49
for corporations or institutions; lastly, the third case represents an intermediary solution.
Using computing resources which are available in “the cloud” is advantageous for a series of reasons (Hon et al. 2011a; Esayas 2012). First of all,
cloud computing can provide services which are tailored to the end user.
Secondly, cloud computing can flexibly respond to changes in users’
demand. And lastly, but certainly not least, cloud computing is significantly cheaper than developing and maintaining individually owned infrastructure, platforms or software. Those resources are centralised, and
thanks to their virtual character, they are shared according to the specific
needs of potential users.
From a technical perspective, this is possible thanks to the so-called
“sharding” (Hon et al. 2011a). Data are not concentrated in a single virtual cloud, but are fragmented into a series of “shards”, replicated, and
stored in different locations. This procedure, which is entirely automated,
allows the cloud computing service to maximise its performance. On the
one hand, smaller pieces of information can be accessed more quickly. On
the other hand, their replication enhances the security of the system by
reducing the risks of node failures or data loss.
The technical architecture of cloud computing creates a series of challenges from a data protection perspective. First of all, cloud computing
providers may be unaware of the fact that they are processing personal
data. Hon et al. talk of the “cloud of unknowing” (2011a, p. 1). Secondly,
the multi-layered structure of cloud computing services may create issues
in relation to the correct identification of the data controller and processor, and the consequent allocation of responsibilities. For example, it has
been contended that cloud service providers merely offering infrastructure
as a service can even hardly be considered as data processors (Hon et al.
2011b). Thirdly, cloud computing models may involve a continuous
transfer of data on a global scale, and therefore potentially interesting a
multiplicity of states. The “sharding” procedure, on which cloud computing relies, partitions and transfers data automatically.
The introduction of the GDPR has removed a series of jurisdictional
problems existing under the Data Protection Directive. The GDPR is
immediately legally binding in all EU member states. As a consequence, at
least if the transfer occurs within the EU, the data controller will have one
single legislative reference point instead of multiple different domestic
pieces of legislation. Moreover, the GDPR has eliminated the reference to
the use of equipment situated in an EU member state as a criterion to
3 COMPETING JURISDICTIONS: DATA PRIVACY ACROSS THE BORDERS
Précédent

- 67/166

Suivant