All the companies which are foreseen the possibility to change its manner to storage, use and manage its data have to seriously pay attention to the contractual criteria used by the cloud computing companies. According to the Spanish Data Protection Agency (hereinafter, “AEPD”) the contractual samples used by such companies does not include the minimum levels of protection required to guarantee a safely use of such technology by whatever company, and to have regulated the consequences of a termination of this kind of agreement.
Then, it is important to underline some basic aspects that we understand have to be included in the Cloud Computing Services Agreement to be executed with the cloud computing company:
• It has to be included the geographic situation of the cloud computing company servers. And it will be interesting to obligate the company to have the servers in Europe, having then a good level of protection according to the current data protection directive (Directive 95/46/EC, ‘the Data Protection Directive’) and the relevant national implementation in the EU members. If the servers are in the United States of America it is convenient to take a look to the secrecy laws there and try to regulate contractually the protection of the data in such server.
• It is convenient to not admit subcontractors in such kind agreement, establishing the contract as a “intuitu personae” Agreement. • Regulate the consequences of the agreement termination and the portability of the data (assign, destroy, or transfer the data).
• Set forth the obligation for the cloud computing company server to provide auditor reports related to the safety measures adopted, following EU member national regulations as for example in Spain (article 96 of the regulation for the development of the Data Protection Law) which includes such provision as mandatory for the medium safety level of protection (for example, for files containing a set of personal data which provide a definition of the characteristics or personality of citizens, evaluating aspects of their personality or behaviour).
• Applicable Law: in Spain the protection data law says that applicable law is the national law of the cloud computer user has its domicile.
It seems then that again the technology goes faster than the law and that all things not covered by the current Data Protection Directive has to be strictly regulated by the parties in the relevant contracts to preserve and have the best guarantee of protection of the data of a company. We expect that with the new EU regulation (being directly applicable in all EU members), which have to be voted by the European Parliament next 2014 to replace the current Data Protection Directive, will cover as better as possible all different scenarios created by cloud computing companies to have protected the companies which want to use such new method to storage, manage and use the company’s data, generating better legal certainty and safety for these new users.
At your disposal to help you in the process of contracting “Cloud” services to secure your interests in the event that some day you have to “get off of the Cloud”.
Share this article
TORRALBA BERTOLIN ABOGADOS is a founding member of ACUTA
Follow us on
© 2020 Torralba Bertolin abogados.
Legal notice. Cookies policy. Privacy policy
Cookie | Duration | Description |
---|---|---|
_ga | 2 years | This cookie is installed by Google Analytics. The cookie is used to calculate visitor, session, campaign data and keep track of site usage for the site's analytics report. The cookies store information anonymously and assign a randomly generated number to identify unique visitors. |
_gid | 1 day | This cookie is installed by Google Analytics. The cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the website is doing. The data collected including the number visitors, the source where they have come from, and the pages visted in an anonymous form. |
Cookie | Duration | Description |
---|---|---|
_gat | 1 minute | This cookies is installed by Google Universal Analytics to throttle the request rate to limit the colllection of data on high traffic sites. |
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |