44
Keywords Cloud computing • Data privacy • Data protection • Data
localisation • Data residency • Digital sovereignty
3.1
IntroductIon
Over the past decade, the right to privacy and the protection of personal
data have been increasingly recognised as fundamental values at global
level (Greenleaf 2019; Bygrave 2014; Solove 2008). Yet, their understanding still varies significantly among jurisdictions. One apparent example is offered by the different approach to data privacy in the European
Union (EU) and the United States (US). In Europe, data protection is a
constitutionalised fundamental right, and a comprehensive set of legislation has been put in place to make the regulation of personal data processing uniform across member states. Conversely, in the US, data privacy is
not explicitly enshrined in the federal constitution, and is regulated only in
selected pieces of legislation targeting specific sectors considered worthy
of intervention.
Divergence in legal frameworks of data protection is certainly not a
novelty of the last decade. However, the recent development of borderless
digital technologies, such as cloud computing, amplifies the risk of tensions between different regulatory models. When data are stored in the
cloud, it becomes more difficult to identify the applicable law easily. In
response to this phenomenon, data localisation initiatives requiring data to
be physically stored in servers located within national boundaries have
recently emerged as a regulatory trend to avoid conflicts of law, enhance
the level of data privacy protection, limit the risk of access from foreign
intelligence agencies, and facilitate domestic law enforcement.
This chapter investigates this twofold dynamic by focusing on the current friction between the EU data protection approach and the US data
privacy model in the context of cloud computing. The chapter is structured as follows. In Sect. 4.2, we discuss the main areas of divergence
between EU and US approach to data privacy. Then, in Sect. 4.3 we
explain how these differences create a series of regulatory challenges in the
context of cloud computing. Section 4.4 analyses how recent legal and
policy developments on both sides of the Atlantic are addressing these
issues, with a particular focus on data localisation initiatives and strategies
to preserve digital sovereignty. The chapter concludes with the
E. CELESTE AND F. FABBRINI
Précédent

- 62/166

Suivant