28
2020 with the CJEU largely following the advice of the Advocate General
i.e. that model clauses should not be invalidated and that reliance on such
clauses requires firms undertake additional measures to assure compliance.
However, the CJEU, somewhat unexpectantly, decided to examine and
rule the EU-U.S. Privacy Shield framework invalid thus requiring organisations relying on this mechanism to urgently consider and put in place
alternatives.
2.4.2
Service Level Agreements and Limitation of Liability
The SLA outlines the CSP’s commitments on availability, reliability, and
performance levels for the specific cloud service contracted. These are
typically presented as quantifiable targets for the standard of service, how
such targets are calculated, mechanisms for auditing service delivery, and
the level and procedure for compensation in the event of underperformance (Leimbach et al. 2014). The exclusions in SLAs can be quite
broad and typically include an amount of scheduled downtime per annum
(e.g. for maintenance) but also factors outside of the CSP’s immediate
control. Again, these are rarely negotiable on the grounds that the traditional cloud computing business model is based on multi-tenancy and
commoditisation; negotiation is only available for those with significant
bargaining power (Weber and Staiger 2014; Hon et al. 2012).
CSPs, reflecting a general practice in the wider IT industry, attempt to
minimise their liability for any loss—direct, indirect, or consequential—
that may arise from the provision of the service. In cloud computing,
indemnities and liabilities are usually related to privacy and security
breaches and resulting data loss, data misuse and associated regulatory
penalties, but may also include service interruptions or outages, or otherwise failing to meet agreed service levels (Hon and Millard 2018; Leimbach
et al. 2014; Bradshaw et al. 2013). It should be noted that CSPs, typically
attempt to compensate, where possible, for underperformance through
service credits. Obviously, this goes to the heart of trust, particularly where
critical systems have been outsourced to a CSP. Trust literature suggests
that trust repair is more effective when complemented with substantive
actions including admission of fault and penance signals (Bachmann et al.
2015). However, in practice, it may be more nuanced. Where a cloud
service is unavailable and business is adversely impacted, service credits for
the same service are unlikely to be desirable or adequate compensation.
Furthermore, CSPs will often seek to exclude a wide range of
T. LYNN
2020 with the CJEU largely following the advice of the Advocate General
i.e. that model clauses should not be invalidated and that reliance on such
clauses requires firms undertake additional measures to assure compliance.
However, the CJEU, somewhat unexpectantly, decided to examine and
rule the EU-U.S. Privacy Shield framework invalid thus requiring organisations relying on this mechanism to urgently consider and put in place
alternatives.
2.4.2
Service Level Agreements and Limitation of Liability
The SLA outlines the CSP’s commitments on availability, reliability, and
performance levels for the specific cloud service contracted. These are
typically presented as quantifiable targets for the standard of service, how
such targets are calculated, mechanisms for auditing service delivery, and
the level and procedure for compensation in the event of underperformance (Leimbach et al. 2014). The exclusions in SLAs can be quite
broad and typically include an amount of scheduled downtime per annum
(e.g. for maintenance) but also factors outside of the CSP’s immediate
control. Again, these are rarely negotiable on the grounds that the traditional cloud computing business model is based on multi-tenancy and
commoditisation; negotiation is only available for those with significant
bargaining power (Weber and Staiger 2014; Hon et al. 2012).
CSPs, reflecting a general practice in the wider IT industry, attempt to
minimise their liability for any loss—direct, indirect, or consequential—
that may arise from the provision of the service. In cloud computing,
indemnities and liabilities are usually related to privacy and security
breaches and resulting data loss, data misuse and associated regulatory
penalties, but may also include service interruptions or outages, or otherwise failing to meet agreed service levels (Hon and Millard 2018; Leimbach
et al. 2014; Bradshaw et al. 2013). It should be noted that CSPs, typically
attempt to compensate, where possible, for underperformance through
service credits. Obviously, this goes to the heart of trust, particularly where
critical systems have been outsourced to a CSP. Trust literature suggests
that trust repair is more effective when complemented with substantive
actions including admission of fault and penance signals (Bachmann et al.
2015). However, in practice, it may be more nuanced. Where a cloud
service is unavailable and business is adversely impacted, service credits for
the same service are unlikely to be desirable or adequate compensation.
Furthermore, CSPs will often seek to exclude a wide range of
T. LYNN
