81
with shared use of resources, making privacy incidents difficult to determine and detect (Ren et al. 2012). This was evidenced by a recent case in
2019, when Rubrik, the cloud data management giant, exposed a large
cache of customer information improperly stored in an Amazon
Elasticsearch database (Techcrunch 2019). With the rise in high-profile
privacy incidents, such as Cambridge Analytica in 2018, and Capital One’s
data breach on AWS (Fortune 2019), cloud service customers (CSCs)
have also become more aware of the potential risks associated with the
processing of data outside the traditional on-premise models. There are
additional tensions arising from the costs of detection, prevention and/or
remediation of privacy incidents versus the value that can be derived from
data services (Acquisti 2008; Chen et al. 2012).
Governments, regulators and policymakers respond to such incidents
by enhancing the specificity and stringency of compliance regulation,
however the pace of change in cloud computing and the exponential
growth in data is fast outpacing the legislative lifecycle. Instead of focusing
on regulation as a response, focusing on privacy from a non-regulatory
perspective may yield more sustainable solutions for CSPs to address the
balance of these tensions more effectively. Reflecting this—in this chapter,
we draw on control theories of privacy (Fried 1984; Moor 1997) to
explain how CSPs comply with privacy law and exact power over data and
systems, and we draw on theories of procedural justice (Allan and Tyler
1988) to explain how CSPs can ‘loosen the leash’ to enable the CSC have
more control.
It would be highly complex to map cloud computing issues across the
full panoply of regulatory privacy architectures, such as the California
Consumer Privacy Act (CCPA), the General Data Protection Regulation
(GDPR), the United Nations Declaration of Human Rights (UDHR), the
Health Insurance Portability and Accountability Act (HIPAA) etc.
However, given the broad reach of GDPR (it jurisdictionally applies to all
EU CSPs, and to any non-EU CSP processing data of EU residents, or to
any data processing within an EU territory) and its position as the strongest data protection regime in the world (Consumers-International 2019),
we focus on GDPR in this chapter as the common reference for privacy
regulation.
Applying these concepts of control and justice to privacy, we present a
proposed privacy orientation framework describing the key privacy orientations of CSPs. This framework can help explain different approaches to
privacy, and to understand their implications. Our framework extends
5 JUSTICE VS CONTROL IN CLOUD COMPUTING: A CONCEPTUAL…
with shared use of resources, making privacy incidents difficult to determine and detect (Ren et al. 2012). This was evidenced by a recent case in
2019, when Rubrik, the cloud data management giant, exposed a large
cache of customer information improperly stored in an Amazon
Elasticsearch database (Techcrunch 2019). With the rise in high-profile
privacy incidents, such as Cambridge Analytica in 2018, and Capital One’s
data breach on AWS (Fortune 2019), cloud service customers (CSCs)
have also become more aware of the potential risks associated with the
processing of data outside the traditional on-premise models. There are
additional tensions arising from the costs of detection, prevention and/or
remediation of privacy incidents versus the value that can be derived from
data services (Acquisti 2008; Chen et al. 2012).
Governments, regulators and policymakers respond to such incidents
by enhancing the specificity and stringency of compliance regulation,
however the pace of change in cloud computing and the exponential
growth in data is fast outpacing the legislative lifecycle. Instead of focusing
on regulation as a response, focusing on privacy from a non-regulatory
perspective may yield more sustainable solutions for CSPs to address the
balance of these tensions more effectively. Reflecting this—in this chapter,
we draw on control theories of privacy (Fried 1984; Moor 1997) to
explain how CSPs comply with privacy law and exact power over data and
systems, and we draw on theories of procedural justice (Allan and Tyler
1988) to explain how CSPs can ‘loosen the leash’ to enable the CSC have
more control.
It would be highly complex to map cloud computing issues across the
full panoply of regulatory privacy architectures, such as the California
Consumer Privacy Act (CCPA), the General Data Protection Regulation
(GDPR), the United Nations Declaration of Human Rights (UDHR), the
Health Insurance Portability and Accountability Act (HIPAA) etc.
However, given the broad reach of GDPR (it jurisdictionally applies to all
EU CSPs, and to any non-EU CSP processing data of EU residents, or to
any data processing within an EU territory) and its position as the strongest data protection regime in the world (Consumers-International 2019),
we focus on GDPR in this chapter as the common reference for privacy
regulation.
Applying these concepts of control and justice to privacy, we present a
proposed privacy orientation framework describing the key privacy orientations of CSPs. This framework can help explain different approaches to
privacy, and to understand their implications. Our framework extends
5 JUSTICE VS CONTROL IN CLOUD COMPUTING: A CONCEPTUAL…
