Feeds

Trust lawyers, not techies, when it comes to the cloud

Minefield of privacy and data laws - so tread carefully

Securing Web Applications Made Simple and Scalable

CCWF2012 CIOs thinking of shifting to the cloud or kicking off a flagship big data project would be better off talking to their lawyers than their techies before starting to leaf through glossy corporate presentations.

Mark Webber, partner and head of technology at law firm Osborne Clarke, speaking at the Cloud Computing World Forum today, said that while the cloud and big data are the buzzwords du jour, CIOs' plans are still governed by UK and EU data law passed in the mid-1990s. Personal data will be covered by whatever "promises" were made at the time it was collected.

"Sometimes the simplification of technology can complicate the legal analysis and cause more legal problems than with a traditional solution," he said.

"In a few instances, where you can't change a solution, you might have to buy a different one."

Obvious issues were security and location of data, with most companies at least vaguely aware of the implications of moving data outside of the EU.

Less obvious was the fact that the more complex the "stack" – with the client's provider itself outsourcing elements such as database analysis – the more potential there was for breaching EU regulations, and bringing data under other, potentially contradictory data regimes.

Even more obscure, if only because of the inevitable affect of corporate amnesia, was the effect of original promises made to individuals when their data was collected.

This equally applied to big data applications, said Webber, where the corporate urge to mine data just to see what's there can conflict with assurances given to individuals at the time it was collected. A further layer of complexity is added when such mounds of data have been accumulated by successive company mergers and acquisitions over a course of years, all covered by different assurances on privacy.

Webber said the very nature of cloud services meant that customers could sign up, tap in a credit card number and start uploading data without ever contemplating what the corporate lawyers - if any - would say. When a cloud service appears as a £1,000-a-month credit card item, it's entirely possible it might never breach the threshold for being examined by lawyers.

Generally, he said, most hurdles could be overcome with transparency, and he said US vendors were becoming increasingly aware of "best practice" in the UK and Europe.

If there's any comfort for data managers who don't like to bring themselves to spend money on lawyers rather than tech, virtually none of this has actually been tested in court. Webber said most cases involving personal data have focused on data loss and breaches. ®

Bridging the IT gap between rising business demands and ageing tools

More from The Register

next story
10Gbps over crumbling COPPER: Boffins cram bits down telco wire
XG-FAST tech could finesse fiber connections
THE GERMANS ARE CLOUDING: New AWS cloud region spotted
eu-central-1.amazonaws.com, aka, your new Amazon Frankfurt bitbarn
Airbus to send 1,200 TFlops of HPC goodness down the runway
HP scores deal to provide plane-maker with new fleet of data-crunching 'PODs'
Tegile boots Dell array out of chemical biz. Dell responds: Tegile, who?
Upstart says it's up, up and away ... but not on the giants' radar – yet
Dimension Data cloud goes TITSUP down under... after EMC storage fail
Replacement hardware needed as Australian cloud flops for 48-plus hours
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
The Power of One Brief: Top reasons to choose HP BladeSystem
Download this brochure to find five ways HP BladeSystem can optimize your business with the power of one.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.