GDPR in the Cloud
Doug Forbes
Senior Business Leader | Aligning the worlds of Business & IT | Delivering critical advisory as a Member of the Board
Welcome to the first of Privacy Specialist’s Monthly Newsletters, keeping it light about data privacy and what is really important in its world.
We know the world of GDPR is in a state of limbo after Brexit, spending has dropped due to Covid making us all tighten our belts and move to Cloud, while we understand the world has gone through a huge digital revolution as we start home working and the exposure that brings to an individual and a Business. (See our second edition for that)
This first edition focuses on the trials of moving to the Cloud and is sponsored by one of our Cloud migration Business partners 1Place, who make Cloud migration faster, and more affordable and recognise the need for Cloud as your Disaster Recovery solution. (www.1Place1Cloud.com)
All editions will give updates on the latest updates in GDPR UK vs EU via video links or articles, along with anything interesting from the ICO, including the latest fines, as we all like to see people being caught ??
If you would like to present an article, please do contact us and we look forward to any feedback via our LinkedIn company page: https://www.dhirubhai.net/company/privacy-specialists
Best Wishes, Doug, CEO @ Privacy Specialists
(https://www.dhirubhai.net/in/douglasforbes/)
GDPR & Cloud Computing
A shift towards greater use of cloud computing is well underway. Innovative products, mobile access to data, and affordable pricing structures are often cited as key drivers for an organisation to consider a move to cloud computing.
The ICO published the Personal information online code of practice in July 2010. The code explains how the DPA applies to the collection and use of personal data online. It provides practical advice for organisations that do business or provide services online.
Data Protection Act in Cloud
It applies to any processing of data, which includes the simple storage of personal data.
If you are currently a data controller, this will remain so if you move to the cloud.
领英推荐
Identifying the Data Controller
This can be quite complicated in the cloud, but ultimately the cloud customer defines who and how someone can process the personal data, so typically would be the data controller. The role of the cloud provider will be reviewed in a case by case but is typically a data processor. See ICO paper on Identifying controllers and data processors.
Always make a risk assessment and cost ROI on what data needs to be moved to the cloud and what should stay locally or be destroyed. The use of your cloud estate for DR and HA, coupled with the reduced cost to a business, should be the driver for the migration.
What to consider when selecting a cloud provider?
Security & Performance
There are very strong standards set out for compliance reasons and each should be considered, a provider would need to have these in place and the policies and procedures around these compliance requirements. Recommendations would be to carry out an external security assessment with a penetration test, test their physical security, and ask for their security compliance certifications, such as ISO27001, Cyber Essentials Plus and for a Quality of Service (QoS) history and guarantee
Business Continuity & Disaster Recovery
Does your cloud provider supply the required recovery time and point objectives (RTO & RPO) required by your business? Is there high availability failover so no real-time data is lost?
Geographic Control
Can your cloud provider guarantee your data is held within the UK, or within the EU/ EEA? If it does host in the US, and we’ve seen this with many HR systems(!), are the appropriate contract clauses in place?
Contracts
Finally, when you have considered all these factors, you need to make sure that your cloud provider, as a data processor, will cover all the requirements contractually and more:
For more information on any of the above areas on GDPR compliance, cloud migration, cloud disaster recovery, or auditing your cloud license costs please do contact us as we are happy to discuss and recommend the best way for you to approach such subjects
The lady in the funky shoes, oh & the wheelchair! Seamstresses on 'The Unique Boutique' | Northern Power Women Future List 2023 | Adaptive Fashion Designer | Disabled Entrepreneur
2 年Nathan Bent
Digital Marketing and Graphic Designer at Fiverr Level 1 Seller
2 年I appreciate you sharing this Newsletter, Doug!
Master Certified Executive Leadership Coach | Linkedin Top Voice | TEDx Speaker | Linkedin Learning Author ?? Coaching Fortune 500 leaders by upgrading their MINDSET, SKILLSET + PERFORMANCE
2 年Have a good one.
Creo Reti Commerciali |Docente Formatore Universitario | Formatore Reti Vendita | Linkedin Expert |Social Selling | Marketing HR e Sales
2 年Thanks Doug. Great Newsletter. Great post
Presensing For Men, A Method For Peace
2 年Your Newsletters never fail to peak my interest.