Cloud Computing. Patrick Van Eecke. Partner, DLA Piper Brussels Professor Universiteit Antwerpen



Similar documents
Legal aspects of cloud computing

How To Protect Your Data In The Cloud

TEXTURA AUSTRALASIA PTY LTD ACN ( Textura ) CONSTRUCTION PAYMENT MANAGEMENT SYSTEM TERMS AND CONDITIONS OF USE

Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015

Acquia Comments on EU Recommendations for Data Processing in the Cloud

Align Technology. Data Protection Binding Corporate Rules Processor Policy Align Technology, Inc. All rights reserved.

PointCentral Subscription Agreement v.9.2

SAMPLE RETURN POLICY

Money One Federal Credit Union Pocket 2 Pocket Service E-SIGNATURE AND ELECTRONIC DISCLOSURES AGREEMENT

Application Programming Interface (API) Application (app) - The API app is the connector between epages and the developers service.

Therm-App Software Development Kit License Agreement

BOLT Software Technology Terms of Use Last Updated: November 4, 2015

PIPER S INTERNET CAFÉ, LLC END USER AGREEMENT

XANGATI END USER SOFTWARE LICENSE TERMS AND CONDITIONS

WHITE PAPER Meeting European Data Protection and Security Requirements with CipherCloud Solutions

GENERAL TERMS AND CONDITIONS FOR THE USE OF THE ENTSO-E TRANSPARENCY PLATFORM

ARTICLE 29 DATA PROTECTION WORKING PARTY

Online Study Affiliate Marketing Agreement

App Terms and Conditions!

computer to identify you as a unique user and to take into account your personal preferences and technical information. We use:

Kaiser Permanente Affiliate Link Provider Web Site Application

By using the Cloud Service, Customer agrees to be bound by this Agreement. If you do not agree to this Agreement, do not use the Cloud Service.

Amazon Trust Services Certificate Subscriber Agreement

Appendix. 1. Scope of application of the user evaluation license agreement

The Copyright and Innovation Consultation in Adobe Systems Inc.

GlaxoSmithKline Single Sign On Portal for ClearView and Campaign Tracker - Terms of Use

Canadian Pharmaceutical Distribution Network Certificate Authority Services Agreement. In this document:

WIRELESS HIGH-SPEED INTERNET SERVICE CHARGES

ACL Training and Consulting Services Terms

EOPTION ELECTRONIC ACCESS AND TRADING AGREEMENT

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

THE TRANSFER OF PERSONAL DATA ABROAD

TERMS AND CONDITIONS

Cloud Computing Contracts. October 11, 2012

Online Communication Suite Live Chat, -Ticket, Knowledge Base, Callback

ELKHART COUNTY BOARD OF REALTORS AND MULTIPLE LISTING SERVICE OF ELKHART COUNTY INC. VIRTUAL OFFICE WEBSITE (VOW) LICENSE AGREEMENT

Paychex Accounting Online Terms of Use

Briefly summarised, SURFmarket has submitted the following questions to the Dutch DPA:

Affiliate means a legal entity that is owned by or under common ownership with Stratus Technologies Ireland Limited.

Privacy in the cloud. DNB has indicated that it considers cloud computing a form of outsourcing.

EMBARCADERO ONLINE PRODUCT CERTIFICATION AGREEMENT

GENERAL TERMS AND CONDITIONS FOR SAP CLOUD SERVICES ( GTC )

PocketSuite Terms of Service. Last modified: November 2015

SourceKraft Systems & Consulting Ltd. LICENSE AGREEMENT FOR SOFTWARE APPLICATIONS

Terms and Conditions

Licence Agreement (the Agreement )

Terms and Conditions for Tax Services

AN INSIDE VIEW FROM THE EU EXPERT GROUP ON CLOUD COMPUTING

Align Technology. Data Protection Binding Corporate Rules Controller Policy Align Technology, Inc. All rights reserved.

Into the Cloud: How will the Draft EU Data Protection Regulation affect cloud computing service providers and users?

ilinc Legal & Technology Briefs The Liability of Internet Intermediaries In the EU

technical factsheet 176

Zentyal Server Subscription Terms

COLOCATION AGREEMENT. 1. Term and Payment for Services

HYBRID SOLUTIONS INDEPENDENT SOFTWARE VENDOR AGREEMENT

Mobile Banking and Mobile Deposit Terms & Conditions

PHOTOGRAPH LICENSE BETWEEN YOU AND DEATH TO THE STOCK PHOTO

Evaluation, Development and Demonstration Software License Agreement

TERMS AND CONDITIONS OF PURCHASE

ZaZaChat End User License Agreement

INTERNET BANKING SERVICES AGREEMENT

Quartz Legal Terms and Conditions

Netaxept Agreement Agreement for epayment Service Merchants

C-DAC Medical Informatics Software Development Kit End User License Agreement

Cloud Computing: Legal Risks and Best Practices

Terms of Service. As of Julyl 1, 2014 IMPORTANT LEGALLY BINDING AGREEMENT

How To Use Etechglobal Online Store

Payroll Services Agreement

BEUC s contribution on Cloud Computing for the Public Hearing in the ITRE Committee, European Parliament, 29 May 2013

MEDICAL EDUCATION INSTITUTE, INC. KDQOL-Complete TM SERVICES and DATA USE AGREEMENT

jchartfx Plus End User License Agreement (EULA)

SOFTWARE SUBSCRIPTION SERVICE (SaaS) AGREEMENT

Cloud Computing and HIPAA Privacy and Security

Service Description for the Webhosting / HomepageTool Tool

WORKERS COMPENSATION AND EMPLOYERS LIABILITY INSURANCE POLICY

Website Disclaimer Disclaimer 1

NRBN VOICE SERVICES RETAIL AGREEMENT. (9-1-1 VoIP Emergency Calling) NIAGARA REGIONAL BROADBAND NETWORK LIMITED ( NRBN ) - and -

Page! 1 of! 6 Initials: [ ] 1CRM Software License Agreement Version The License

APPENDIX A that is not acceptable. Arbitration settled by arbitration arbitration shall be held in New Jersey substantive law of New Jersey

General Terms and Conditions Regarding Accepting Ticket solutions for Meal and/or Sports and Cultural Services

General Terms and Conditions for Online Sales of TomTom Inc ( TomTom )

TERMS and CONDITIONS OF USE - NextSTEPS TM

Licensed software: DayPilot Pro for ASP.NET WebForms, including source and binary form and documentation ( the Work ).

KAWASAKI MOTORS CORP., U.S.A. WEBSITE LINKING AGREEMENT

How To Use Merrimack Web Site

PLEASE CAREFULLY REVIEW THESE TERMS AND CONDITIONS BEFORE PROCEEDING:

THE TERMS AND CONDITIONS OF FUTURE LINK AUTOMATED OFFSITE BACKUP SERVICE

TRIAL AGREEMENT FOR QUALIANCE

Transcription:

Cloud Computing Legal issues Patrick Van Eecke Partner, DLA Piper Brussels Professor Universiteit Antwerpen

Cloud computing & the law Infrastructure as a Service Data storage e.g. Amazon S3 Platform as a Service Application development e.g. Google App Engine Software as a Service Applications e.g. Zoho.com Legal impact?

Cloud computing: legal challenges Liability Applicable law Compliance Data protection Copyright Data portability

Current EU legal framework DLA Piper

1. Personal data protection

Privacy and data protection Applicable laws EU Directive 95/46/EC National transpositions e.g., the Belgian Act of 8 December 1992 Adopted in pre-internet area, when centralised and limited processing was the rule EU rules are substantially more restrictive than rules from other countries (particularly US) 6

Privacy and data protection Cloud computing exposes the age, formality and complex application of the current laws Many legal issues are not yet resolved Reform of the current rules in the pipeline, but not for tomorrow Three examples of problems: Who is controller? Which law is applicable? Transfer outside of EU? 7

Data controllers and data processors Legislation makes fundamental distinction between: data controller: party that defines the purpose and the means of the processing data processor: dumb performer Distinction is crucial to know who is responsible Data controller is liable towards the data subjects Data controller must choose appropriate data processors, and must seek adequate contractual protection from them 8

Data protection issues in the cloud Severe issues when applied in cloud computing context: both customer and particularly the hosting provider define the means of the processing statutory assumption that the controller is entirely in control of the processing cloud computing is all about reducing the level of direct control, while EU legislation is all about keeping control of data what about sub-processors? 9

Applicable data protection law An EU Member State s national law will apply when: establishment of EU-based controller located in its territory processes personal data controller outside EU uses equipment within territory Applied to cloud computing: using EU-based data centre = becoming subject to the very strict EU data protection rules? most authorities interpret equipment in an extremely broad way (even browser cookies) 10

Transfer of data outside EU Principle: no transfer of data to countries outside the EU that do not offer an adequate level of protection only Switzerland, Argentinia and Canada Exceptions: ask permission from every data subject involved if transfer is necessary to execute contract with the data subjects for US: subscribing to safe harbour list Binding Corporate Rules European Commission s model agreement 11

Transfer of data outside EU In practice: only use cloud provider with data centre within EU e.g. Amazon EC2: choice of location (US East, US West or Ireland) or make sure that model agreement is concluded with the cloud provider 12

2. Contracting issues

Small contract, big liability? Cloud computing services offer low barrier to entry and easy scaling possibilities click-wrap agreements are legally enforceable! Many publicly available cloud computing contracts limit liability of hosting provider to a level that is not in line with the potential risk Cloud computing contracts resemble typical software licenses, although potential risk is much higher 14

Example We and our licensors shall not be responsible for any service interruptions, including, without limitation, power outages, system failures or other interruptions, including those that affect the receipt, processing, acceptance, completion or settlement of any payment services. (...) Neither we nor any of our licensors shall be liable to you for any direct, indirect, incidental, special, consequential or exemplary damages, including, but not limited to, damages for loss of profits, goodwill, use, data or other losses (...) 15

Other contractual issues Vendor lock-in There is no general legal requirement for a vendor to provide you with data export facilities. Everything depends on your contractual agreement. Unilateral termination possibilities Cloud provider often reserves the right to unilaterally terminate its service provision Involvement of multiple parties no single point of contact 16

Other contractual issues Auditing requirements many contracts impose auditing possibilities that include physical inspection how can these auditing requirements be complied with when geographically decentralised cloud services are used? Applicable law & competent court if outside own country, any litigation can become prohibitively expensive What happens in case of bankruptcy of the provider? 17

Service Level Agreement Important in any service contract, crucial in a cloud computing context Points of attention: How is the availability calculated by the provider? e.g. 10 outages of 6 minutes versus 1 outage of 1 hour Independent measurement of performance? Are service credits the sole remedy? 18

3. Liability for illegal data

Liability of cloud provider for illegal content In many jurisdictions, cloud providers can be held liable for the illegal data they may be hosting ecommerce Directive (2000/31/EC) introduced special liability protection for hosting providers: no liability for services that consist of the storage of electronic information under the condition that the provider has no knowledge or awareness of illegal nature......and removes or blocks illegal data when it does gain knowledge or become aware of illegal nature ( notice and takedown ) 20

Liability of cloud provider for illegal content Issues: special protection is focused on storage, and does not take into account processing activities significant amount of (particularly French) case law does not offer protection when services do not consist exclusively of storage activities liability protection does not prevent so-called injunctions, which can be as costly and timeconsuming no standard notice-and-takedown procedure Reform in the pipeline? 21

4. Compliance issues

Compliance issues IaS Data retention obligations Tax related storage requirements Labour law related storage requirements etc. SaaS electronic invoicing legislation ecommerce legislation electronic signature legislation etc.

Contact patrick.van.eecke@dlapiper.com