50
define its scope of application. The idea of linking the applicability of EU
data protection law to the physical use of an equipment no longer corresponded to the technological reality (Hon et  al. 2012; Esayas 2012;
Christopher Kuner 2010). The GDPR now regulates data controllers who
are not established in the EU, but offer goods or services in the EU or
monitor the behaviour of European data subjects (Article 3 GDPR).
However, the GDPR has not substantially modified the data transfer
regime involving third countries. Therefore, data controllers should still
ensure that, when using cloud computing services, European data are not
transferred to third countries which do not guarantee an adequate level of
protection, or without appropriate safeguards (Hon and Millard 2012).
The existence of these regulatory obstacles to the free flow of personal
data from the EU to third countries has led cloud computing providers to
offer services storing personal data on servers exclusively located in the
EU (Hon and Millard 2012). EU data protection law has been one of the
main drivers behind the creation of “regional” clouds besides cross-border
ones (Svantesson and Clarke 2010). A tension therefore emerges between,
on the one hand, the economic and technological dimensions that push
towards the offer of cloud computing services on a global scale in order to
maximise efficiency and minimise costs, and, on the other hand, regulatory and policy initiatives that conversely impose boundaries and de facto
limit the free flow of data for privacy rights reasons. Since the main cloud
computing providers are based in the US and, as pointed out above, the
EU and US are adopting different approaches in relation to data privacy,
this situation raises several challenges. The next section will examine a
series of initiatives that are emerging on both sides of the Atlantic to
address these problems.
3.4 data localIsatIon and dIgItal sovereIgnty
Over the past few years, data localisation—which is the requirement to
store data in servers located within a given jurisdiction—has also emerged
as a regulatory trend at global level (Mishra 2015; Selby 2017). To mention a successful example, in 2014 Russia introduced a statute requiring
citizens’ personal data to be stored in the national territory (Hon et al.
2016; Selby 2017). The objectives of these kinds of legislation are disparate. Safeguarding data privacy and ensuring effective law enforcement at
domestic level are the two most recurrent explicit justifications of these
initiatives (Mishra 2015; Hon et  al. 2016). The timing of this
E. CELESTE AND F. FABBRINI
Précédent

- 68/166

Suivant