86
• IaaS—the CSP is responsible for the implementation and management of privacy controls only within the physical infrastructure. The
CSC is responsible for all other aspects of privacy.
• PaaS—the CSP is responsible for IaaS. However, CSCs and CSPs are
jointly responsible for ensuring appropriate privacy controls are
implemented within the applications deployed on the PaaS
environment.
• SaaS—the CSC has limited control over privacy and security. CSCs
will generally maintain responsibility for managing identity and
access management controls to ensure minimum permissions are
assigned to roles. The CSP is responsible for ensuring all other privacy controls are in place.
As a CSC moves from on-premise models to cloud service models, they
lose control over their data, including control over the privacy of that data.
Although the shared responsibilities model assumes a level of transparency
and control for the CSC, CSPs have traditionally lacked transparency
regarding their privacy policies, strategy, service, thresholds etc. making it
difficult for CSCs to objectively perform evaluations and risk assessments
for a CSP service (Cruzes and Jaatun 2015). The implementation of ethical principles such as those in FIPPs not only mitigate the key privacy risks
associated with cloud computing (Pearson 2009) but also offer the CSP
an opportunity to rebalance the control-justice equilibrium for the CSC.
Many CSPs including Amazon, Microsoft, and IBM do offer simple
breakdowns of performance metrics and responsibilities etc. However,
some CSPs (e.g. SAAS model CSPs such as Salesforce or Workday) do not
clearly define these sufficiently (Prüfer 2018). In a recent survey of IT
decision makers (Netapp 2016) 35% believed responsibility for data sits
with the CSPs, while 3% did not know who would be responsible. GDPR
is very clear that responsibility for personal data lies firmly with the data
controller (GDPR, Article 24). Under GDPR, the CSC is responsible
(regardless of cloud computing model) for ensuring their own compliance
requirements are handled effectively by the CSP and ensuring these
requirements are adequately reflected in legally binding contractual agreements (called Data Processing Agreements, or DPAs) with the
CSP. However, if a CSP is not transparent for instance, about which core
IT services they themselves outsource to sub-processors, the CSC is unable
to properly evaluate risks. In some cases, it may be difficult for the CSC (in
its role as data controller) to assess the adequacy of the CSP’s data
V. LYONS
Précédent

- 104/166

Suivant