• Homepage
  • Our Solutions
    • Records Storage and Document Management
      • Deed Storage
      • Long Term Storage
      • Media Storage Solutions
      • On Demand Storage
      • Onsite Management
      • Secure Vault Storage
    • Invoice Automation Solution
      • Start Your AP Journey
      • Kefron AP Integrations
    • Online Document Solutions
      • Online Document
        Management Software
      • Online Document Storage
    • Scanning and Data Capture
      • Book Scanning
      • Digital Mailroom
      • Document Scanning
      • Scan to Digitise
      • Scan to Process
    • Business Process Services
      • Data Management
      • Data Subject Access Requests
      • Securities and Deeds Management
      • GDPR Services
  • Who We Are
    • About Kefron
    • Who We Are
    • Contact Us
    • Careers
  • News & Events
    • News & Events
    • Articles & Updates
    • Customer Stories
    • Upcoming Events
    • On-demand Events
  • Let’s Talk

The GDPR and Cloud Hosting

For a while now, talk amongst the information technology community has been rife with conversation about the upcoming EU General Data Protection Regulation (GPDR). The legislation is to be finalised this year and will be effective from May 2018. The following article discusses how the GDPR will affect cloud hosting for both providers and users.

What the new regulation means for cloud providers

The GDPR will help both native and US-based cloud hosting firms and providers find business across Europe. When the new regulation comes into play, providers will be on equal footing with users and data controllers regarding rule violations and data breaches. For this reason, it is essential that the provider community is aware of all new obligations going forward.

These obligations include reporting breaches to the authorities within a 72-hour turnaround. As they often don’t have a direct relationship with users, providers will need an efficient incident-response management program to enable them to identify breaches and inform their users.

The GDPR will hold providers and users equally liable for data breaches, so it’s important that a contract is in place between both parties in order to address breach notification requirements.

Providers will also have a responsibility to assist users with security measures to ensure successful data protection.

Existing legislation

It’s worth noting that much of what is required by the cloud and data provider community is already covered by existing legislation, i.e. ISO 27001. This means that anyone certified by the ISO standard will spend most of their preparation reviewing what the provider is currently doing.

If a provider doesn’t have the ISO 27001 standard, the GDPR will have big ramifications for how users run their cloud hosting businesses.

The ‘right to be forgotten’

The updated version of the legislation will expand on the ‘right to be forgotten’, to apply to non-European companies processing the data of EU citizens, no matter where their services are located. The problem is, information can easily be copied or redistributed elsewhere, making it difficult to erase.

However, duplicated data can be avoided if systems are designed with deletion in mind. For example, companies can collect more meta data around the information they hold, as this makes it easier to find where the data is sorted and therefore easier to delete. It is essential that fool-proof systems are in place to confirm that data has been entirely erased.

Factors cloud users need to be aware of

The average European enterprise uses a total of 608 cloud apps. This may seem like a large amount, however, the usage of cloud apps has increased over time with many companies underestimating the number used by around 90%. This begs into question how organisations using cloud hosting services can successfully comply with the GDPR if they don’t know how many apps people have access to.

There are several important factors that cloud users need to consider in relation to the GDPR when serving to European customers:

    • Where are the apps storing and processing data?

This information can be obtained by finding out which cloud apps are being used within a company and discovering where the data is being hosted. It’s also important to remember that data can be moved around between an app’s different data centres.

    • Data processing agreement

Once a user knows which apps are being used in their organisation, they should close a data processing agreement with the apps to make sure they follow the GDPR’s data privacy protection requirements. In this agreement, it’s important to specify that the app should only collect the personal data necessary for the cloud to function. There should be limits on the ‘special’ data (information revealing religion, race, political persuasion etc.) collected.

    • Protecting personal data

It is crucial for users to have good security measures in place to protect personal data against alteration, loss and unofficial processing. Apps that don’t meet the company’s standards of security must be blocked.

    • Terms and conditions

All cloud apps should clearly state in their terms and conditions that the data is owned by the customer and will not be shared with third parties.
The terms should also specify that users can immediately download their own data and that the data will be erased when the app is deleted.

Will cloud hosting cost more with the GDPR?

Once the GDPR has taken effect, the cost of cloud hosting will increase to account for the additional administration necessary to deal with the regulations for each customer deployment. But the cost increase is a far better alternative to a €100m fine, or 5% of the company’s annual global turnover for anyone who doesn’t comply.

Pitfalls and consequences

The rules of the GDPR don’t come without consequences and one possible pitfall is that the regulation assumes there are only processors and controllers within a cloud ecosystem. In reality, there are many groups of companies buying into cloud services, often through Cloud Solution Provider (CSP) resellers, with hosting facilities and operations subcontracted worldwide.

There is also concern that small companies and providers might not have the resources to operate in compliance with the GDPR and therefore choose not to.

That said, the uncertainty of the new rules combined with the consequences for those who don’t comply with the regulation is likely to draw more attention to the data protection clauses in cloud service contracts.

Is your business ready for the GDPR? Take a look at our resources for all the information you need to prepare for the new regulations.

BlogBusiness Processes

Related articles

6 Simple Steps To Creating A Paperless Office

BlogBusiness Processes

How can you make the switch to a paperless office? Here are 6 simple steps to help your company make the dream a reality. Read our latest blog.

Read more

GDPR Compliance: One Year On, How Has Your Business Been Affected?

BlogBusiness Processes

Only a year ago, the long-awaited arrival of the European Union’s stringent GDPR final ended, and the business world would never be the same again. But now than the dust has settled, has the expected dramatic shake-up to data protection actually ha...

Read more

GDPR: Non-Compliant Businesses Facing First Fines

BlogBusiness Processes

It is now 6 months since the EU’s new data protection measures, the General Data Protection Regulation (GDPR), finally came into effect. But although May 25th had long been known as the deadline, there are still companies out there who are not yet ...

Read more

Data Protection in Hospitals: How To Rectify GDPR Failings In The Hospital Sector

BlogBusiness Processes

Not every sector has yet complied with GDPR. One of the biggest is the Hospitals Sector, with the Data Protection Commission highlighting 14 matters of concern it has found in hospitals. But while the situation is serious, some key steps are all that...

Read more

Why Maximizing Staff Awareness Is The Key To A Smooth GDPR Transition

BlogBusiness Processes

With D-Day fast approaching, full GDPR readiness should almost be complete. But does your staff really understand their role in the transition? Staff awareness is not only a key part of compliance, it can strengthen your organisation’s long-term po...

Read more

Data Protection Impact Assessments: What Are They and Why The GDPR Insists On Them

BlogBusiness Processes

With the GDPR around the corner, companies throughout Europe have had to re-examine both their business structures and practices. With the new regulations relating to data protection, Data Protection Impact Assessments are set to become compulsory. B...

Read more

5 Benefits Getting GDPR Ready Brings To Your Business

BlogBusiness Processes

For many business owners, the imminent arrival of the EU’s General Data Protection Regulations (GDPR) next year is something that is keeping them up at night. But initiatives associated with getting GDPR-ready are set to also bring real benefits to...

Read more

How CCTV Footage Has Become A Data Protection Matter

BlogBusiness Processes

CCTV used to be considered a solution to security issues. But in recent years, data protection legislation in both the UK and Ireland has reflected concerns over privacy and personal rights. Storing recorded security footage is now considered the s...

Read more

Why Storing Dark Data and Mining Its Secrets Benefits Businesses

BlogBusiness Processes

With a name that, alone, suggests it’s something no enterprise should want to keep, Dark Data is often a misunderstood presence in company servers. In fact, despite its ominous name, it is actually a highly-valuable asset, and storing Dark Data and...

Read more

The Role of the Information Commissioner’s Office (ICO) in Relation to the GDPR

BlogBusiness Processes

The Information Commissioner’s Office (ICO) is the independent regulatory office in charge of upholding information rights in the interest of the public. The organisation covers the following: Data Protection Act Freedom of Information Act Privacy ...

Read more

Get in touch

United Kingdom
63-66 Hatton Garden
London, EC1N 8LE
T: +44 (0)118 997 7380

Ireland
53 Park West Road
Dublin 12, D12 F8RK
T: +353 (0)1 438 0200

Connect with us

twitteryoutubeinstagramlinkedinfacebookvimeo

  • Privacy Statement
  • Terms And Conditions
  • Sitemap

© Copyright 2022 Kefron. All Rights Reserved

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT