Tag Archives: Cloud Computing

Department of Commerce Provides Clarification Regarding the Safe Harbor Framework and Cloud Computing

On April 12, 2013, the Department of Commerce’s International Trade Administration (“ITA”) issued a guidance document to clarify how the U.S.-European Union Safe Harbor Framework facilitates the transfer of personal data from the European Union to the United States in the cloud computing context. The document underscores that the U.S.- European Union Safe Harbor Framework is an officially recognized means of complying with the adequacy requirement of EU Data Protection Directive 95/46/EC. ITA has received a number of inquiries from Safe Harbor participants indicating that they (and their EU clients, customers and partners) have heard conflicting information and are unsure about how the Safe Harbor Framework may enable data transfers to cloud service providers in the United States.

Continue reading…

Tags: Cloud Computing, Department of Commerce, European Union, Information Security, International, Safe Harbor

German Law Enforcement Access to Cloud Data in Foreign Jurisdictions, Including the U.S.

On March 8, 2013, the German government published a response to a formal inquiry from one of the German Parliament’s parties on the international security, data protection and surveillance implications of cloud computing. The response describes international cooperation between German and foreign law enforcement agencies that have used mutual legal assistance treaties to obtain cloud data in foreign jurisdictions. An earlier study by the European Parliament’s Committee on Civil Liberties, Justice and Home Affairs considered the scope of U.S. laws that allow surveillance of non-U.S. residents in a cloud computing context. The German government’s response now provides information on how German law enforcement agencies obtain data from clouds outside their jurisdiction (e.g., in the United States) pursuant to mutual legal assistance treaties.

Continue reading…

Tags: Cloud Computing, Enforcement, European Union, Germany, Information Security, International, Telecommunications

European Commission Launches Cybersecurity Strategy and Draft Directive on Network and Information Security

On February 7, 2013, the European Commission, together with the High Representative of the Union for Foreign Affairs and Security Policy, launched their cybersecurity strategy for the European Union (“Strategy”). As part of this Strategy, the European Commission also proposed a draft directive on measures to ensure a common level of network and information security (“NIS”) across the EU (the “Directive”).

Continue reading…

Tags: Cloud Computing, Cybersecurity, ENISA, EU Data Protection Directive, EU Member States, EU Regulation, European Commission, European Union, Information Security, International, Online Privacy, Security Breach, Social Media

EU Parliament Committee Issues Study on Cybercrime and the Privacy Implications of Cloud Computing

Recently, the European Parliament’s Committee on Civil Liberties, Justice and Home Affairs (“LIBE”) released a study titled Fighting cyber crime and protecting privacy in the cloud (the “Study”). The Study originally was prepared in October 2012 at the request of the LIBE Committee by the European Parliament’s Policy Department of Citizens’ Rights and Constitutional Affairs, with the help of the Centre for European Policy Studies and the Centre d’Etudes sur les Conflits.

Continue reading…

Tags: Accountability, Cloud Computing, Cybersecurity, Data Controller, Data Processor, Data Transfer, EU Data Protection Directive, EU Regulation, European Union, International, Online Privacy, Safe Harbor, Telecommunications

German Federal Council Requests Revisions to the European Commission’s Cloud Computing Strategy

On November 23, 2012, the German Federal Council (Bundesrat or the “Council”) published (in German) its comments on the European Commission’s strategy on cloud computing and also submitted them to the Commission.

Continue reading…

Tags: Cloud Computing, Data Protection Authority, Encryption, European Commission, European Union, Germany, Information Security, International, Peter Hustinx

European Data Protection Supervisor Publishes Cloud Computing Opinion

On November 16, 2012, European Data Protection Supervisor Peter Hustinx published an Opinion on the European Commission’s Communication on cloud computing (part of the Commission’s broader cloud computing strategy). The Opinion focuses on the accountability principle and emphasizes the importance of clearly defining the responsibilities of all parties involved in cloud computing, and analyzes specific cloud computing issues in the context of both the current EU data protection framework, as well as the proposed General Data Protection Regulation.

Continue reading…

Tags: Accountability, Cloud Computing, Data Controller, Data Processor, EU Member States, European Commission, European Data Protection Supervisor, European Union, International, Peter Hustinx

Upcoming SC Magazine Virtual Summit to Tackle Key Data Protection Issues for 2013

In partnership with SC Magazine, we are pleased to announce that on November 22-23, 2012, SC Magazine will host its 2012 Virtual Summit “Tackling the Big 3: Clouds, Consumerisation, Cybercrime,” featuring Hunton & Williams partner Bridget Treacy. Following a year of sharp increases in data breaches and regulatory fines, the SC Summit will explore and focus on cybercrime, mobile devices and cloud security – three key priorities for 2013. Bridget Treacy and Paul Swarbrick, Chief Information Security Officer and Head of Cybersecurity for National Air Traffic Services, will open the Summit with their keynote presentation, “Where’s the Danger? From Cybercrime to Consumerisation to the Cloud, Today’s Most Potent Threats Unmasked.” Paul will discuss the data security issues that keep him awake at night and Bridget will offer vital, current perspective on the ever-changing legal landscape.

Continue reading…

Tags: Bridget Treacy, Cloud Computing, Cybersecurity, European Union, Events, Information Security, International, Mobile Device, Online Privacy, Security Breach

German DPAs Publish Guidelines on Data Processing Separation in the Context of Shared IT Systems

On November 10, 2012, the German working group on technical and organizational data protection matters published guidelines (in German) on the technical and organizational separation requirements for automated data processing on shared IT systems (the “Guidelines”). The working group is part of the Conference of the German Data Protection Commissioners, which recently concluded its 84th Conference in Frankfurt (Oder).

Continue reading…

Tags: Cloud Computing, Data Processor, Data Protection Authority, European Union, Germany, Information Security, International

Data Protection Commissioners Adopt Three Resolutions at 34th International Conference

On October 26, 2012, three resolutions were adopted by the closed session of the 34th International Conference of Data Protection and Privacy Commissioners and have been published on the conference website. Below we provide an overview of these resolutions.

Continue reading…

Tags: Accountability, APEC, Behavioral Advertising, Centre for Information Policy Leadership, Cloud Computing, Data Protection Authority, EU Data Protection Directive, European Union, International, Jacob Kohnstamm

UK ICO Publishes Cloud Computing Guidance

On September 27, 2012, the UK Information Commissioner’s Office (“ICO”) published guidance on complying with the requirements of the UK Data Protection Act 1998 (“DPA”) in the context of cloud computing services (the “Guidance”). In its Guidance, the ICO reminds data controllers that transferring personal data to the cloud does not absolve them of their compliance obligations under the DPA.

Continue reading…

Tags: Christopher Graham, Cloud Computing, Data Controller, Data Processor, Data Protection Act, European Union, Information Commissioners Office, International, Online Privacy, Service Provider, United Kingdom