48
2016). Nevertheless, recently, a new legal challenge was made against the
EU-US Privacy Shield and in July 2020 the ECJ declared also this instrument invalid for breach of EU data privacy law. (Case C-311/18, Data
Protection Commissioner v Facebook Ireland Limited, Maximilian Schrems).
In its ruling, the ECJ emphasized the same problem as in Schrems I: the
level of protection of EU data in the US is still contested.
The Schrems I and Schrems II cases both represent examples of circumstances in which the EU and US data protection frameworks enter in conflict. This situation arises when transnational processing of data is involved,
and is highly problematic both from a EU and US perspective. On the one
hand, EU data protection law imposes limits to the free transfer of personal data to third countries that are not deemed to offer an adequate level
of protection of personal data. On the other hand, US authorities are loath
of bending their sovereign decisions to EU requests in the field of data
privacy as a result of the so-called Brussels effect (Bradford 2012). As the
next section will explain, cloud computing, by ordinarily involving transborder data processing, represents a particularly challenging area.
3.3 regulatIng Borderless cloud comPutIng
Cloud computing denotes “flexible, location-independent access to computing resources that are quickly and seamlessly allocated or released in
response to demand” (Hon et al. 2011a, p. 6). This broad definition
encompasses three models of cloud computing: Infrastructure as a Service
(IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
These models, as is apparent from their denomination, differ on the basis
of the service offered, spanning from the mere provision of infrastructure
to the supply of software (Hon et al. 2011a). These paradigms, however,
are not mutually exclusive. It is conversely possible that a cloud computing
service is composed of infrastructure, platform or service layers at the same
time (Hon et al. 2011a). Just to mention some familiar examples in the
academic context, Dropbox, the Google apps and Microsoft 365 represent commonly used Software as a Service cloud computing services.
A further classification of cloud computing models takes into account
their users: one can distinguish between public, private or hybrid cloud
computing models (Esayas 2012; see also Varadi et al. 2012). In the first
case, cloud computing services are available to the general public, an
example being the social network Facebook; in the second case, their use
is restricted to a limited number of users, such as in tailored cloud services
E. CELESTE AND F. FABBRINI
2016). Nevertheless, recently, a new legal challenge was made against the
EU-US Privacy Shield and in July 2020 the ECJ declared also this instrument invalid for breach of EU data privacy law. (Case C-311/18, Data
Protection Commissioner v Facebook Ireland Limited, Maximilian Schrems).
In its ruling, the ECJ emphasized the same problem as in Schrems I: the
level of protection of EU data in the US is still contested.
The Schrems I and Schrems II cases both represent examples of circumstances in which the EU and US data protection frameworks enter in conflict. This situation arises when transnational processing of data is involved,
and is highly problematic both from a EU and US perspective. On the one
hand, EU data protection law imposes limits to the free transfer of personal data to third countries that are not deemed to offer an adequate level
of protection of personal data. On the other hand, US authorities are loath
of bending their sovereign decisions to EU requests in the field of data
privacy as a result of the so-called Brussels effect (Bradford 2012). As the
next section will explain, cloud computing, by ordinarily involving transborder data processing, represents a particularly challenging area.
3.3 regulatIng Borderless cloud comPutIng
Cloud computing denotes “flexible, location-independent access to computing resources that are quickly and seamlessly allocated or released in
response to demand” (Hon et al. 2011a, p. 6). This broad definition
encompasses three models of cloud computing: Infrastructure as a Service
(IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
These models, as is apparent from their denomination, differ on the basis
of the service offered, spanning from the mere provision of infrastructure
to the supply of software (Hon et al. 2011a). These paradigms, however,
are not mutually exclusive. It is conversely possible that a cloud computing
service is composed of infrastructure, platform or service layers at the same
time (Hon et al. 2011a). Just to mention some familiar examples in the
academic context, Dropbox, the Google apps and Microsoft 365 represent commonly used Software as a Service cloud computing services.
A further classification of cloud computing models takes into account
their users: one can distinguish between public, private or hybrid cloud
computing models (Esayas 2012; see also Varadi et al. 2012). In the first
case, cloud computing services are available to the general public, an
example being the social network Facebook; in the second case, their use
is restricted to a limited number of users, such as in tailored cloud services
E. CELESTE AND F. FABBRINI
