87
handling practices to ensure that their data is handled in a lawful way. This
problem is exacerbated in cases of multiple transfers of data e.g. between
federated clouds. This lack of transparency is linked to decreased levels of
trust in the CSP, is a key barrier for the adoption of cloud services (Del
Alamo et al. 2015) and is associated with lack of accountability (Pearson
2009; Haeberlen 2010).
Finally, CSCs often overlook the on-premise privacy measures that traditional applications rely on such as on-premise firewall configurations
that block logins from specific locations (such as embargoed countries),
intrusion prevention systems, behavior analytics platforms (detecting
insider threats), log management and alerting solutions (Oracle 2017).
Since these and other measures protect privacy in applications in the enterprise campus, they are often taken for granted in the context of any one
particular application and the responsibility for their installation and
upkeep falls squarely on the CSC (Oracle 2017).
Alongside issues of transparency, responsibility and accountability,
Abed and Chavan (2019) highlight a number of universal privacy issues
facing CSCs, when considering cloud computing adoption, namely; the
institutional obligation for disclosure (to governments), breach and incident disclosure, data accessibility and retention, and physical storage
location):
• Institutional obligation for disclosure to Governments: Studies have
shown that CSCs considering cloud adoption are concerned that
data outsourced to the CSP can be accessed by others, notably public
authorities with legitimate or illegitimate objectives as well as legal
and illegal private actors (August et al. 2014). For instance in 2018,
the Clarifying Lawful Overseas Use of Data Act (CLOUD Act,
House of Representatives Bill 4943, 2018) enabled law enforcement
agencies to access data processed by US-based companies, regardless
of whether the servers were located in the US.
• Breach and incident disclosure: GDPR mandates that a privacy incident/breach be reported within 72 hours of its discovery. However,
when the privacy incident/breach occurs in the CSP environment, it
is very difficult for the CSC to have transparent discovery and disclosure arrangements in place. The breach disclosure requirements are
defined under Article 28 of the GDPR and need to be incorporated
into the DPA with the CSP. This contract also needs to clearly define
the balance of liability in the event of a data breach.
5 JUSTICE VS CONTROL IN CLOUD COMPUTING: A CONCEPTUAL…
Précédent

- 105/166

Suivant