Feeds

Trust lawyers, not techies, when it comes to the cloud

Minefield of privacy and data laws - so tread carefully

Secure remote control for conventional and virtual desktops

CCWF2012 CIOs thinking of shifting to the cloud or kicking off a flagship big data project would be better off talking to their lawyers than their techies before starting to leaf through glossy corporate presentations.

Mark Webber, partner and head of technology at law firm Osborne Clarke, speaking at the Cloud Computing World Forum today, said that while the cloud and big data are the buzzwords du jour, CIOs' plans are still governed by UK and EU data law passed in the mid-1990s. Personal data will be covered by whatever "promises" were made at the time it was collected.

"Sometimes the simplification of technology can complicate the legal analysis and cause more legal problems than with a traditional solution," he said.

"In a few instances, where you can't change a solution, you might have to buy a different one."

Obvious issues were security and location of data, with most companies at least vaguely aware of the implications of moving data outside of the EU.

Less obvious was the fact that the more complex the "stack" – with the client's provider itself outsourcing elements such as database analysis – the more potential there was for breaching EU regulations, and bringing data under other, potentially contradictory data regimes.

Even more obscure, if only because of the inevitable affect of corporate amnesia, was the effect of original promises made to individuals when their data was collected.

This equally applied to big data applications, said Webber, where the corporate urge to mine data just to see what's there can conflict with assurances given to individuals at the time it was collected. A further layer of complexity is added when such mounds of data have been accumulated by successive company mergers and acquisitions over a course of years, all covered by different assurances on privacy.

Webber said the very nature of cloud services meant that customers could sign up, tap in a credit card number and start uploading data without ever contemplating what the corporate lawyers - if any - would say. When a cloud service appears as a £1,000-a-month credit card item, it's entirely possible it might never breach the threshold for being examined by lawyers.

Generally, he said, most hurdles could be overcome with transparency, and he said US vendors were becoming increasingly aware of "best practice" in the UK and Europe.

If there's any comfort for data managers who don't like to bring themselves to spend money on lawyers rather than tech, virtually none of this has actually been tested in court. Webber said most cases involving personal data have focused on data loss and breaches. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ellison: Sparc M7 is Oracle's most important silicon EVER
'Acceleration engines' key to performance, security, Larry says
Linux? Bah! Red Hat has its eye on the CLOUD – and it wants to own it
CEO says it will be 'undisputed leader' in enterprise cloud tech
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Ello? ello? ello?: Facebook challenger in DDoS KNOCKOUT
Gets back up again after half an hour though
Hey, what's a STORAGE company doing working on Internet-of-Cars?
Boo - it's not a terabyte car, it's just predictive maintenance and that
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.