Cloud computing is the provision of IT resources such as storage, computing power or software over the internet by an external provider.
Data protection classification
Where a cloud provider processes personal data on behalf of a customer, this is generally processing on behalf of a controller. A data processing agreement is then required, and the customer must check whether the provider offers sufficient guarantees of data security.
Responsibility for the lawfulness of the processing remains with the customer. The provider's certifications and audit reports make it easier to provide evidence.
Third-country aspects
If the provider or a sub-processor is based outside the EU or the EEA, or if access from there is possible, the rules on third-country transfers also apply. For US providers, it is particularly important whether they are certified under the EU-U.S. Data Privacy Framework or whether standard contractual clauses are used.
Legal provisions
- Art. 28 GDPR
- Processing on behalf of a controller and contractual obligations.
- Art. 32 GDPR
- Security of processing.
- Arts. 44 to 46 GDPR
- Conditions for transfers to third countries.