GDPR and Cloud

GDPR and Cloud

What is GDPR?

The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information of individuals within the European Union (EU)

You can find full text of GDPR here

Who should comply:

GDPR applies to all companies who do business in EU regardless of where they are located. Meaning - All major companies across the world are covered

Key Terms:

  • Data Subject - People signing up for the service,
  • Data Controller - Service provider
  • Data Protection Officer - Someone who will ensure GDPR compliance

Key Features:

  1. Right to Portability and Erasure: Data subjects may transfer their personal data between service providers more easily (also called the “right to portability”), and they may direct a controller to erase their personal data under certain circumstances (also called the “right to erasure”).
  2. Reasonable Data Protection Measures: Requires companies to implement reasonable data protection measures to protect consumers’ personal data and privacy against loss or exposure.
  3. Notification of Data Breaches: Controllers must notify SAs of a personal data breach within 72 hours of learning of the breach and must provide specific details of the breach such as the nature of it and the approximate number of data subjects affected. Data controllers to notify data subjects as quickly as possible of breaches when the breaches place their rights and freedoms at high risk.
  4. Data Protection Impact Assessments: Requires companies to perform Data Protection Impact Assessments to identify risks to consumer data and Data Protection Compliance Reviews to ensure those risks are addressed.
  5. Data protection officer: Any company that processes data revealing a subject’s genetic data, health, racial or ethnic origin, religious beliefs, etc. must designate a data protection officer. Also outlines the data protection officer position and its responsibilities in ensuring GDPR compliance as well as reporting to Supervisory Authorities and data subjects.
  6. Penalties for non-compliance: Outlines the penalties for GDPR non-compliance, which can be up to 4% of the violating company’s global annual revenue depending on the nature of the violation.

How does this impact CSPs (Cloud Service Providers)?

Cloud Service Providers store various kinds of data. Cloud Services also transfer and import lot of personal data. All cloud service providers have been preparing for GDPR compliance for its services for many months.

AWS

AWS has GDPR center where all announcements are stored.

AWS has announced that all its services are GDPR ready

AZURE

While getting ready for GDPR, Azure also has made many guides and utilities available for its clients

AZURE will also help you streamline you GDPR requests. Read about it here

Google Cloud Platform (GCP)

GCP has listed its commitments to GDPR on its sites for variety of Google Services

GCP has created a resource center for GDPR compliance and can be found here

Among others, Oracle, IBM and Alibaba cloud has provided information on GDPR

Overall preparedness on GDPR is high. My expectation is GDPR will become baseline standard for protecting the data on cloud. Hopefully this information collection if useful for its readers.

Sandeep - Thanks for writing. Well written, in simple and straight language.

要查看或添加评论,请登录

Sandeep S.的更多文章

  • Quantum Proofing Future Cyber

    Quantum Proofing Future Cyber

    In August 2024, NIST (National Institute of Standards and Technology) put out its last set of encryption standards to…

  • Hosting the 2017 Eclipse: Lessons from NASA's WESTPrime Program

    Hosting the 2017 Eclipse: Lessons from NASA's WESTPrime Program

    As a Program Manager for NASA's WESTPrime program, I had the incredible opportunity to spearhead the hosting of the…

    1 条评论
  • Summary - State of Cloud 2024

    Summary - State of Cloud 2024

    Over the years, I've avidly followed several cloud and cyber-related publications, including the State of Cloud Report…

    1 条评论
  • Cloud Computing by Numbers

    Cloud Computing by Numbers

    The cloud computing sector is experiencing rapid growth, turning the digital world into a hub of innovation. McKinsey…

    4 条评论
  • Perspectives on Ethics in AI

    Perspectives on Ethics in AI

    NOTE: Opinions expressed in this article are authors personal views and are built based on publicly available…

    7 条评论
  • COVID Open Information Accelerator (COIA)

    COVID Open Information Accelerator (COIA)

    Disclaimer: Correctness of information is solely dependent on the provider of the links. Attempt has been made to use…

    1 条评论
  • WARNING! - Cyber crimes flourishing - during CORONA Scare

    WARNING! - Cyber crimes flourishing - during CORONA Scare

    There is surge in cyber crime activity over last few weeks. This is an attempt to aggregate to the recent events to…

  • Most Common - Cloud Security Hacks

    Most Common - Cloud Security Hacks

    Inspired by https://www.darkreading.

    2 条评论
  • CORONA Pandemic - Test for Cloud Computing to prove its "Business Agility"

    CORONA Pandemic - Test for Cloud Computing to prove its "Business Agility"

    As the COVID-19 or CoronaVirus Pandemic is taking shape communities, states, countries, agencies, organizations and…

  • Analyzing CSP outages ...

    Analyzing CSP outages ...

    Transparency shown by Cloud Service Providers (CSP) in root cause analysis (RCA) of outages is very informative, but…

社区洞察

其他会员也浏览了