27
2.4 common chaLLenGes and Issues In GeneraL
cLoud computInG contracts
2.4.1
Choice of Law
By definition, cloud computing is a distributed model. Data can be, and
most likely will be, stored and processed across multiple data centres,
potentially in different jurisdictions, and even where stored and processed
in one jurisdiction, may be transferred across borders and accessed in different jurisdictions. It is possible that the provider and the end user are
unaware of where the data is processed. For enterprise clients, the TOS
increasingly allow data residency in a specific region; a region may be a
country or a larger area such as the European Union. While consumer
cloud users may not have that choice, with the transposition of the General
Data Protection Regulation (Directive 95/46/EC) (GDPR), CSPs typically store European data within the EU for compliance reasons.
Notwithstanding this, a recent survey of 322 cloud TOS and privacy policies, suggested that 267 CSPs indicated that the US was the preferred
jurisdiction, and specifically Californian law (Martic 2017).
Chapter 3 will discuss jurisdictional issues in greater detail, however it is
important to highlight that choice of law can favour one side or the other
in a cloud contract. For example, EU law does not allow the exclusion or
limitation of liability to the same extent that US law might, and similarly
the GDPR introduces significant responsibilities and penalties on data controllers and processors. Courts will consider a number of factors when
deciding on the actual jurisdiction for a cloud contract including: (1) the
choice of law in the TOS; (2) the nature and quality of the CSP’s commercial activity in the jurisdiction; (3) whether the CSP is actively aware that
they are making sales to client resident in a particular jurisdiction; (4) the
jurisdiction that clients are resident or domiciled in; (5) the location where
the cloud service is consumed; (6) the location whether the data is stored
and processed; (7) the location of the CSP’s offices; and (8) whether the
CSP markets or solicits business in a given jurisdiction. If the answer to one
or more of these questions is affirmative, a court may enforce jurisdiction.
In Europe, CSPs and enterprise clients often seek to use and rely on
standard contract clauses, so-called EU model clauses, to manage data
transfer outside the EU. However the applicability of these have been
challenged in the recent case of Data Protection Commissioner v Facebook
Ireland (Schrems II). The judgment for this case was delivered in July
2 DEAR CLOUD, I THINK WE HAVE TRUST ISSUES: CLOUD COMPUTING…
2.4 common chaLLenGes and Issues In GeneraL
cLoud computInG contracts
2.4.1
Choice of Law
By definition, cloud computing is a distributed model. Data can be, and
most likely will be, stored and processed across multiple data centres,
potentially in different jurisdictions, and even where stored and processed
in one jurisdiction, may be transferred across borders and accessed in different jurisdictions. It is possible that the provider and the end user are
unaware of where the data is processed. For enterprise clients, the TOS
increasingly allow data residency in a specific region; a region may be a
country or a larger area such as the European Union. While consumer
cloud users may not have that choice, with the transposition of the General
Data Protection Regulation (Directive 95/46/EC) (GDPR), CSPs typically store European data within the EU for compliance reasons.
Notwithstanding this, a recent survey of 322 cloud TOS and privacy policies, suggested that 267 CSPs indicated that the US was the preferred
jurisdiction, and specifically Californian law (Martic 2017).
Chapter 3 will discuss jurisdictional issues in greater detail, however it is
important to highlight that choice of law can favour one side or the other
in a cloud contract. For example, EU law does not allow the exclusion or
limitation of liability to the same extent that US law might, and similarly
the GDPR introduces significant responsibilities and penalties on data controllers and processors. Courts will consider a number of factors when
deciding on the actual jurisdiction for a cloud contract including: (1) the
choice of law in the TOS; (2) the nature and quality of the CSP’s commercial activity in the jurisdiction; (3) whether the CSP is actively aware that
they are making sales to client resident in a particular jurisdiction; (4) the
jurisdiction that clients are resident or domiciled in; (5) the location where
the cloud service is consumed; (6) the location whether the data is stored
and processed; (7) the location of the CSP’s offices; and (8) whether the
CSP markets or solicits business in a given jurisdiction. If the answer to one
or more of these questions is affirmative, a court may enforce jurisdiction.
In Europe, CSPs and enterprise clients often seek to use and rely on
standard contract clauses, so-called EU model clauses, to manage data
transfer outside the EU. However the applicability of these have been
challenged in the recent case of Data Protection Commissioner v Facebook
Ireland (Schrems II). The judgment for this case was delivered in July
2 DEAR CLOUD, I THINK WE HAVE TRUST ISSUES: CLOUD COMPUTING…
