Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Legal issues in the Cloud - Part 1

Cloud computing is entrenching itself in enterprises as they recognise first the economic benefits and then the agility it promises
Cloud computing requires users to weigh potential advantages against perceived risks.

Cloud computing requires users to weigh potential advantages against perceived risks.

The Cloud can be cheaper, more flexible, easier to manage and efficient. But users and providers of Cloud services have to weigh these advantages against the risks or perceived risks — such as regulatory compliance, security, performance, availability of service, and liabilities and remedies under the governing contracts.

Many of the issues would be addressed in the contract (or terms and conditions of use) which may, for example, tackle issues around the standard of services; the ownership of intellectual property; service level agreements; liability regimes; warranties and indemnity provisions; confidentiality obligations; termination clauses and the like. There are also various other requirements that are imposed by law regarding confidentiality, the liability of the parties (under the Australian Trade Practices Act, for example) and privacy.

There are no laws unique to the Cloud. However, the Cloud throws three key issues into sharp relief: The sovereignty on the internet — the location and use of data, terms of use and reliability, and lock-in and exit issues.

Data sovereignty

Unlike a fixed server in your office or at a data centre in Australia, data in the Cloud can potentially be located anywhere in the world — even in multiple data centres in multiple copies worldwide. A Cloud service provider may not even know where the data resides at any one time.

The Cloud may not be tied to any particular location but this is clearly not the case with the laws of each country. Any ‘global’ technology solution will be impacted by the laws of a large number of nation states. As a result, sending and processing data around the globe could, in the process, fail to comply with data protection and privacy laws in various countries.

The legal term for this phenomenon is ‘trans-border data flow’. Each country has its own set of laws regarding data protection and privacy — and of course some are dramatically more stringent than others.

In the UK for example, HSBC, in one of a series of security breaches relating to its customer data, was recently fined £3 million for failing to have adequate safeguards in place for its customers’ confidential details.

It’s important, therefore, for Cloud providers and users to understand their obligations.

Read Part 2 - Data sovereignty.

In June 2010, the Australian government released an exposure draft of the Australian Privacy Principles (APPs), which are intended to replace the current National Privacy Principles (NPPs).

The current NPPs dealt weakly with cross-border data flows, suggesting that personal data could be exported to any country if ‘reasonable steps’ were taken to see that the use of the data reflects the National Privacy Principles.

The new exposure draft unveiled Australian Privacy Principle 8, which regulates the same cross-border data flows. Like the current principles, it outlines that a company holding ‘personal information’ in Australia can export that information overseas if it takes ‘reasonable steps’ to ensure that the overseas recipient will not breach the APPs. Unlike the existing principles, however, the consequence of a company not taking ‘reasonable steps’ means that any breach by the overseas information-holder will be taken to have been committed by the company that exported the data. Google has raised concerns that this imposes strict liability on the entity that exports the personal information overseas. It is particularly relevant given the lack of guidelines under the APPs about what actually constitutes ‘reasonable steps’. Responses to the exposure draft have highlighted this lack of guidance as a concern, and several responses suggest that the Privacy Commissioner should release guidelines that outline and clarify these ‘reasonable steps’.

Read 12 questions to ask when considering the Cloud.

The APPs are still only an exposure draft at present, and there is talk of exceptions — one of the exceptions relates to informed consent by the individual to the disclosure of his or her data overseas — but the trend towards tougher data protection is clear, with an awareness that the uses of technology are increasingly not tied to any one legal jurisdiction. A harmonised approach is desirable and some Cloud providers have called for progress in this area, but there are hurdles to overcome.

Work is being done at the international level through the OECD and APEC to harmonise approaches to privacy regulation. An example is the new APEC Cross-border Privacy Enforcement Arrangement which has created a framework for regional cooperation in the enforcement of privacy laws. This arrangement commenced on 16 July 2010.

Mark Vincent is the lead technology and intellectual property partner and Nick Hart is a senior lawyer with Sydney based new economy law firm, Truman Hoyle.

Read Part 2 - Data sovereignty.

Read Part 3 - Due diligence.

Read Part 4 - Data exit from the Cloud.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: APEC, Google, HSBC, OECD, PEC
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: cloud computing, data sovereignty, legal, privacy, Truman Hoyle
Latest Blog Posts
Whitepapers
  • The Pathways ICT Leadership Development Program Brochure and Curriculum 2012
    Developed by the CIO executive Council, Pathways is a unique, flexible, self-managed, self-paced 12-month CIO designed and delivered professional development program that brings together best practices, thought leadership and business insights for today’s most promising ICT professionals.
    Learn more »
  • Prepare Your Enterprise for the Mobile Revolution: Boost the Bottom Line with Mobile UC
    This white paper will highlight the changes in the mobile workplace; outline the benefits of unified communications (UC) and Fixed-Mobile Convergence (FMC) for mobile workers; identify the key market trends and business challenges IT managers must pay attention to now and into the future; and offer best practices for choosing a solution that will deliver clear ROI.
    Learn more »
  • Improving Productivity in the Connected Enterprise Through Collaboration
    In the market for collaborative applications, a large convergence is beginning to take hold, and the consumerization of IT is central to this movement. The technologies that people use as consumers are impacting the way employees, customers, and partners want to interact and collaborate at work. People want to take the same technology experiences that are available at home and plug them into their daily work lives. This movement is setting worker expectations as both employees and corporate consumers. Workers need to have the choice and flexibility to consume the applications they want, where they want, and on their preferred device. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments