Questions to ask about a cloud service. enter



Similar documents
XIT CLOUD SOLUTIONS LIMITED

CLOUD COMPUTING FOR SMALL- AND MEDIUM-SIZED ENTERPRISES:

Annex 1. Contract Checklist for Cloud-Based Genomic Research Version 1.0, 21 July 2015

Cloud Computing: Legal Risks and Best Practices

Making the leap to the cloud: IS my data private and secure?

Clevertar Privacy Policy

Cloud computing. Advantages and disadvantages

Cloud Computing: Privacy and Other Risks

Website Hosting General Terms and Service Levels for Web Hosting and E- Mail

Cloud Computing Contracts. October 11, 2012

Licence Fee means the fees calculated as set out on the Website or such other fee as is agreed between You and the Supplier from time to time.

Better protection for customers, and recurring revenue for you!

The use of this website is subject to the following terms of use:

Contact person responsible for these disclosure statements can be contacted via the following address: Uli Knapp,

Type of Personal Data We Collect and How We Use It

Social Media. Scope. Computer Use Employee Code of Conduct Privacy Emergency Management Plan Communications Strategy Community Engagement Strategy

Privacy and Cloud Computing for Australian Government Agencies

FISHER & PAYKEL PRIVACY POLICY

Data Protection Act Bring your own device (BYOD)

HIPAA Enforcement. Emily Prehm, J.D. Office for Civil Rights U.S. Department of Health and Human Services. December 18, 2013

Quorum Privacy Policy

Considerations for Outsourcing Records Storage to the Cloud

IT asset disposal for organisations

Cloud Computing and Records Management

How To Know If A Cloud Service Is Right For You

How To Choose A Cloud Computing Solution

3 What Personal Information do we collect and why do we need it?

Cloud Services Agreement & SLA

The Use of Cloud Computing for the Storing and Accessing of Client Information: Some Practical and Ethical Considerations

ADRI. Advice on managing the recordkeeping risks associated with cloud computing. ADRI v1.0

HIPAA/HITECH Compliance Using VMware vcloud Air

DISASTER RECOVERY WITH AWS

PROFESSIONAL INDEMNITY RENEWAL DECLARATION IMPORTANT INFORMATION: PLEASE READ THE FOLLOWING INFORMATION BEFORE COMPLETING THIS RENEWAL DECLARATION

Service Schedule for CLOUD SERVICES

HOSTING SERVICES ADDENDUM TO MASTER SOFTWARE LICENCE AGREEMENT

Data Protection Breach Management Policy

NOS for IT User and Application Specialist. IT Security (ESKITU04) November 2014 V1.0

Health Information Privacy Refresher Training. March 2013

Daltrak Building Services Pty Ltd ABN: Privacy Policy Manual

HTTPS Inspection with Cisco CWS

HRIS and Payroll System Administrator

Cyber, Security and Privacy Questionnaire

Data Protection Act Guidance on the use of cloud computing

How To Use A Minicloud Server On An Ovh Cloud (For Free) For A Long Time

Is online backup right for your business? Eight reasons to consider protecting your data with a hybrid backup solution

FAQ Answers to frequently asked questions relating to the security, protection and redundancy of images stored in the Eclipse Data Center

PUBLIC & PRODUCTS LIABILITY PROPOSAL FORM IMPORTANT INFORMATION: PLEASE READ THE FOLLOWING INFORMATION BEFORE COMPLETING THIS PROPOSAL

City of Houston HITS Cloud Strategy and Body Worn Camera Project. Tina Carkhuff CIO/Interim Director

Trends in Cloud Computing in Higher Education

Our Customer Relationship Agreement HOSTING & DOMAINS SERVICE DESCRIPTION

LAN/WAN TECHNICAL SUPPORT Level 1

Bring Your Own Device (BYOD)

Terms and conditions for Small Business Hosting

PUBLIC & PRODUCTS LIABILITY PROPOSAL FORM IMPORTANT INFORMATION: PLEASE READ THE FOLLOWING INFORMATION BEFORE COMPLETING THIS PROPOSAL

Cbeyond Cloud Server Packages

Backup & Disaster Recovery

CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING

2.1 It is an offence under UK law to transmit, receive or store certain types of files.

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist

OCR s Anatomy: HIPAA Breaches, Investigations, and Enforcement

Mortgage & Finance Brokers Professional Indemnity Insurance

What is Cloud-Based Security? Cloud-based Security = Security Management + Cloud Computing.

Fact sheet: Duties of directors of a company limited by guarantee

GENOA, a QoL HEALTHCARE COMPANY, LLC WEBSITE PRIVACY POLICY

BRITISH COUNCIL DATA PROTECTION CODE FOR PARTNERS AND SUPPLIERS

Terms and Conditions Website Development

Service Level Agreement SAN Storage

Document Control. Version Control. Sunbeam House Services Policy Document. Data Breach Management Policy. Effective Date: 01 October 2014

ailexpert MailExpert Security form

PRIVACY POLICY. Last updated February 2, 2009 INTRODUCTION

Jeff M. Bauman, Psy.D. P.A. and Associates FLORIDA-HIPAA PRIVACY NOTICE FORM

Transcription:

Questions to ask about a cloud service enter

How should this guide be used? This guide provides a list of questions you may wish to consider about a cloud service you are considering or already using. Not all the questions will be of relevance or interest to you. As a consumer you may wish to identify and explore the questions of most relevance to assist you in evaluating a cloud service. Many of these questions you can already answer for yourself by researching a cloud service online and reading the terms and conditions. There are some questions you may wish to discuss with the cloud provider. Overall, these questions are intended to help you better understand and evaluate whether a cloud service meets your needs and help you compare between different services 2

Ownership of and access to your data Data ownership is an important consideration. Creating, uploading, or accessing information in a cloud does not necessarily equate with legal ownership. It is important that you understand data ownership and access arrangements before entering into an agreement. It may also be important for you to understand how to obtain a copy of your data from a cloud service provider once the agreement ends. Q: Does the cloud provider claim any ownership of data it stores? Q: How can I get a copy of my data at the end of an agreement? How long do I have to get a copy of this data? In what format will the data be provided? Q: Is all of my data deleted once our agreement ends? Are there any circumstances where I would be denied access to my data? 3

Location of data storage and backup Cloud service providers may store data on a number of servers, locally or offshore. Understanding broadly where data is located can help you assess the risks and benefits. Knowing if and how often data is backed up can help you understand how this compares to alternative back-up options. Q: Where (Country/State) is my data being stored? Q: Is my data being backed up? If yes, where and how often? 4

Privacy and data breaches Some cloud services store your data in multiple countries. It is important to understand whether your data is shared with third parties, and what happens if your data is breached. If you are storing your customer s details in a cloud-based service, it will also be important for you to have assurance that you are meeting any obligations you have under the Privacy Act 1988. For more information on privacy and cloud computing please see the small business factsheet on Privacy Considerations in the Cloud. Q: Does the cloud provider comply with Australian privacy laws? Q: Under what circumstances would the cloud provider access my data or disclose information to a third party? Q: Will I be notified if my data has been lost, breached or its security compromised? What arrangements are in place to secure my data? Will I be compensated if my data is compromised? 5

Staying flexible and being able to change providers Service level and complaint handling The ability to move data and switch providers is an important consideration for consumers of cloud services. Cloud service providers may use different technologies to create, store and process information. You should seek to understand what options are available to transfer your data to a new provider, or recover your data in a usable format. Q: What options are available to transfer my data? In what format can I get a copy of my data at the end of our agreement? Q: What tools are available for copying or transferring my data? Will I be charged if I withdraw my data? Cloud service providers and their products may vary in the support they provide and the service level they offer. Understanding your cloud service provider s service level and support arrangements can assist you in matching a service to meet your business needs. Q: Will I be notified about service outages? If yes, how will I be notified? Q: What service-level agreement does the cloud provider offer? Will I or my customers be compensated for periods of service downtime? Q: How can I contact the cloud provider if an issue arises? What are their customer support hours? 6

Fees and charges Further information As with all communication and utility services it is important to understand what fees and charges apply in order to avoid bill shock. In particular, it may be useful to ask about any potential excess or hidden fees and the triggers for those fees. Q: Are there any additional fees or excess charges? What are they and when are they triggered? Cloud service providers, just like any other business, are covered by Australian consumer protection and privacy legislation. For further information about your rights and responsibilities as a cloud consumer consumer please see Legal Tips for Small Business using Cloud Services. Q: In what circumstances can would a cloud provider change the terms and conditions of their service? Will I be notified about the change before it comes into effect? 7

Disclaimer: This document provides factual information only and is not business or legal advice. You should seek professional advice before taking any action based on its contents. back to start