33
computing, such an infringement may be difficult to prove. CSPs make
use of a wide range of proprietary, third party and open source software in
the delivery of their services, and will often attempt to exclude warranties
on IP relating to such software, and particularly open source software
(Hon et al. 2012). At the same time, AUPs will often include infringement of IP as a prohibited activity. Again, software indemnities tend to be
one-sided in cloud contracts favouring the CSP.
Despite persistent rumours that social networking sites and other CSPs
are attempting to claim rights in images loaded on to their systems, recent
research suggests that CSPs do not seek to have copyright assigned to
them but in many cases explicitly acknowledge that the end user retained
the copyright (Michels et al. 2019). The ownership of metadata is less
clear. Metadata is data about data and is often a by-product generated
from the interaction of the clients and their end users with the cloud service. In this way, new data (which may be of value and therefore be an
intangible asset) is created by the cooperation of the client, or their end
users, and the CSP. While some data is used for cloud service optimisation,
other data may be collected with no specific purpose in mind. This data,
sometimes referred to as ‘exhaust data’ or ‘digital data exhaust’, may have
significant value to third parties through data mining, aggregation or
other data analytics techniques. Reed (2010) suggests that data generated
by the CSP for its own internal purposes belongs to them, however if the
data contains client data protected under copyright, the client may have an
infringement claim—if the client is aware of such use at all. Reed (2010)
suggests CSPs need to pay careful attention that they do not take unfair
advantage of clients nor infringe copyrighted works. But what of digital
data exhaust? Who owns this data? CSPs are typically silent on this. Indeed,
it may be a case of ‘don’t ask, don’t tell’. Nonetheless, contracts should
state clearly whether such data is being collected and for what use.
Hon et al. (2012) identify similar issues relating to the ownership of
software applications developed by clients or end users on a CSP’s IaaS or
PaaS platform where the CSPs integration tools are used or the software is
designed for specific use only with that CSP’s software, and is therefore
tied to the CSP’s IP. The emergence of cloud service brokerage (CSB)
models, and in particular consumer app marketplaces (e.g. Google Play
and Apple AppStore), B2B cloud application and API marketplaces (e.g.
Salesforce AppExchange and RapidAPI), and indeed Marketplace as a
Service models (Paulsson et al. 2016; Paulsson et al. 2020), complicate
these matters further. In these cases, independent software vendors build
2 DEAR CLOUD, I THINK WE HAVE TRUST ISSUES: CLOUD COMPUTING…
computing, such an infringement may be difficult to prove. CSPs make
use of a wide range of proprietary, third party and open source software in
the delivery of their services, and will often attempt to exclude warranties
on IP relating to such software, and particularly open source software
(Hon et al. 2012). At the same time, AUPs will often include infringement of IP as a prohibited activity. Again, software indemnities tend to be
one-sided in cloud contracts favouring the CSP.
Despite persistent rumours that social networking sites and other CSPs
are attempting to claim rights in images loaded on to their systems, recent
research suggests that CSPs do not seek to have copyright assigned to
them but in many cases explicitly acknowledge that the end user retained
the copyright (Michels et al. 2019). The ownership of metadata is less
clear. Metadata is data about data and is often a by-product generated
from the interaction of the clients and their end users with the cloud service. In this way, new data (which may be of value and therefore be an
intangible asset) is created by the cooperation of the client, or their end
users, and the CSP. While some data is used for cloud service optimisation,
other data may be collected with no specific purpose in mind. This data,
sometimes referred to as ‘exhaust data’ or ‘digital data exhaust’, may have
significant value to third parties through data mining, aggregation or
other data analytics techniques. Reed (2010) suggests that data generated
by the CSP for its own internal purposes belongs to them, however if the
data contains client data protected under copyright, the client may have an
infringement claim—if the client is aware of such use at all. Reed (2010)
suggests CSPs need to pay careful attention that they do not take unfair
advantage of clients nor infringe copyrighted works. But what of digital
data exhaust? Who owns this data? CSPs are typically silent on this. Indeed,
it may be a case of ‘don’t ask, don’t tell’. Nonetheless, contracts should
state clearly whether such data is being collected and for what use.
Hon et al. (2012) identify similar issues relating to the ownership of
software applications developed by clients or end users on a CSP’s IaaS or
PaaS platform where the CSPs integration tools are used or the software is
designed for specific use only with that CSP’s software, and is therefore
tied to the CSP’s IP. The emergence of cloud service brokerage (CSB)
models, and in particular consumer app marketplaces (e.g. Google Play
and Apple AppStore), B2B cloud application and API marketplaces (e.g.
Salesforce AppExchange and RapidAPI), and indeed Marketplace as a
Service models (Paulsson et al. 2016; Paulsson et al. 2020), complicate
these matters further. In these cases, independent software vendors build
2 DEAR CLOUD, I THINK WE HAVE TRUST ISSUES: CLOUD COMPUTING…
