Feeds

Trust lawyers, not techies, when it comes to the cloud

Minefield of privacy and data laws - so tread carefully

Top 5 reasons to deploy VMware with Tegile

CCWF2012 CIOs thinking of shifting to the cloud or kicking off a flagship big data project would be better off talking to their lawyers than their techies before starting to leaf through glossy corporate presentations.

Mark Webber, partner and head of technology at law firm Osborne Clarke, speaking at the Cloud Computing World Forum today, said that while the cloud and big data are the buzzwords du jour, CIOs' plans are still governed by UK and EU data law passed in the mid-1990s. Personal data will be covered by whatever "promises" were made at the time it was collected.

"Sometimes the simplification of technology can complicate the legal analysis and cause more legal problems than with a traditional solution," he said.

"In a few instances, where you can't change a solution, you might have to buy a different one."

Obvious issues were security and location of data, with most companies at least vaguely aware of the implications of moving data outside of the EU.

Less obvious was the fact that the more complex the "stack" – with the client's provider itself outsourcing elements such as database analysis – the more potential there was for breaching EU regulations, and bringing data under other, potentially contradictory data regimes.

Even more obscure, if only because of the inevitable affect of corporate amnesia, was the effect of original promises made to individuals when their data was collected.

This equally applied to big data applications, said Webber, where the corporate urge to mine data just to see what's there can conflict with assurances given to individuals at the time it was collected. A further layer of complexity is added when such mounds of data have been accumulated by successive company mergers and acquisitions over a course of years, all covered by different assurances on privacy.

Webber said the very nature of cloud services meant that customers could sign up, tap in a credit card number and start uploading data without ever contemplating what the corporate lawyers - if any - would say. When a cloud service appears as a £1,000-a-month credit card item, it's entirely possible it might never breach the threshold for being examined by lawyers.

Generally, he said, most hurdles could be overcome with transparency, and he said US vendors were becoming increasingly aware of "best practice" in the UK and Europe.

If there's any comfort for data managers who don't like to bring themselves to spend money on lawyers rather than tech, virtually none of this has actually been tested in court. Webber said most cases involving personal data have focused on data loss and breaches. ®

Beginner's guide to SSL certificates

More from The Register

next story
It's Big, it's Blue... it's simply FABLESS! IBM's chip-free future
Or why the reversal of globalisation ain't gonna 'appen
IBM storage revenues sink: 'We are disappointed,' says CEO
Time to put the storage biz up for sale?
'Hmm, why CAN'T I run a water pipe through that rack of media servers?'
Leaving Las Vegas for Armenia kludging and Dubai dune bashing
Microsoft and Dell’s cloud in a box: Instant Azure for the data centre
A less painful way to run Microsoft’s private cloud
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
Windows 10: Forget Cloudobile, put Security and Privacy First
But - dammit - It would be insane to say 'don't collect, because NSA'
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.