30
misuse (O’Byrne 2019; Bradshaw et  al. 2011). Common categories of
prohibited activities include:
1. activities that engage in, foster, solicit or promote illegal, abusive or
irresponsible behaviour e.g. fraud, hacking, hosting and distributing
viruses, or abusive, offensive or morally repugnant content e.g. child
pornography, excessive violence, hate speech etc.;
2. high risk use where the failure or fault of the cloud service could
result in death or serious bodily or to physical or environmental
damage e.g. use in air transportation, nuclear or chemical facilities;
3. non-consensual e-mail, advertising, tracking or other uses of personal data e.g. using cloud services to spam third parties with email
or advertising; and
4. abusive or offensive behaviour towards a member of the CSP staff.
This is not an exhaustive list, yet one can see that many of these activities could preclude perfectly legal activities, e.g. healthcare, and many
involve a judgment by the CSP, the basis of which is typically unclear.
AUPs are often neglected by clients yet can result in suspension or termination of end user accounts or indeed the client’s overarching agreement.
Furthermore, CSPs often retain the right to vary the terms of the AUP
independently of the main TOS. For enterprise clients, aligning their AUP
and their CSP’s AUP is critical, otherwise an end user may have an account
terminated by the CSP while the enterprise client is still accountable for
delivering the service (Hon et al. 2012). Ideally, enterprise clients should
negotiate a process that may be more appropriate for their needs, e.g. that
they, the enterprise client, should inform their end users of AUPs, end user
account suspensions, or terminations. Hon et al. (2012) note that such
negotiations would seem to be the exception rather than the rule.
2.4.4 Data Protection and Privacy Policies
Issues relating to data protection and privacy can be found in the TOS,
SLA, AUP and, of course, the privacy policy. It is worth noting that the
privacy policy often primarily relates to CSP collection and use of
personally- identifiable data. Chapters 3, 4, and 5 discuss data protection
and privacy in much greater detail, however three contractual aspects are
worthy of note, namely data protection, data integrity and data availability.
CSPs are required to comply with data protection regulations. Under
the GDPR, CSPs are typically “data processors” but may be “data
T. LYNN
Précédent

- 48/166

Suivant