August User Guide: Cloud Computing Contracts, SLAs and Terms & Conditions of Use. Key Points. What s in this Guide?
|
|
|
- Cameron Lane
- 10 years ago
- Views:
Transcription
1 August 2011 User Guide: Cloud Computing Contracts, SLAs and Terms & Conditions of Use Please Note: This guidance is for information only and is not intended to replace legal advice when faced with a risk decision. What s in this Guide? This is a practical guide to the terms and conditions commonly found in cloud computing service provision contracts and agreements. It is designed to assist you in understanding the division of rights and responsibilities between the provider and the user of a cloud computing service, and to allow you to make an informed judgement as to the legal risk. This guide is part of the JISC Legal Cloud Computing toolkit. Information on how to access the full toolkit is at the end. Key Points Adopting cloud computing services does not change an institution s legal duties, only the means by which the institution will comply. The Cloud Computing Contract and Service Level Agreement are essential steps in implementing a successful cloud computing solution. Particular issues to be considered are clauses relating to jurisdiction, security of data and intellectual property rights. This work, with the exception of logos, and any other content marked with a separate copyright notice, is licensed under a Creative Commons Attribution 3.0 Unported Licence. Attribution should be JISC Legal used under Creative Commons Attribution 3.0 Unported Licence (with clickable URLs where possible). The use of logos in the work is licensed for use only on non-derivative copies. Further information at
2 Contents 1. Introduction Cloud Computing Contracts Data Protection Intellectual Property Rights Freedom of Information Obligations Legal Compliance Law Enforcement and Loss of Control Licensing Confidentiality Monitoring by Cloud Provider Law and Jurisdiction Data Retention Schedules Subcontracting Acceptable Use Policy Warranties Indemnities Exclusions and Limitations of Liability Change of Service by Cloud Provider Termination Service Level Agreement Summary Introduction This practical guide outlines the specific risks associated with contractual arrangements for procuring and implementing cloud computing solutions. It is aimed at any educational professional involved in the process of setting up or managing contracts for cloud computing solutions. It will be specifically useful to project and risk managers, contract managers, IT professionals, and procurement managers in FE and HE. Getting the contract terms right between FE and HE institutions and cloud providers is essential for the successful implementation of cloud computing. The contract terms and conditions should set out responsibilities, service expectations, financial arrangements and what happens if things go wrong. In addition to the usual contractual considerations with any commercial agreement with a third party, cloud Page 2
3 computing raises a number of legal considerations specific to the nature of internet based service delivery. 2. Cloud Computing Contracts The most important factor at the contract stage of any cloud computing project is to ensure that the cloud provider will take reasonable steps to meet the institution s existing legal duties while they are providing the service. The main legal considerations at this stage are data protection, data security and jurisdiction. There are also some intellectual property matters to manage and general contract law considerations. The contract terms and conditions between institutions and cloud providers set out the division of responsibility for both parties at the organisational and operational level. Cloud computing contracts may set out Service Level Agreements (SLAs), any licence agreements, security schedules, clauses on rights and responsibilities and processes to be activated on non-performance or breach of contract. Cloud computing contracts can vary in format and wording depending on the cloud provider and type of solution the institution is procuring. For all cloud computing contracts it is good practice to ensure that legal areas are dealt with to your satisfaction and to seek legal guidance where appropriate. Areas that are dealt with in more detail below include: the obligation to comply with data protection legislation appropriate management of intellectual property rights maintaining the capability to comply with freedom of information legislation obligations law enforcement obligations - access to cloud data confidentiality of information appropriate licensing of resources monitoring of users and security of data regulating acceptable use of IT systems - safeguarding users Page 3
4 2.1. Data Protection The Data Protection Act 1998 (DPA) governs how the personal data of individuals is processed. Whether outsourcing processing of personal data to a cloud provider or processing personal data internally, as data controllers, institutions are required to ensure that all processing of personal data that they are responsible for adheres to the eight data protection principles. Whilst compliance with all the data protection principles is necessary it is the seventh principle relating to security of data and the eighth principle relating to the geographical jurisdiction of where data is stored which are most problematic for UK institutions using a cloud provider. More information about the application of the data protection principles, which are contained in a schedule to the DPA, is available on the Information Commissioner s Office (ICO) website at: Data Security The seventh data protection principle requires an institution to ensure that personal data relating to its staff, learners and others remains secure, including protecting such data from accidental loss, damage and destruction. Where an institution uses a third party, in this case a cloud provider, to process personal data on its behalf it will be responsible for what the third party does with the data. This means that an institution could be liable where data stored using a cloud provider is lost or destroyed. The institution has an obligation to ensure that its cloud provider has adequate measures in place to protect personal data securely against unauthorised or unlawful processing and against accidental loss, destruction and damage. The institution can manage these requirements by including a security schedule within the contract with its cloud provider which outlines how they handle personal data, including: how the institution s data is separated from other organisations data restrictions on the use of personal data responses to security breaches reactions to UK DPA requirements use of security measures such as encryption Page 4
5 Institutions may want to ensure that the contract with their cloud provider contains a suitable indemnity in relation to any claim from an individual (data subject) as a result of unlawful processing (including breach of security) by the cloud provider. Insisting on industry standard security requirements within the cloud service contract will also reduce the likelihood or impact of the institution facing a third party claim under contract law for a breach of security where it has agreed in a contract with a third party to ensure the security of data. Similarly, it may reduce the likelihood of a claim in negligence from a third party alleging that the institution failed to take the security precautions reasonably expected Geographical Location of Data Cloud providers are likely to store and move data around multiple servers situated in a number of jurisdictions which may very likely be outside the European Economic Area (EEA). The DPA restricts the transfer of personal data to countries within the EEA (the eighth data protection principle). The transfer of personal data outside the EEA is not permitted unless the country has an adequate level of protection for the individual in relation to the processing of personal data. The institution may be concerned about the security of personal data stored by a cloud provider outside the EEA. An institution as data controller will remain responsible for the adequate protection of the personal data of their staff, learners and others and will need to find out where the cloud provider is processing data in order to assess how to proceed. To maintain compliance with the DPA, the institution should consider using a cloud provider in a country already assessed by the European Commission as having adequate protection, or a US provider who has signed up to the Safe Harbor Regulations (this can be checked on the US Trade Information Center - Export.gov website: safeharbor.export.gov/list.aspx or use European Commission approved contract terms with its cloud provider. Further information regarding transfer of data abroad can be found on the ICO website: Page 5
6 When contracting with a cloud provider, it is good practice, as part of the contract, to ensure the institution has a warranty or a legal contractual assurance with respect to the geographical location of the institution s stored or archived data. The institution should also consider adopting a reporting or audit mechanism to monitor compliance with this requirement. Some major cloud providers offer a number of regional zones in which a customer may be assured the data will remain. For example, Amazon s sign-up process includes a choice of storage domains: aws.amazon.com/s3/faqs/#where_is_my_data_stored and Amazon s AWS Customer Agreement (updated in 2011) includes an undertaking not to transfer content from the selected region without notification, unless required to comply with the law or requests from governmental entities: aws.amazon.com/agreement/ Fundamentally the data protection principles apply to the processing of personal data irrespective of the geographical location chosen by the institution or the cloud provider. The legal contract with the cloud provider is the means by which the institution ensures that its legal obligations continue to be fulfilled Intellectual Property Rights An arrangement with a cloud provider how intellectual property rights are to be handled is an important aspect to get right from the outset. In contrast to concerns often expressed regarding cloud services, an analysis of cloud provider s standard terms and conditions conducted by the Queen Mary University of London School of Law indicates that cloud providers do not normally assert ownership of the intellectual property rights in content and data uploaded by their users (Queen Mary University of London School of Law Legal Studies Research Paper No. 63/2010 Contracts for Clouds: Comparison and Analysis of the Terms and Conditions of Cloud Computing Services: papers.ssrn.com/sol3/papers.cfm?abstract_id= # However, the nature of the cloud means that information is constantly being added and removed or modified, and new information generated, therefore, it is important to review the cloud provider s terms and conditions and ensure that the contract is clear where ownership of this new data lies. It is essential to state in the contract that all data will continue to be owned by the institution and to ensure that any residual database rights are owned by the institution. For example, institutions will want to Page 6
7 retain copyright in literary works (teaching and research materials), database rights, and design rights in software. When several institutions are working together on a private cloud, they may decide to draw up a consortium agreement outlining the terms and conditions of the arrangements for collaborative working between institutions. This means that should there be a change in institutional structures or personnel, the collaborative working arrangements remain clearly defined. The consortium agreement should also set out how intellectual property rights are assigned for new materials created as part of the private cloud (for example, a shared guidance manual, or a data centre used for data mining with a shared centre licence), and specify how metadata will be tagged. Cloud providers, although not asserting intellectual property rights, frequently include in their contract terms and conditions a term that their customer (the institution) grants the provider a compulsory licence to republish some or all of the customer s data for the purpose of provision of the service. The institution will want to ensure that the extent of any licence is: limited to what is necessary for the provision of the cloud computing service. compatible with the institution s obligations under the DPA to process data fairly and lawfully and for limited stated purposes. compatible with its obligations to third parties Freedom of Information Obligations Freedom of Information (FOI) legislation gives individuals a right of access to information held by the institution. The legislation covers all records and information held whether digital or print, current or archived. Even though the information is stored in the cloud, an institution will still be deemed to be holding it for the purposes of FOI. It is important for the institution to address in the contract with its cloud provider how timely access to information is facilitated. It is also important to ensure that outages and failures at the cloud provider s end do not prevent the institution from fulfilling its legal obligations to respond to FOI requests within twenty working days. Page 7
8 2.4. Legal Compliance The institution should have in place a take down policy for its internal and external published content in the event of being notified of material that breaks criminal or civil law. The institution should assess whether the cloud provider can give assurances that information can be taken down without delay from websites or other accessible locations on the instruction of the institution s IT director. The institution needs to ensure in the contract with its cloud provider that there are policies and procedures which will enable the institution to comply with its investigation and take down policy Law Enforcement and Loss of Control The Regulation of Investigatory Powers Act 2000 (RIPA) governs disclosure of information by the institution to law enforcement agencies. These obligations will remain for FE and HE institutions irrespective of the type of infrastructure being used, cloud or otherwise. The contract with the cloud provider is the means by which the institution maintains control over its data and records and which enables its own compliance with law enforcement obligations Licensing An institution will have contractually agreed with publishers via current educational licences (e.g. The Copyright Licensing Agency Limited (CLA)) to safeguard resources. The licence agreement may state that only authorised persons e.g. staff and students, may view the digital resource, or storage of digital material may be restricted under licence to local servers. When using cloud computing services there is the possibility of third party access e.g. by the cloud provider or their subcontractors and the location of data may not be specific. Contractual agreements with the resource suppliers regarding location and access need to be reflected in the contract with your cloud provider. The institution may require assurances from the cloud provider in respect of geographical location of data (see section hereof) and that best efforts will be made by the provider to prevent access by unlicensed users and to prevent any unauthorised usage of the licensed resources. Page 8
9 2.7. Confidentiality There are many occasions when information is required to be kept confidential by administration staff or researchers at an institution. This will include handling personal health data, some types of employment related data, and management related data that may be sensitive commercially. Prior to entering into a cloud service agreement, senior managers will want the proposed systems to be tested to ensure that confidential data can be processed without being compromised and will also require to assess whether the cloud is an appropriate place to store and work with certain information where confidentiality is critical. The processes in place for protecting confidentiality should include outlining confidentiality provisions in the contract. The standard terms and conditions of cloud providers vary in the degree to which they undertake to maintain the confidentiality of customer s data. In fact, some cloud providers state that they have no duty of confidentiality regarding customer data and place responsibility for confidentiality on the institution, for example, via encryption. Therefore, it is desirable to state clearly in the contract terms what obligations of confidentiality are owed between the parties Monitoring by Cloud Provider Institutions may not want their use of the cloud service to be monitored by their cloud provider either due to concerns regarding the outcome of such monitoring or because it may disclose the institution s confidential data to the cloud provider. Cloud providers have different policies with respect to monitoring, for example: monitoring the nature and pattern of use (such as bandwidth consumption) monitoring use specifically for the purpose of ensuring a good quality service provision for statistical analysis for enforcing their Acceptable Use Policy (AUP) The institution will need to examine the contract details to ensure that the terms are clear with respect to the level of monitoring carried out and that the terms are consistent with their own requirements. Page 9
10 2.9. Law and Jurisdiction The nature of the cloud is such that it is likely that more than one legal jurisdiction will be involved in relation to any particular external cloud service. For example, relevant jurisdictions are likely to include the UK (where the institution is based) and the countries where the cloud provider, its servers and any subcontractors reside. The laws governing which country's laws apply to a particular issue and which country's courts will hear a particular dispute can be complex. The resolution may vary according to the area of law and the jurisdiction in which the question arises. However, some general observations are possible. A cloud provider will normally specify within its contract terms that the contract is governed by the laws of a specific country and that disputes will be heard in that country's courts. Usually this will refer to the jurisdiction in which the cloud provider has its principal place of business, but occasionally it may be the legal system where the customer is based. The law typically places few restrictions on this type of contractual clause, except some controls on electing a totally irrelevant jurisdiction, and more stringent controls in relation to consumer (non-business) contracts. In the event of a dispute the institution, if possible, will want to avoid having to enforce contractual terms in an overseas jurisdiction, under foreign law, or having to defend an action in an overseas jurisdiction and under foreign law. Institutions may therefore have to consider the possible additional costs if the cloud provider chosen applies a foreign choice of law and jurisdiction clause, versus the benefits of that particular service. For further analysis of the laws and jurisdiction applicable in cloud computing contracts refer to the Terms of Service Analysis for Cloud Providers, Legal Studies Research Paper No. 63/2010, published by Queen Mary University of London School of Law. Page 10
11 2.10. Data Retention Schedules The institution is likely to have committed to and have in place practices and procedures for records handling to enable disposal and retention of data as required by its legal obligations. How these retention schedules are complied with when the data is hosted and processed in the cloud needs to be clarified in the contract with the cloud provider Subcontracting It is important to determine whether third parties will have access to data, for example, to what extent elements of the cloud service are subcontracted by the cloud provider to third parties. If subcontracting takes place, the institution should ensure that the terms of the contract with the cloud provider reflect the institution s security requirements Acceptable Use Policy Cloud providers are broadly similar with respect to the rules they impose on how an institution may use their services. Such rules will frequently be embodied in an Acceptable Use Policy (AUP) which highlights the cloud provider s need to exclude liability arising from the actions of its customers. An AUP will normally outline activities deemed to be improper or outright illegal uses of the cloud service. Examples may include bulk unsolicited commercial (spam), fraud, gambling, hacking into other systems or the hosting of content that is obscene, defamatory, or which may promote discrimination or incite hatred. The institution should review the cloud provider s AUP to ensure that the institution can comply and it may be worth comparing the terms with those contained in the institution s own AUP for users of its IT systems and infrastructure. The types of activities which are not considered acceptable are likely to be similar. Page 11
12 2.13. Warranties In common with any outsourced service, the institution should consider any warranty it would expect to receive from its cloud provider in relation to the performance of the cloud services. It should examine the extent of any warranties provided in the cloud provider s terms and conditions accordingly. The research into standard terms and conditions of cloud providers conducted by the Queen Mary University London School of Law indicated that every cloud provider surveyed went to great lengths to deny that any warranty existed in respect of performance of the services. US providers were particularly comprehensive with respect to excluding warranties. The result of this research highlights that any warranty required by the institution would need to be negotiated with the cloud provider Indemnities Institution As with any outsourced service, the cloud provider s terms and conditions will normally incorporate indemnification clauses. These require the institution to indemnify (undertake to compensate for loss) the cloud provider against any claim arising from the institution s use of the service and this is the case even where the service provided is free. The institution should review the indemnification provisions as they would when procuring any service Cloud Provider Some cloud providers undertake to indemnify (compensate for loss) the customer in certain circumstances. Google, for example, (for Google Apps Premier will indemnify the institution against any liability arising from a third party claim that Google s technology used to provide the cloud service infringes third party intellectual property rights. Institutions should ensure that the contract with their cloud provider contains a suitable indemnity in relation to any claim from an individual (data subject) as a result of unlawful processing (including breach of security) by the cloud provider. Page 12
13 2.15. Exclusions and Limitations of Liability The institution should scrutinise the limitations of liability in the contract with its cloud provider as they would do in any case when outsourcing services. It is worth bearing in mind that limitations of liability may be buried within other provisions of the contract, for example, in the force majeure provisions or within a separate Service Level Agreement. (Force majeure is a term that effectively means unexpected events that prevent someone from doing what they had agreed to do - see section below.) Direct Damages The institution s cloud provider may include, in their standard contract terms and conditions, an exclusion for some categories of direct damages. Such terms are designed to limit the cloud provider s liability. The research carried out by Queen Mary University London School of Law found that cloud providers based in the US tended to seek to deny liability for direct damages as far as possible while European based cloud providers were less overt about seeking to exclude direct liability, presumably on the basis that in most European legal systems it is difficult to do so. This difference in approach may be a point for the institution to consider in its selection of cloud provider. The limitation of liability provisions should be carefully examined to determine the extent of any exclusion of liability for direct damages. For example, in the case where a cloud provider loses data, the institution may be able to claim for direct losses such as the cost of reconstituting data or the cost of notification. This will not be the case if the cloud provider has included an absolute exclusion of liability for loss of data in the contract. In assessing the cloud provider s liability for direct damages, the institution should also review the terms of the Service Level Agreement (SLA) to determine whether the provisions of the SLA state that the performance rebates provided in the SLA are the sole and exclusive remedy for failure in the service provision. In cases where the SLA is framed in such terms this would effectively prevent the institution from claiming for any other direct damages arising from loss of service which exceed the level of rebate but are within the overall cap on liability in the contract (SLAs are dealt with in more detail in section 3 below.) Page 13
14 Indirect Damages It is standard practice for service providers to exclude liability for indirect or consequential loss, for example, loss of profits. The case is no different for providers of cloud services. However, in reviewing the contract terms, the institution should be wary that the cloud provider does not include loss of data in its description of indirect losses Force Majeure Force majeure is a boilerplate clause normally included in service contracts to exclude liability for losses arising from circumstances outside the reasonable control of the service provider. It often includes examples such as natural disaster, governmental action, act of war or terrorism or, in the case of cloud computing services, interruption to the internet. In the case where the institution is aware that elements of the cloud service will be or may be subcontracted to a third party the institution should determine whether the force majeure provision in the contract with its cloud provider excludes liability resulting from any failure of a subcontractor. While it may be acceptable that liability is excluded where the subcontractor suffers a force majeure event. it may not be acceptable to the institution that it has no means of recourse against its cloud provider where failure in the service results from the actions of a subcontractor, in particular, where the cloud provider takes no action to rectify the situation and has not carried out any audit or monitoring of its subcontractor Cap on Direct Loss It is typical, in the terms and conditions of cloud providers, to include an overall cap on the extent of any damages for which the cloud provider will be liable which is related to the value of the contract. This can be expressed, for example, as the value of the lifetime of the contract or as the amount of the fees paid by the institution in the twelve months prior to the event giving rise to the liability. In cases where a cloud provider limits its legal responsibility to a specific amount, the figure stated will depend on the nature of the cloud service and the type of users for such service. Page 14
15 In assessing whether the cap on liability proposed by the cloud provider is acceptable, the institution should use similar criteria as it would use in the procurement process for any other outsourced service Change of Service by Cloud Provider In comparison with traditional software licensing, where an institution has no obligation to upgrade to a new version of software but may find that the old version is no longer supported, in cloud computing the cloud provider may expect to migrate all its customers to the latest version. This explains why standard contracts containing a provision where changes require written agreement of both parties tend to be the exception rather than the rule. An institution however, may be cautious of its cloud provider having a unilateral right to make changes to the service terms and conditions without notice which places an onus on the institution to review the terms and conditions as hosted on the cloud provider s website on a regular basis to check whether there have been any changes. The institution may opt for a middle ground with its cloud provider whereby different classes of change are handled differently. For example it may be appropriate to allow the cloud provider to make changes to avoid intellectual property infringement or service changes that do not impact on functionality without notice. Likewise it may be appropriate to require notice and possibly an option to terminate the contract in the case of a material change in the service which negatively impacts on the institution. Page 15
16 2.17. Termination The contract terms and conditions for cloud services will usually specify the initial duration of the contract, its renewal period and the steps to be taken by either party to terminate the contract. It is not unusual for the contract to continue indefinitely subject to payment of service fees and unless terminated by either party. The institution will expect the contract to be clear with respect to the circumstances under which either party may terminate the contract. An important issue for institutions is what happens to their data following the end of the relationship with their cloud provider Possession of Data on Termination The institution will want to ensure that they reserve the right to have data returned on termination of the contract and that the contract is specific about the format in which data is to be returned. The terms should be clear on the length of time during which data will be preserved by the cloud provider in order for the institution to retrieve it and details of charges or conditions, if any, in respect of such retrieval Deletion of Data The contract should outline the procedure agreed between the parties with respect to deletion of data. The institution will want to know whether the cloud provider will delete their data on termination of the contract. It is likely that in order for the institution to ensure compliance with its legal obligations with respect to data and to preserve confidentiality the institution will want all copies of data in the possession of the cloud provider deleted after it has exercised its rights to have data returned. 3. Service Level Agreement Although many cloud providers may seek to exclude or limit liability for performance of the service some providers will outline in a separate Service Level Agreement (SLA) a service performance target that it will aim to meet and provide a mechanism for compensating the institution for failure to meet such target. The compensation to the institution will usually be in the form of a services credit providing the institution with a rebate against billing for future services. The institution will want to ensure that the level of performance rebate is sufficient to compensate the institution and incentivise the cloud provider. Page 16
17 The institution will want to examine carefully the period within which service levels are measured in particular with respect to the definition of availability. For example where a cloud provider commits to 99.9% service availability then the actual service downtime will be significantly less if the 0.1% downtime is measured over a period of twelve months rather than being measured over one month. The SLA will usually include a list of exclusions where the performance targets and consequently performance rebates will not apply including such causes of downtime as scheduled maintenance or any circumstances outside the cloud provider s immediate control, such as routing or traffic issues affecting internet links. The SLA will often be expressed as an exhaustive or exclusive remedy for failure to provide the service. If performance rebates detailed in the SLA are stated to be the sole remedy available for failure to perform the services then the institution may be unable to terminate the contract for material breach where the breach is failure to provide the agreed service/meet service levels agreed and may be restricted from pursuing the cloud provider for any direct damages over and above the performance rebate. The SLA may also define the support available from the cloud provider with respect to the provision of its services. 4. Summary For institutions the legal obligations will largely remain unchanged in the cloud environment. However the means by which an institution ensures that its duties are met have to be adapted to fit any new service delivery model using cloud computing solutions. The contract is a critical step to achieving a successful and legally compliant relationship with the cloud provider. The legal issues this raises are similar to any contractual issues that arise when outsourcing information services to a third party. One particular issue that arises when using an internet hosted service provision is jurisdiction and the institution s obligations in terms of principle eight of the Data Protection Act Ensuring security of data held in the cloud is also a key factor. Thinking about who will own what with regard to intellectual property rights is also important to set out in the contract. Finally, as with all commercial contracts, it will be necessary to obtain appropriate legal advice and carry out proper risk assessments when choosing your cloud computing solution. Page 17
18 About JISC Legal JISC Legal, a JISC Advance service, provides guidance to prevent legal issues being a barrier to the development and adoption of new ICT within the education sector. It supports a wide range of staff within FE and HE, including managers, IT directors, administrators, and academics, with the aim to make best use of technology in developing institutional effectiveness, without legal issues becoming a barrier to appropriate use. High quality, practical support is delivered through: Written publications e.g. Web 2.0 series, blanket copyright licences, e-repositories and the law Multimedia presentations, such as recorded webcasts on staying legal with web 2.0, and digital copyright. These offer the benefit of training delivered directly to lecturers and tutors at a time convenient for them Events at various locations around the country A short turnaround help desk. This enquiry service addresses problems specific to the enquirer. Common problems are then identified by the JISC legal staff and converted into helpful FAQs on the website Commissioned research projects and joint activities with other JISC Advance services JISC Legal is a JISC Advance service. For more information on JISC Advance, please visit: JISC Legal is hosted by the University of Strathclyde, a charitable body, registered in Scotland, with registration number SC What can JISC Legal do for me? Essentials Succinct guides to areas of law relevant to ICT use in further and higher education Overviews More detailed guides to relevant areas of law Publications A range of materials on specific issues Videos On important areas of law News Recent events relevant to ICT and law, with a focus on practical consequences Events A calendar of forthcoming events from JISC Legal Useful Links An access point to other relevant information providers Enquiries A quick turnaround enquiry service, for those specific questions you may have Keeping Up-to-date Visit our website: Follow us on Twitter: Tune-in via Vimeo: Or Subscribe to our free, monthly newsletter: Page 18
August 2011. Report on Cloud Computing and the Law for UK FE and HE (An Overview)
August 2011 Report on Cloud Computing and the Law for UK FE and HE (An Overview) Please Note: This guidance is for information only and is not intended to replace legal advice when faced with a risk decision.
Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015
Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015 The following comprises a checklist of areas that genomic research organizations or consortia (collectively referred
TERMS & CONDITIONS of SERVICE for MSKnote. Refers to MSKnote Limited. Refers to you or your organisation
TERMS & CONDITIONS of SERVICE for MSKnote Definitions: "Us or Our or We or Company" You or Your or Client Refers to MSKnote Limited Refers to you or your organisation Information about us: We are MSKnote
Website Hosting Agreement
Website Hosting Agreement This Agreement is Between: (1) Tutch Media Limited, a company registered in England whose office is at 121c London Road, Knebworth, Herts, SG3 6EX ( the Host ) and (2) The Client
How To Make A Contract Between A Client And A Hoster
Web Hosting Terms & Conditions Please read these web-hosting terms carefully, as they set out our and your rights and obligations in relation to our web hosting services. AGREEMENT: Whereas: (1) The Ruby
Clause 1. Definitions and Interpretation
[Standard data protection [agreement/clauses] for the transfer of Personal Data from the University of Edinburgh (as Data Controller) to a Data Processor within the European Economic Area ] In this Agreement:-
technical factsheet 176
technical factsheet 176 Data Protection CONTENTS 1. Introduction 1 2. Register with the Information Commissioner s Office 1 3. Period protection rights and duties remain effective 2 4. The data protection
www.echoromeo.co.uk Web Hosting Contract
www.echoromeo.co.uk Web Hosting Contract 47 Glenmoor Road Ferndown Dorset BH22 8QE Ferndown: +44 (0)845 508 96 21 Aldershot: +44 (0)845 154 98 97 E-Mail: [email protected] This Agreement is Between:
Cloud Computing: Legal Risks and Best Practices
Cloud Computing: Legal Risks and Best Practices A Bennett Jones Presentation Toronto, Ontario Lisa Abe-Oldenburg, Partner Bennett Jones LLP November 7, 2012 Introduction Security and Data Privacy Recent
Agreement Addendum for Hosting Services. 1. Definitions. 2. Service Provision. 3. Scope of Client's Use 1/6
Agreement Addendum for Hosting Services 1. Definitions 1.1 Application means the specific hosted application(s) for which the Hosting Services are provided, identified and described in the Schedule. 1.2
One Education Internet Services SLA 2014-2015
One Education Internet Services SLA 2014-2015 1. Commencement a. The Contract begins on the date One Education or agents working on its behalf communicate its acceptance of the customer s order for the
By using the Cloud Service, Customer agrees to be bound by this Agreement. If you do not agree to this Agreement, do not use the Cloud Service.
1/9 CLOUD SERVICE AGREEMENT (hereinafter Agreement ) 1. THIS AGREEMENT This Cloud Service Agreement ("Agreement") is a binding legal document between Deveo and you, which explains your rights and obligations
Markley Cloud Services Hosting Agreement
Cloud Services Hosting Agreement Markley PLEASE READ CAREFULLY - THIS IS A BINDING AGREEMENT. THIS MCS CLOUD PLAN HOSTING AGREEMENT ( AGREEMENT ) IS A BINDING AGREEMENT BETWEEN ONE SUMMER COLOCATION LLC,
APPLICANT VERIFICATION SERVICES TERMS AND CONDITIONS OF USE
APPLICANT VERIFICATION SERVICES TERMS AND CONDITIONS OF USE 1 P a g e Contents 1. Interpretation and Definitions 2. Commencement and Term 3. Recitals and Relationship 4. Services 5. Systems and Software
Team Anywhere EMAIL ORDER FORM
1. Applicant Details Team Anywhere EMAIL ORDER FORM Please complete and return this form to: Quincerto Group (NZ) Ltd, PO Box 31-248, Christchurch, New Zealand Telephone: 0508 332 537 Fax: 03 342 6109
Data Protection Act 1998. Guidance on the use of cloud computing
Data Protection Act 1998 Guidance on the use of cloud computing Contents Overview... 2 Introduction... 2 What is cloud computing?... 3 Definitions... 3 Deployment models... 4 Service models... 5 Layered
Data Protection in Ireland
Data Protection in Ireland 0 Contents Data Protection in Ireland Introduction Page 2 Appointment of a Data Processor Page 2 Security Measures (onus on a data controller) Page 3 8 Principles Page 3 Fair
SCOTLAND S COMMISSIONER FOR CHILDREN AND YOUNG PEOPLE STANDARD CONDITIONS OF CONTRACT FOR SERVICES
SCOTLAND S COMMISSIONER FOR CHILDREN AND YOUNG PEOPLE STANDARD CONDITIONS OF CONTRACT FOR SERVICES 1 1 Definitions In these conditions:- We means Scotland s Commissioner for Children and Young People,
Privacy and Cloud Computing for Australian Government Agencies
Privacy and Cloud Computing for Australian Government Agencies Better Practice Guide February 2013 Version 1.1 Introduction Despite common perceptions, cloud computing has the potential to enhance privacy
SLA, Terms & Conditions Website
Subject / SLA, Terms & Conditions Website 1. DEFINITION OF TERMS Design Limited (AJA Design),,,,. trading as AJA Design having its principal place of business at,,,.. The Client - the entity which enters
Article 29 Working Party Issues Opinion on Cloud Computing
Client Alert Global Regulatory Enforcement If you have questions or would like additional information on the material covered in this Alert, please contact one of the authors: Cynthia O Donoghue Partner,
SOUTH DOWNS INTRODUCTIONS LTD ACCEPTABLE USE POLICY INCORPORATING WEBSITE TERMS AND CONDITIONS
These terms of use govern your use of our site. Please read the whole of these terms in full before you use this Website. If you do not accept these terms, please do not use this Website. Your continued
Data Protection and Privacy Policy
Data Protection and Privacy Policy 1. General This policy outlines Conciliation Resources commitments to respect the privacy of people s personal information and observe the relevant data protection legislation.
Standard conditions of purchase
Standard conditions of purchase 1 OFFER AND ACCEPTANCE 2 PROPERTY, RISK & DELIVERY 3 PRICES & RATES The Supplier shall provide all Goods and Services in accordance with the terms and conditions set out
4.1 The property and any copyright or other intellectual property rights in any Input Material shall belong to the Subscriber.
1 Interpretation 1.1 In these Conditions: THE SERVICE PROVIDER means Cutec Remote Backup Terms and Conditions THE SERVICE PROVIDER S STANDARD CHARGES means the charges shown in the Order Sheet or other
Checklist: Cloud Computing Agreement
Checklist: Cloud Computing Agreement crosslaw s checklists Date : 21 November 2015 Version 1.4 Tags : ICT Law Johan Vandendriessche Johan is partner and heads the ICT/IP/Data Protection practice. He combines
Data controllers and data processors: what the difference is and what the governance implications are
ICO lo : what the difference is and what the governance implications are Data Protection Act Contents Introduction... 3 Overview... 3 Section 1 - What is the difference between a data controller and a
Asset Protection Agreement Templates - Customer Explanatory Notes. Explanatory Notes on Asset Protection Agreement
Asset Protection Agreement Templates - Customer Explanatory Notes Explanatory Notes on Asset Protection Agreement Clause Heading Background The Asset Protection Agreement is intended for use where the
Policy and Procedure for approving, monitoring and reviewing personal data processing agreements
Policy and Procedure for approving, monitoring and reviewing personal data processing agreements 1 Personal data processing by external suppliers, contractors, agents and partners Policy and Procedure
Terms and Conditions.
Terms and Conditions. We ask that you read them through and keep a copy for your own records, just in case you need to refer back to them at any time. By ordering or using a Systems Integration (UK) Ltd.service
Web Hosting & Domain Name - Terms and Conditions
BETWEEN: Web Hosting & Domain Name - Terms and Conditions (1) Cutec Ltd a company registered in England under number 3827758 whose registered office is at 20 Branson Court, Plymouth, PL7 2WU ( the Host
If you have any questions about any of our policies, please contact the Customer Services Team.
Acceptable Use Policy (AUP) 1. Introduction Blue Monkee has created this Acceptable Use Policy (AUP) for hosting customers to protect our resources and the resources of our other customers and hosting
Trinity Online Application - Terms and Conditions of Use
IMPORTANT NOTICE PLEASE READ THE FOLLOWING TERMS AND CONDITIONS CAREFULLY. IF YOU DO NOT AGREE WITH THESE TERMS AND CONDITIONS, YOU MUST NOT USE THIS APPLICATION. BY USING THIS APPLICATION AND/OR ANY OF
Licence Fee means the fees calculated as set out on the Website or such other fee as is agreed between You and the Supplier from time to time.
BY CLICKING ON I AGREE BELOW, OR BY DOWNLOADING, INSTALLING OR MAKING ANY USE OF THE SYSTEM DESCRIBED BELOW, YOU AGREE TO THE FOLLOWING TERMS OF THIS AGREEMENT BETWEEN YOU AND {Reseller Business Name}
For the purpose of this agreement the following words and phrases shall have the meanings detailed below:
Scania Fleet Management Terms & Conditions 1. Definitions For the purpose of this agreement the following words and phrases shall have the meanings detailed below: Agent: the authorised Scania dealer or
ANZ Expense Manager TERMS AND CONDITIONS 03.10
ANZ Expense Manager TERMS AND CONDITIONS 03.10 Contents 1 Introduction 4 2 Defined Terms 4 2.1 Interpretation 7 2.2 Customer More Than One Person 8 3 Provision of ANZ Expense Manager 8 4 ANZ Expense Manager
Little Marlow Parish Council Registration Number for ICO Z3112320
Data Protection Policy Little Marlow Parish Council Registration Number for ICO Z3112320 Adopted 2012 Reviewed 23 rd February 2016 Introduction The Parish Council is fully committed to compliance with
TERMS & CONDITIONS FOR INTERNET ACCESS. Service Provided by Fast Telecommunication Company W.L.L. (hereinafter referred to as FAST Telco )
TERMS & CONDITIONS FOR INTERNET ACCESS Service Provided by Fast Telecommunication Company W.L.L. (hereinafter referred to as FAST Telco ) These are the Terms & Conditions upon which Fast Telco will provide
Service Schedule for Business Email Lite powered by Microsoft Office 365
Service Schedule for Business Email Lite powered by Microsoft Office 365 1. SERVICE DESCRIPTION Service Overview 1.1 The Service is a hosted messaging service that delivers the capabilities of Microsoft
1.1 These Terms and Conditions set out the agreement between MRS Web Solutions Ltd, 1 Blue Prior Business Park, Redfields Ln, Church Crookham,
Terms and Conditions of Sale and Services Please read these Terms and Conditions for the Supply of Services ( Terms and Conditions ) carefully, as they form part of the Agreement for the supply of our
MynxNet Broadband Terms and Conditions
MynxNet Broadband Terms and Conditions Updated 10/12/15 Introduction These terms form the basis of the services provided by MynxNet (referred to as Mynx, Mynxnet, we, us, or our ) to yourself and your
Terms of Use (basic) 1
Terms of Use (basic) 1 (1) Introduction These terms of use govern your use of our website; by using our website, you accept these terms of use in full. 2 If you disagree with these terms of use or any
TXD Digital Marketing Web Hosting Terms
TXD Digital Marketing Web Hosting Terms Page 1 of 11 Revision 1.3 Web Hosting Terms Please read these Web Hosting Terms carefully, as they set out our and your legal rights and obligations in relation
DATA PROTECTION POLICY
DATA PROTECTION POLICY Version 1.3 April 2014 Contents 1 POLICY STATEMENT...2 2 PURPOSE....2 3 LEGAL CONTEXT AND DEFINITIONS...2 3.1 Data Protection Act 1998...2 3.2 Other related legislation.....4 3.3
(1) Helastel Ltd. (2) You WEBSITE HOSTING AGREEMENT
(1) Helastel Ltd (2) You WEBSITE HOSTING AGREEMENT Helastel Ltd Website Hosting Agreement 1 THIS AGREEMENT IS BETWEEN: (1) Helastel Ltd a company registered in United Kingdom under number 05146061 whose
Service Schedule for BT Business Lite Web Hosting and Business Email Lite powered by Microsoft Office 365
1. SERVICE DESCRIPTION 1.1 The Service enables the Customer to: set up a web site(s); create a sub-domain name associated with the web site; create email addresses. 1.2 The email element of the Service
License Agreement Software as a Service (SaaS)
License Agreement Software as a Service (SaaS) Please read the following terms and conditions carefully. By clicking the accept option, downloading or installing the Software, paying for or using the Service,
Soltec Computer Systems Limited ( THE COMPANY ) Suite 1 Castlethorpe Court, Castlethorpe, Brigg, North Lincolnshire, DN20 9LG
Soltec Computer Systems Limited ( THE COMPANY ) Suite 1 Court,, Brigg,, Website Hosting Terms & Conditions 1 Notice All Users of services provided by Soltec Computer Systems Limited, by use of such services,
Hosting Service Agreement
tesseract-online.com Hosting Service Agreement Cranbox Limited T/A Tesseract Commencement Date: 1. Agreement 1.1. This Agreement is made between you (the 'Customer') and Cranbox Limited trading as Tesseract
DOMAIN NAME REGISTRATION SERVICES TERMS AND CONDITIONS
DOMAIN NAME REGISTRATION SERVICES TERMS AND CONDITIONS 1. INTERPRETATION 1.1 In this Agreement the following terms shall have the following meanings: Agreement Bundled Services Domain Names Fees Initial
Support Services Agreement
Support Services Agreement General Terms 1. This document together with various attachments forms a Contract between you (the Account Holder ) and Jarrett & Lam Consulting (trading as JLC, we, us ). 2.
Application Programming Interface (API) Application (app) - The API app is the connector between epages and the developers service.
Developer Program 0. Preamble epages is the owner and vendor of the online shop software epages which enables merchants to run their online shop in the cloud. epages provides a developer program for third
AGREEMENT WITH A SELF-EMPLOYED CONTRACTOR FOR CONSULTANCY SERVICES
AGREEMENT WITH A SELF-EMPLOYED CONTRACTOR FOR CONSULTANCY SERVICES Names of Parties 1. (Company Name) of (Company Address) ( Consultancy ). 2. Redline Group Ltd of 26-34 Liverpool Road, Luton. Beds LU1
HERTSMERE BOROUGH COUNCIL
HERTSMERE BOROUGH COUNCIL DATA PROTECTION POLICY October 2007 1 1. Introduction Hertsmere Borough Council ( the Council ) is fully committed to compliance with the requirements of the Data Protection Act
Website Hosting General Terms and Service Levels for Web Hosting and E- Mail
Website Hosting General Terms and Service Levels for Web Hosting and E- Mail Between Web Results Direct Ltd ( we/us/our ); and The Customer ( you/your ) A Bandwidth If your bandwidth either exceeds the
Ya-YaOnline Platform ( Service ).
SOFTWARE AS A SERVICE AGREEMENT FOR THE USE OF: Ya-YaOnline Platform ( Service ). NOW IT IS HEREBY AGREED by and between the parties hereto as follows:- Definitions "Agreement" means this Agreement and
Website terms and conditions
Website terms and conditions Thank you for visiting our website. Before you go any further, it is important that you read and understand the conditions under which you will be using this site. Acceptance
Web Drive Limited STANDARD TERMS AND CONDITIONS FOR THE SUPPLY OF SERVICES
Web Drive Limited STANDARD TERMS AND CONDITIONS FOR THE SUPPLY OF SERVICES Web Drive Limited trading is herein referred to as "Web Drive". 1. Definitions a) Web Drive includes its employees and directors.
fdsfdsfdsfdsfsdfdsfsdfdsfsdfsd Square Box Systems Technical Support Agreement
fdsfdsfdsfdsfsdfdsfsdfdsfsdfsd Square Box Systems Technical Support Agreement Last updated 4 th January 2016 Technical Support Agreement This Technical support agreement is made up of these terms and conditions
Trioptek Solutions, Inc. Terms of Service (TOS) And Hosted Services Agreement
Trioptek Solutions, Inc. Terms of Service (TOS) And Hosted Services Agreement Client: Date: The following terms of service ( Terms of Service ), the TOS, or agreement is between Trioptek Solutions, Inc.
SURE E-Mail Services Terms and Conditions SURE MAIL
SURE E-Mail Services Terms and Conditions SURE MAIL Sure offers an E-mail service that allows access to a mailbox provided by a 3 rd party partner ( Service ). The Service is accessed via the internet.
ROYAL MAIL GROUP ADDRESS MANAGEMENT UNIT PAF DIRECT END USER LICENCE
ROYAL MAIL GROUP ADDRESS MANAGEMENT UNIT PAF DIRECT END USER LICENCE Introduction This licence permits the use of PAF Data by an end user. Details of other licences available for the use of PAF Data can
1.3 The Terms are accepted by the Customer upon registration or ordering of the Products or renewal of any such subscription.
September 2015 WEBCRM SUBSCRIPTION TERMS AND CONDITIONS COMMERCIAL USE ONLY 1. Introduction 1.1 These subscription terms and conditions ("Terms") govern your ("Customer") subscription for and use of the
STANDARD HOSTING AGREEMENT
Elysium Ltd Head Office Milton House Whitehill Road Crowborough East Sussex TN6 1LB Phone: +44 (0)1892 667411 Fax: +44 (0)1892 667433 Web: www.elysium.ltd.uk Email: [email protected] STANDARD HOSTING
Special Terms and Conditions for HGC Business email Services
Special Terms and Conditions for HGC Business email Services 1. Description a. The Services are the HGC Business email Services, which is more particularly defined in the Order Form. The Services are provided
Terms and Conditions. Acceptable Use Policy Introduction. Compliance with UK Law. Compliance with foreign law
Terms and Conditions Acceptable Use Policy Introduction (hereafter called Hosted Developments) has created this Acceptable Use Policy (AUP) for hosting customers to protect our resources, and the resources
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:
CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES: Privacy Responsibilities and Considerations Cloud computing is the delivery of computing services over the Internet, and it offers many potential
SPECIAL CONDITIONS OF PRIVATE CLOUD Version dated 08/06/2011
SPECIAL CONDITIONS OF PRIVATE CLOUD Version dated 08/06/2011 DEFINITIONS : Cloud: Technology that uses remote resources and storage. Host Server: Physical Server with a memory load and a processor load.
Cyber and data Policy wording
Please read the schedule to see whether Breach costs, Cyber business interruption, Hacker damage, Cyber extortion, Privacy protection or Media liability are covered by this section. The General terms and
Appendix A. Call-off Terms and Conditions for the Provision of Services
Appendix A Call-off Terms and Conditions for the Provision of Services Where an Order Form is issued by the Authority that refers to the Framework Agreement, the Contract is made between the Authority
Best Companies Limited Website Terms and Conditions
These Terms and Conditions ( Terms ) govern your access to and use of the Website. By accessing and using the Website you agree that you have read and accept these terms and conditions and that they shall
Heslop & Platt Solicitors Limited
TERMS OF BUSINESS Heslop & Platt Solicitors Limited 1. Introduction and Definitions 1.1 In these terms of business, the following words and phrases have the following meanings: Initial Client Letter Client
Network Support Service Contract Terms & Conditions. Business Terms describes this agreement for the provision of support services to the client;
Network Support Service Contract Terms & Conditions 1. Definitions In these Terms and Conditions: Business Terms describes this agreement for the provision of support services to the client; Service Manager
Guide to Reviewing Contract Documentation
Guide to Reviewing Contract Documentation Introduction In order to help members address the issues associated with the review of contracts The Royal Institute of British Architects (RIBA), in association
General Terms of Public Procurement in Service Contracts JYSE 2014 SERVICES
General Terms of Public Procurement in Service Contracts January 2015 Contents Introduction...3 Issues to be observed in applying...5 General Terms of Public Procurement in Service Contracts ()...9 1 Definitions...9
WEBSITE HOSTING, DOMAIN NAME REGISTRATION AND ADD-ON SERVICES TERMS AND CONDITIONS
WEBSITE HOSTING, DOMAIN NAME REGISTRATION AND ADD-ON SERVICES TERMS AND CONDITIONS These terms and conditions constitute an agreement BETWEEN: (1) CompuTech Computing Services ( CompuTech ) and (2) the
Entee Global Services General Terms and Conditions
Entee Global Services General Terms and Conditions These General Terms & Conditions and any information relating to the Service provided by Entee Global Services forms the Agreement between Us. By accepting
Firm Registration Form
Firm Registration Form Firm Registration Form This registration form should be completed by firms who are authorised and regulated by the Financial Conduct Authority. All sections of this form are mandatory.
You must not: (a) Copy and republish material from this website (including republication on another website);
Terms of Use (1) Introduction These terms of use govern your use of our website; by using our website, you accept these terms of use in full. If you disagree with these terms of use or any part of these
Service Description for the Webhosting / HomepageTool Tool
Service Description for the Webhosting / HomepageTool Tool 1 Area of application The «Webhosting/Homepagetool Service Description» («Service Description») of Swisscom (Switzerland) AG («Swisscom») applies
EASTLINK PERSONAL CLOUD TERMS OF SERVICE
EASTLINK PERSONAL CLOUD TERMS OF SERVICE IMPORTANT - READ THE FOLLOWING TERMS AND CONDITIONS CAREFULLY BEFORE PROCEEDING WITH DOWNLOADING AND/OR THE INSTALLATION OF THE SOFTWARE OR USING EASTLINK PERSONAL
TERMS AND CONDITIONS
TERMS AND CONDITIONS The following constitute the terms and conditions under which GemBiz Limited trades and supplies its services and related products. These conditions represent the totality of the agreement
ATTENTION: This legal notice applies to the entire contents of this website under the domain name
Terms and Conditions ATTENTION: This legal notice applies to the entire contents of this website under the domain name www.pentasia.com ("the Website") and to any correspondence by e-mail between us and
Recommendations for companies planning to use Cloud computing services
Recommendations for companies planning to use Cloud computing services From a legal standpoint, CNIL finds that Cloud computing raises a number of difficulties with regard to compliance with the legislation
Cloud Software Services for Schools
Cloud Software Services for Schools Supplier self-certification statements with service and support commitments Supplier name Address Contact name Contact email Contact telephone Parent Teacher Online
Terms and Conditions for Online Services of BOC Credit Card (International) Limited
Terms and Conditions for Online Services of BOC Credit Card (International) Limited Online Services of BOC Credit Card (International) Limited ("BOCCC") are provided to you by Bank of China (Hong Kong)
