the Dragon
Negotiating Employment Contracts in the Year of the Dragon
 
Contract drafting
Contract draftingContract drafting
Contract drafting
 
Negotiate Like a Pro - the Four Levers of a Sale by Lessonly
Negotiate Like a Pro - the Four Levers of a Sale by LessonlyNegotiate Like a Pro - the Four Levers of a Sale by Lessonly
Negotiate Like a Pro - the Four Levers of a Sale by Lessonly
 
Presentation 2 national income
Presentation 2 national incomePresentation 2 national income
Presentation 2 national income
 
Common Mistakes Attorneys [and Their Clients] Make Drafting and Negotating Co...
Common Mistakes Attorneys [and Their Clients] Make Drafting and Negotating Co...Common Mistakes Attorneys [and Their Clients] Make Drafting and Negotating Co...
Common Mistakes Attorneys [and Their Clients] Make Drafting and Negotating Co...
 
Intercultural Negotiation Components Chapter 11
Intercultural Negotiation Components Chapter 11Intercultural Negotiation Components Chapter 11
Intercultural Negotiation Components Chapter 11
 
Finance Vocabulary (ESL: Personal Finance)
Finance Vocabulary (ESL:  Personal Finance)Finance Vocabulary (ESL:  Personal Finance)
Finance Vocabulary (ESL: Personal Finance)
 
How to Build, Deliver and Sell Online Courses (BESIG 2016)
How to Build, Deliver and Sell Online Courses (BESIG 2016)How to Build, Deliver and Sell Online Courses (BESIG 2016)
How to Build, Deliver and Sell Online Courses (BESIG 2016)
 
Intercultural Negotiation Process: Chapter10
Intercultural Negotiation Process: Chapter10Intercultural Negotiation Process: Chapter10
Intercultural Negotiation Process: Chapter10
 
Contract Drafting
Contract DraftingContract Drafting
Contract Drafting
 

Ähnlich wie Cloud Computing: legal issues

Contracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy BortzContracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy Bortz
itnewsafrica
 
Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013
IgorMate
 
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009 Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
EuroCloud
 
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
guestd7fc9c
 

Ähnlich wie Cloud Computing: legal issues (20)

Is There Sun Behind Those Clouds
Is There Sun Behind Those CloudsIs There Sun Behind Those Clouds
Is There Sun Behind Those Clouds
 
Securing data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law FirmsSecuring data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law Firms
 
Cloud computing : legal , privacy and contract issues
Cloud computing : legal , privacy and contract issuesCloud computing : legal , privacy and contract issues
Cloud computing : legal , privacy and contract issues
 
Contracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy BortzContracting in the Cloud by Tammy Bortz
Contracting in the Cloud by Tammy Bortz
 
Cloud computing and Law-India legal summit
Cloud computing and Law-India legal summitCloud computing and Law-India legal summit
Cloud computing and Law-India legal summit
 
Cloud computing and law-India legal summit 2011
Cloud computing and law-India legal summit 2011Cloud computing and law-India legal summit 2011
Cloud computing and law-India legal summit 2011
 
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
 
Legal issues in cloud computing
Legal issues in cloud computingLegal issues in cloud computing
Legal issues in cloud computing
 
Case by case - moving data centres to Romania
Case by case - moving data centres to RomaniaCase by case - moving data centres to Romania
Case by case - moving data centres to Romania
 
Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013
 
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
 
The Cloud Computing Contract Playbook: Contracting for Cloud Services
The Cloud Computing Contract Playbook: Contracting for Cloud ServicesThe Cloud Computing Contract Playbook: Contracting for Cloud Services
The Cloud Computing Contract Playbook: Contracting for Cloud Services
 
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009 Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
 
Clouds and Chains
Clouds and ChainsClouds and Chains
Clouds and Chains
 
Legal Framework for Cloud Computing Cebit May 31 2011 Sydney
Legal Framework for Cloud Computing Cebit May 31 2011 SydneyLegal Framework for Cloud Computing Cebit May 31 2011 Sydney
Legal Framework for Cloud Computing Cebit May 31 2011 Sydney
 
Cloud
CloudCloud
Cloud
 
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
 
Legal/technical strategies addressing data risks as perimeter shifts to Cloud
Legal/technical strategies addressing data risks as perimeter shifts to CloudLegal/technical strategies addressing data risks as perimeter shifts to Cloud
Legal/technical strategies addressing data risks as perimeter shifts to Cloud
 
Cutting To The Chase: Cloud From A Customers Perspective
Cutting To The Chase: Cloud From A Customers PerspectiveCutting To The Chase: Cloud From A Customers Perspective
Cutting To The Chase: Cloud From A Customers Perspective
 
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Kürzlich hochgeladen (20)

Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 

Cloud Computing: legal issues

  • 1. Cloud Computing Legal issues Patrick Van Eecke Partner, DLA Piper Brussels Professor Universiteit Antwerpen
  • 2. Cloud computing & the law Infrastructure as a Service Data storage e.g. Amazon S3 Platform as a Service Application development e.g. Google App Engine Software as a Service Applications Legal impact? e.g. Zoho.com
  • 3. Cloud computing: legal challenges Liability Applicable law Data protection Compliance Data portability Copyright
  • 4. Current EU legal framework © DLA Piper
  • 6. Privacy and data protection Applicable laws EU Directive 95/46/EC National transpositions e.g., the Belgian Act of 8 December 1992 Adopted in pre-Internet area, when centralised and limited processing was the rule EU rules are substantially more restrictive than rules from other countries (particularly US) 6
  • 7. Privacy and data protection Cloud computing exposes the age, formality and complex application of the current laws Many legal issues are not yet resolved Reform of the current rules in the pipeline, but not for tomorrow Three examples of problems: Who is controller? Which law is applicable? Transfer outside of EU? 7
  • 8. “Data controllers” and “data processors” Legislation makes fundamental distinction between: data controller: party that defines the purpose and the means of the processing data processor: “dumb performer” Distinction is crucial to know who is responsible Data controller is liable towards the “data subjects” Data controller must choose appropriate data processors, and must seek adequate contractual protection from them 8
  • 9. Data protection issues in the cloud Severe issues when applied in cloud computing context: both customer and — particularly — the hosting provider define the “means” of the processing statutory assumption that the controller is entirely in control of the processing cloud computing is all about reducing the level of direct control, while EU legislation is all about keeping control of data what about “sub-processors”? 9
  • 10. Applicable data protection law An EU Member State’s national law will apply when: establishment of EU-based controller located in its territory processes personal data controller outside EU uses “equipment” within territory Applied to cloud computing: using EU-based data centre = becoming subject to the very strict EU data protection rules? most authorities interpret “equipment” in an extremely broad way (even browser cookies) 10
  • 11. Transfer of data outside EU Principle: no transfer of data to countries outside the EU that do not offer an “adequate level of protection” only Switzerland, Argentinia and Canada Exceptions: ask permission from every “data subject” involved if transfer is necessary to execute contract with the data subjects for US: subscribing to “safe harbour list” “Binding Corporate Rules” European Commission’s model agreement 11
  • 12. Transfer of data outside EU In practice: only use cloud provider with data centre within EU e.g. Amazon EC2: choice of location (US East, US West or Ireland) or make sure that model agreement is concluded with the cloud provider 12
  • 14. Small contract, big liability? Cloud computing services offer low barrier to entry and easy scaling possibilities “click-wrap agreements” are legally enforceable! Many publicly available cloud computing contracts limit liability of hosting provider to a level that is not in line with the potential risk Cloud computing contracts resemble typical software licenses, although potential risk is much higher 14
  • 15. Example We and our licensors shall not be responsible for any service interruptions, including, without limitation, power outages, system failures or other interruptions, including those that affect the receipt, processing, acceptance, completion or settlement of any payment services. (...) Neither we nor any of our licensors shall be liable to you for any direct, indirect, incidental, special, consequential or exemplary damages, including, but not limited to, damages for loss of profits, goodwill, use, data or other losses (...) 15
  • 16. Other contractual issues Vendor lock-in There is no general legal requirement for a vendor to provide you with data export facilities. Everything depends on your contractual agreement. Unilateral termination possibilities Cloud provider often reserves the right to unilaterally terminate its service provision Involvement of multiple parties no single point of contact 16
  • 17. Other contractual issues Auditing requirements many contracts impose auditing possibilities that include physical inspection how can these auditing requirements be complied with when geographically decentralised cloud services are used? Applicable law & competent court if outside own country, any litigation can become prohibitively expensive What happens in case of bankruptcy of the provider? 17
  • 18. Service Level Agreement Important in any service contract, crucial in a cloud computing context Points of attention: How is the availability calculated by the provider? e.g. 10 outages of 6 minutes versus 1 outage of 1 hour Independent measurement of performance? Are service credits the “sole remedy”? 18
  • 19. 3. Liability for illegal data
  • 20. Liability of cloud provider for illegal content In many jurisdictions, cloud providers can be held liable for the illegal data they may be hosting eCommerce Directive (2000/31/EC) introduced special liability protection for hosting providers: no liability for services that “consist of” the storage of electronic information under the condition that the provider has no knowledge or awareness of illegal nature... ...and removes or blocks illegal data when it does gain knowledge or become aware of illegal nature (“notice and takedown”) 20
  • 21. Liability of cloud provider for illegal content Issues: special protection is focused on storage, and does not take into account processing activities significant amount of (particularly French) case law does not offer protection when services do not consist exclusively of storage activities liability protection does not prevent so-called injunctions, which can be as costly and time- consuming no standard notice-and-takedown procedure Reform in the pipeline? 21
  • 23. Compliance issues IaS Data retention obligations Tax related storage requirements Labour law related storage requirements etc. SaaS electronic invoicing legislation ecommerce legislation electronic signature legislation etc.