New EU Data Protection Laws (GDPR) and Cloud Services
Over the past few days the new EU data protection laws have been passed which will for the first time in 20 years rewrite the requirements and responsibilities of those who store data. It will also give more rights to the users who have data stored. The new General Data Protection Regulation (GDPR) will require many businesses to re-think and rework their current strategies. One area which interested me was in the effect of the GDPR on cloud service providers. I have studied many articles and discusssions and thought I could take the main points and simplify them here. First some terminology Data Controller - The business who actually owns the data Data Processor - The cloud provider The current situation: All of the responsibility of data protection currently lies with the Data Controller. The Data Processor basically facilitates a platform on which the systems run. With the introduction of the GDPR Both the Data Controller and the Data Processo...