SlideShare ist ein Scribd-Unternehmen logo
1 von 26
Downloaden Sie, um offline zu lesen
19/05/2013
1
New Technologies
& Paradigms,
Old Laws
Kuan Hon
Independent Consultant
PhD Candidate, QMUL
Eduserv Symposium 2013, London 16 May 2013
@kuan∅
Outline
• Introduction
• Cloud
• Open data, big data
19/05/2013
2
@kuan∅
Introduction
• Self
[2 hats 4 clouds 3 weasels]
• Attendees?
@kuan∅
Legal risks of new tech
Risk pyramid
Legal
Reputational
[Public trust] etc etc
19/05/2013
3
@kuan∅
Communication
&
Mindsets
@kuan∅
Technologists
Binary, 1s & 0s
19/05/2013
4
@kuan∅
LawyersLawyers
(Image reproduced by
kind permission of
Firebox.com)
Certainty? Hah!
‘It depends…’
Interpretation
Context
Probabilities
19/05/2013
5
@kuan∅
Skills
For legal (& many other) issues:
Know WHO to ask,
& WHEN,
& WHAT to tell ‘em!
@kuan∅
WHO
Lawyers
19/05/2013
6
@kuan∅
WHEN
ASAP!
@kuan∅
WHAT
Your role
19/05/2013
7
@kuan∅
HOW
Money!
@kuan∅
Cloud
Open data
Big data
19/05/2013
8
@kuan∅
Laws & the internet
@kuan∅
Cloud computing & law
Risk pyramid
Laws
Reputational
[Public trust] etc etc
19/05/2013
9
@kuan∅
Let your lawyer do the
worrying…
@kuan∅
Cloud computing
• Legal risks - brief lawyers on:
– what’s cloud?
•recap
•NB layers
•12 Cs; cf traditional outsourcing
– what do you want to use it for?
•requirements, risk tolerance
User ---- DropBox ---- Amazon
SaaS IaaS
19/05/2013
10
@kuan∅
Cloud legal issues
• Lots! – IP, competition – no time…
– see cloudlegalproject.org + book
• Pre-contract checks + contract
• For public sector:
– government policy
– CloudStore
@kuan∅
Location
19/05/2013
11
@kuan∅
Data location, me & you
• Public sector – Gov ICT Offshoring
(International Sourcing) Guidance -
data location unrestricted, unless:
– national security
– data protection laws
• Data protection – cloud guidance
– Article 29 WP opinion
– UK ICO guidance
@kuan∅
Law vs IT
“Technical &
organisational
measures”
IT security
& IT
“data
protection”
“Data
protection”
(law)
19/05/2013
12
@kuan∅
Data protection laws:
“Personal data”
(cf anonymous data)
@kuan∅
EU Data Protection Directive
Data export restriction
NO transfer of PD outside
European Economic Area
19/05/2013
13
@kuan∅
Unless…
• Exception
• “Adequate protection”
/ “adequate safeguards”
• But problems…
@kuan∅
So, in practice…
• Regional clouds - easy, safe
19/05/2013
14
@kuan∅
EEA, EU, Europe…
http://bit.ly
/eu-venn for
large version
& table
@kuan∅
‘Transfer’ – physical location
• Gear: storage / processing; caches
• People: remote access
19/05/2013
15
@kuan∅
• + Names of all
“sub-contractors”
• Follow this… + other
DP regulators’
recommendations
(eg liability chain)
public cloud!
Gimme gimme gimme
your data locations…
Image from Beeld en Geluidwiki
@kuan∅
Traditional
outsourcing
Cloud
Cook food yourself
Hire caterers to cook
for you on your
instructions
Rent kitchen, cook
food yourself
Get take-out or ready
meal, cook it yourself
19/05/2013
16
@kuan∅
Key tensions
• “Guaranteed” security / liability
– should be possible – but will cost!
– cheap / free public cloud model
• Control of supply / contract chain
– will big players be the winners?
@kuan∅
“It’s unworkable, so just ignore it?”
@kuan∅
19/05/2013
17
@kuan∅
Draft Data Protection Regulation
Up to 2%
annual
global
turnover
@kuan∅
@kuan∅
Good
intentions…
Flames of hell…?
19/05/2013
18
@kuan∅
Cloud contracts
@kuan∅
Cloud contracts
• 3 aspects:
– pre-contract due diligence
– contract terms
– post-contract – monitoring etc
• See negotiated contracts article
– “no names” interviews, FOI etc
– Forbes report
19/05/2013
19
@kuan∅
Standard terms
• Providers’ standard terms
– weighted; customer-appropriate?
• Negotiable? – customer / deal size
• Gov / banks - trad. IT outsourcing
– cloud-appropriate?
• Customer process issue – bypass IT,
legal!
@kuan∅
Pre-contract due diligence
• If personal data – all sub-providers’
names; locations; security
• Lock-in and exit – practical: test data
portability in advance (NB fake data!)
• Security – pen testing, certifications?
• NB backups
• + Post-contract - security audits etc
• ENISA papers (hunt!)
19/05/2013
20
@kuan∅
Contract terms
• If personal data:
– choice of provider (security), contract
requirements: “instructions”, security
• More generally, some key issues:
– provider liability (vs price)
– lock-in – term, termination; exit terms
– security – confidentiality; audit rights?
– right to change terms? (cf G-Cloud…)
@kuan∅
G-Cloud: CloudStore
• Process - no mini-competition,
no negotiation! (though fill in blanks…)
- Price / MEAT
• Info - G-Cloud site, @G_Cloud_UK,
BuyCamp events (Friday; 7 June)
• NB overlay approach & supplier terms:
– get advice on own specific data type/use
– see G-Cloud paper
19/05/2013
21
@kuan∅
Cloud
Open data
Big data
@kuan∅
Protection of Freedoms Act
• s 102 amends FOIA
– datasets – electronic, reusable form
– open licensing – allow reuse (fees?)
• In force May/June…?
– Draft Code of Practice – consultation
– ICO publication scheme, guidance
• What datasets, how to handle?
19/05/2013
22
@kuan∅
Open data vs personal data
• Anonymise any PD before release
• Tricky! eg Sweeney etc research
• Big, eg EE / Ipsos Mori! But worthwhile
• ICO Code of Practice (full disclosure..)
– limited controlled release, vs fully public
• UK Anonymisation Network (2 years)
– anonymisation clinics – 28 June
@kuan∅
STOP PRESS
• Shakespeare review of PSI, 15 May 2013
– Deloitte market assessment
– His summary in the Guardian
• Same ol’ same ol’, words vs action? (eg jail for
unlawfully obtaining personal data…)
– Following 'best practice' guidelines should be enough, so
long as we are willing to prosecute those who misuse
personal data… In considering further legislation we should
institute increased penalties – not only loss of
accreditation and much heavier fines, but also
imprisonment in cases of deliberate and harmful misuses
of data.
19/05/2013
23
@kuan∅
Cloud
Open data
Big data
@kuan∅
Big data vs personal data
• Data protection compliance (eg
security) & anonymisation, again…
• Less data good?
• Other issues? eg IP
19/05/2013
24
@kuan∅
New technologies
and paradigms,
old laws
@kuan∅
Old laws
• Outdated assumptions
• Appropriate to new paradigms??
• But - the law is the law!
• Until laws are updated properly…
• Same ol’ strategy still sensible:
– RRRR + EEEE
19/05/2013
25
@kuan∅
Key takeaways 1
• RRRR:
– requirements evaluation, for
– real life intended use
– review & understand tech / model
– risk assessment – technological,
legal, reputational, public trust etc
(for intended data type/use case)
@kuan∅
Key takeaways 2
• EEEE – get:
– expert input / advice – legal, IT,
risk, security, stats etc
– based on exact data type, use case
– explain the tech / model properly
– early, not last minute or after!
19/05/2013
26
@kuan∅
Thank you!
Kuan Hon
Twitter: @kuan∅
Email: k @ domain below
kuan∅.com/publications.html
blog.kuan∅.com
Half lawyer | half geek | mostly harmless

Weitere ähnliche Inhalte

Ähnlich wie Legal Risks of Cloud Computing and Open Data

Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...Heiko Paulheim
 
SoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social MiningSoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social MiningResearch Data Alliance
 
AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024Aurélie Pols
 
Musings about the post covid19 world
Musings about the post covid19 worldMusings about the post covid19 world
Musings about the post covid19 worldAnant Kadiyala
 
Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data DATAVERSITY
 
Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data Data Blueprint
 
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...Bruno Segers
 
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...Heiko Paulheim
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017Ray Bugg
 
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...MicheleNati
 
Data Accountability & Consumer Trust
Data Accountability & Consumer TrustData Accountability & Consumer Trust
Data Accountability & Consumer TrustAurélie Pols
 
Sbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-finalSbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-finalFreek Bomhof
 
What is open data
What is open dataWhat is open data
What is open dataScott Sosna
 
CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018LERNER Consulting
 
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...Usama Fayyad
 
Cloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UKCloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UKCloudera, Inc.
 
Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...eraser Juan José Calderón
 
Open data for UK public sector organisations
Open data for UK public sector organisationsOpen data for UK public sector organisations
Open data for UK public sector organisationsAndrew Mackenzie
 
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...
Blockchain and Data Science:Enabling Data Integrity for Predictions through ...Blockchain and Data Science:Enabling Data Integrity for Predictions through ...
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...SunilKrPandey1
 
Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights ManagementSabrina Kirrane
 

Ähnlich wie Legal Risks of Cloud Computing and Open Data (20)

Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
 
SoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social MiningSoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social Mining
 
AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024
 
Musings about the post covid19 world
Musings about the post covid19 worldMusings about the post covid19 world
Musings about the post covid19 world
 
Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data
 
Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data
 
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
 
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017
 
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
 
Data Accountability & Consumer Trust
Data Accountability & Consumer TrustData Accountability & Consumer Trust
Data Accountability & Consumer Trust
 
Sbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-finalSbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-final
 
What is open data
What is open dataWhat is open data
What is open data
 
CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018
 
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
 
Cloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UKCloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UK
 
Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...
 
Open data for UK public sector organisations
Open data for UK public sector organisationsOpen data for UK public sector organisations
Open data for UK public sector organisations
 
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...
Blockchain and Data Science:Enabling Data Integrity for Predictions through ...Blockchain and Data Science:Enabling Data Integrity for Predictions through ...
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...
 
Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights Management
 

Mehr von Eduserv

Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionEduserv
 
Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources Eduserv
 
Lightning talk - EBSCO
Lightning talk - EBSCOLightning talk - EBSCO
Lightning talk - EBSCOEduserv
 
Lightning talk - Boopsie
Lightning talk - BoopsieLightning talk - Boopsie
Lightning talk - BoopsieEduserv
 
Lightning talk - Softlink
Lightning talk - SoftlinkLightning talk - Softlink
Lightning talk - SoftlinkEduserv
 
Lightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZineLightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZineEduserv
 
Lightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest AgreementsLightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest AgreementsEduserv
 
Phase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolutionPhase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolutionEduserv
 
Key considerations when mapping your end user experience
Key considerations when mapping your end user experienceKey considerations when mapping your end user experience
Key considerations when mapping your end user experienceEduserv
 
Our product development methodology
Our product development methodologyOur product development methodology
Our product development methodologyEduserv
 
How Readers Discover Content
How Readers Discover ContentHow Readers Discover Content
How Readers Discover ContentEduserv
 
OpenAthens product update
OpenAthens product updateOpenAthens product update
OpenAthens product updateEduserv
 
OpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome addressOpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome addressEduserv
 
Generating leads with content marketing
Generating leads with content marketingGenerating leads with content marketing
Generating leads with content marketingEduserv
 
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016Eduserv
 
Mobius from Maplesoft
Mobius from MaplesoftMobius from Maplesoft
Mobius from MaplesoftEduserv
 
QSR NVivo
QSR NVivo QSR NVivo
QSR NVivo Eduserv
 
How Eduserv are helping local government organisations
How Eduserv are helping local government organisationsHow Eduserv are helping local government organisations
How Eduserv are helping local government organisationsEduserv
 
Is cloud the right fit for your needs?
Is cloud the right fit for your needs?Is cloud the right fit for your needs?
Is cloud the right fit for your needs?Eduserv
 
Planning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing CouncilsPlanning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing CouncilsEduserv
 

Mehr von Eduserv (20)

Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect option
 
Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources
 
Lightning talk - EBSCO
Lightning talk - EBSCOLightning talk - EBSCO
Lightning talk - EBSCO
 
Lightning talk - Boopsie
Lightning talk - BoopsieLightning talk - Boopsie
Lightning talk - Boopsie
 
Lightning talk - Softlink
Lightning talk - SoftlinkLightning talk - Softlink
Lightning talk - Softlink
 
Lightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZineLightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZine
 
Lightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest AgreementsLightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest Agreements
 
Phase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolutionPhase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolution
 
Key considerations when mapping your end user experience
Key considerations when mapping your end user experienceKey considerations when mapping your end user experience
Key considerations when mapping your end user experience
 
Our product development methodology
Our product development methodologyOur product development methodology
Our product development methodology
 
How Readers Discover Content
How Readers Discover ContentHow Readers Discover Content
How Readers Discover Content
 
OpenAthens product update
OpenAthens product updateOpenAthens product update
OpenAthens product update
 
OpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome addressOpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome address
 
Generating leads with content marketing
Generating leads with content marketingGenerating leads with content marketing
Generating leads with content marketing
 
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
 
Mobius from Maplesoft
Mobius from MaplesoftMobius from Maplesoft
Mobius from Maplesoft
 
QSR NVivo
QSR NVivo QSR NVivo
QSR NVivo
 
How Eduserv are helping local government organisations
How Eduserv are helping local government organisationsHow Eduserv are helping local government organisations
How Eduserv are helping local government organisations
 
Is cloud the right fit for your needs?
Is cloud the right fit for your needs?Is cloud the right fit for your needs?
Is cloud the right fit for your needs?
 
Planning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing CouncilsPlanning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing Councils
 

Kürzlich hochgeladen

Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 

Kürzlich hochgeladen (20)

Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 

Legal Risks of Cloud Computing and Open Data

  • 1. 19/05/2013 1 New Technologies & Paradigms, Old Laws Kuan Hon Independent Consultant PhD Candidate, QMUL Eduserv Symposium 2013, London 16 May 2013 @kuan∅ Outline • Introduction • Cloud • Open data, big data
  • 2. 19/05/2013 2 @kuan∅ Introduction • Self [2 hats 4 clouds 3 weasels] • Attendees? @kuan∅ Legal risks of new tech Risk pyramid Legal Reputational [Public trust] etc etc
  • 4. 19/05/2013 4 @kuan∅ LawyersLawyers (Image reproduced by kind permission of Firebox.com) Certainty? Hah! ‘It depends…’ Interpretation Context Probabilities
  • 5. 19/05/2013 5 @kuan∅ Skills For legal (& many other) issues: Know WHO to ask, & WHEN, & WHAT to tell ‘em! @kuan∅ WHO Lawyers
  • 8. 19/05/2013 8 @kuan∅ Laws & the internet @kuan∅ Cloud computing & law Risk pyramid Laws Reputational [Public trust] etc etc
  • 9. 19/05/2013 9 @kuan∅ Let your lawyer do the worrying… @kuan∅ Cloud computing • Legal risks - brief lawyers on: – what’s cloud? •recap •NB layers •12 Cs; cf traditional outsourcing – what do you want to use it for? •requirements, risk tolerance User ---- DropBox ---- Amazon SaaS IaaS
  • 10. 19/05/2013 10 @kuan∅ Cloud legal issues • Lots! – IP, competition – no time… – see cloudlegalproject.org + book • Pre-contract checks + contract • For public sector: – government policy – CloudStore @kuan∅ Location
  • 11. 19/05/2013 11 @kuan∅ Data location, me & you • Public sector – Gov ICT Offshoring (International Sourcing) Guidance - data location unrestricted, unless: – national security – data protection laws • Data protection – cloud guidance – Article 29 WP opinion – UK ICO guidance @kuan∅ Law vs IT “Technical & organisational measures” IT security & IT “data protection” “Data protection” (law)
  • 12. 19/05/2013 12 @kuan∅ Data protection laws: “Personal data” (cf anonymous data) @kuan∅ EU Data Protection Directive Data export restriction NO transfer of PD outside European Economic Area
  • 13. 19/05/2013 13 @kuan∅ Unless… • Exception • “Adequate protection” / “adequate safeguards” • But problems… @kuan∅ So, in practice… • Regional clouds - easy, safe
  • 14. 19/05/2013 14 @kuan∅ EEA, EU, Europe… http://bit.ly /eu-venn for large version & table @kuan∅ ‘Transfer’ – physical location • Gear: storage / processing; caches • People: remote access
  • 15. 19/05/2013 15 @kuan∅ • + Names of all “sub-contractors” • Follow this… + other DP regulators’ recommendations (eg liability chain) public cloud! Gimme gimme gimme your data locations… Image from Beeld en Geluidwiki @kuan∅ Traditional outsourcing Cloud Cook food yourself Hire caterers to cook for you on your instructions Rent kitchen, cook food yourself Get take-out or ready meal, cook it yourself
  • 16. 19/05/2013 16 @kuan∅ Key tensions • “Guaranteed” security / liability – should be possible – but will cost! – cheap / free public cloud model • Control of supply / contract chain – will big players be the winners? @kuan∅ “It’s unworkable, so just ignore it?” @kuan∅
  • 17. 19/05/2013 17 @kuan∅ Draft Data Protection Regulation Up to 2% annual global turnover @kuan∅ @kuan∅ Good intentions… Flames of hell…?
  • 18. 19/05/2013 18 @kuan∅ Cloud contracts @kuan∅ Cloud contracts • 3 aspects: – pre-contract due diligence – contract terms – post-contract – monitoring etc • See negotiated contracts article – “no names” interviews, FOI etc – Forbes report
  • 19. 19/05/2013 19 @kuan∅ Standard terms • Providers’ standard terms – weighted; customer-appropriate? • Negotiable? – customer / deal size • Gov / banks - trad. IT outsourcing – cloud-appropriate? • Customer process issue – bypass IT, legal! @kuan∅ Pre-contract due diligence • If personal data – all sub-providers’ names; locations; security • Lock-in and exit – practical: test data portability in advance (NB fake data!) • Security – pen testing, certifications? • NB backups • + Post-contract - security audits etc • ENISA papers (hunt!)
  • 20. 19/05/2013 20 @kuan∅ Contract terms • If personal data: – choice of provider (security), contract requirements: “instructions”, security • More generally, some key issues: – provider liability (vs price) – lock-in – term, termination; exit terms – security – confidentiality; audit rights? – right to change terms? (cf G-Cloud…) @kuan∅ G-Cloud: CloudStore • Process - no mini-competition, no negotiation! (though fill in blanks…) - Price / MEAT • Info - G-Cloud site, @G_Cloud_UK, BuyCamp events (Friday; 7 June) • NB overlay approach & supplier terms: – get advice on own specific data type/use – see G-Cloud paper
  • 21. 19/05/2013 21 @kuan∅ Cloud Open data Big data @kuan∅ Protection of Freedoms Act • s 102 amends FOIA – datasets – electronic, reusable form – open licensing – allow reuse (fees?) • In force May/June…? – Draft Code of Practice – consultation – ICO publication scheme, guidance • What datasets, how to handle?
  • 22. 19/05/2013 22 @kuan∅ Open data vs personal data • Anonymise any PD before release • Tricky! eg Sweeney etc research • Big, eg EE / Ipsos Mori! But worthwhile • ICO Code of Practice (full disclosure..) – limited controlled release, vs fully public • UK Anonymisation Network (2 years) – anonymisation clinics – 28 June @kuan∅ STOP PRESS • Shakespeare review of PSI, 15 May 2013 – Deloitte market assessment – His summary in the Guardian • Same ol’ same ol’, words vs action? (eg jail for unlawfully obtaining personal data…) – Following 'best practice' guidelines should be enough, so long as we are willing to prosecute those who misuse personal data… In considering further legislation we should institute increased penalties – not only loss of accreditation and much heavier fines, but also imprisonment in cases of deliberate and harmful misuses of data.
  • 23. 19/05/2013 23 @kuan∅ Cloud Open data Big data @kuan∅ Big data vs personal data • Data protection compliance (eg security) & anonymisation, again… • Less data good? • Other issues? eg IP
  • 24. 19/05/2013 24 @kuan∅ New technologies and paradigms, old laws @kuan∅ Old laws • Outdated assumptions • Appropriate to new paradigms?? • But - the law is the law! • Until laws are updated properly… • Same ol’ strategy still sensible: – RRRR + EEEE
  • 25. 19/05/2013 25 @kuan∅ Key takeaways 1 • RRRR: – requirements evaluation, for – real life intended use – review & understand tech / model – risk assessment – technological, legal, reputational, public trust etc (for intended data type/use case) @kuan∅ Key takeaways 2 • EEEE – get: – expert input / advice – legal, IT, risk, security, stats etc – based on exact data type, use case – explain the tech / model properly – early, not last minute or after!
  • 26. 19/05/2013 26 @kuan∅ Thank you! Kuan Hon Twitter: @kuan∅ Email: k @ domain below kuan∅.com/publications.html blog.kuan∅.com Half lawyer | half geek | mostly harmless