{"id":692,"date":"2016-02-19T09:41:57","date_gmt":"2016-02-19T09:41:57","guid":{"rendered":"http:\/\/kb2.host.dbj.systems\/?p=692"},"modified":"2016-02-19T09:41:57","modified_gmt":"2016-02-19T09:41:57","slug":"what-the-end-of-safe-harbor-means-for-eu-companies","status":"publish","type":"post","link":"https:\/\/dbj.systems\/kb\/2016\/02\/19\/what-the-end-of-safe-harbor-means-for-eu-companies\/","title":{"rendered":"What the End of Safe Harbor Means for EU Companies"},"content":{"rendered":"<h1>Using Cloud Services? What the End of Safe Harbor Means for EU Companies<\/h1>\n<div id=\"articleHeader__separator\" class=\"separator\">\u00a0We find <a href=\"http:\/\/techproessentials.com\/using-cloud-services-what-the-end-of-safe-harbor-means-for-eu-companies\/\" target=\"_blank\" rel=\"noopener noreferrer\">this article<\/a> so useful and in he same time important for us and our customers, we have decided to copy it over in a &#8220;text only&#8221; clean form.<\/div>\n<p><!--more--><\/p>\n<div>by <a title=\"Posts by Guest Contributor\" href=\"http:\/\/techproessentials.com\/author\/abgguestcontributor\/\" target=\"_blank\" rel=\"noopener noreferrer\">Guest Contributor<\/a> November 23, 2015 9:00 am<\/div>\n<p><a class=\"readableLinkWithMediumImage\" href=\"https:\/\/i0.wp.com\/techproessentials.com\/wp-content\/uploads\/sites\/19\/2014\/08\/bigstock-Modern-data-center-room-41089753.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright\" src=\"https:\/\/i0.wp.com\/techproessentials.com\/wp-content\/uploads\/sites\/19\/2014\/08\/bigstock-Modern-data-center-room-41089753.jpg?resize=260%2C173\" alt=\"Modern data center room.\" width=\"260\" height=\"173\" \/><\/a>It\u2019s common knowledge that you shouldn\u2019t leave sensitive data open to the public, but companies are willingly handing over private information <a href=\"http:\/\/techproessentials.com\/tag\/cloud\/\" target=\"_blank\" rel=\"noopener noreferrer\">in the cloud<\/a>\u2026even though they know it\u2019s going to be under surveillance by foreign governments.<\/p>\n<p>In fact, <a href=\"http:\/\/www.gartner.com\/newsroom\/id\/1862714\" target=\"_blank\" rel=\"noopener noreferrer\">a report by Gartner<\/a> predicts that by the end of 2016, more than 50 percent of Global 1000 companies will have stored customer-sensitive data <a href=\"http:\/\/www.aberdeen.com\/research\/9921\/kb-cloud-applications\/content.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">in the public cloud<\/a>.<\/p>\n<p>The rationale has always been that if there is a reputable safeguard like the <a href=\"http:\/\/www.export.gov\/safeharbor\/eu\/eg_main_018476.asp\" target=\"_blank\" rel=\"noopener noreferrer\">Safe Harbor Act<\/a>, then any cloud vendor\u00a0must be safe to use, and it\u00a0would never do anything with a customer\u2019s\u00a0information. However, after Edward Snowden\u2019s disclosure of NSA surveillance programs in the United States, the premise of the Safe Harbor Act became complex, especially since it was routinely used by governments for surveillance. The\u00a0<a href=\"http:\/\/www.businessinsider.com\/european-court-of-justice-safe-harbor-ruling-2015-10?r=UK&amp;IR=T\" target=\"_blank\" rel=\"noopener noreferrer\">European Court of Justice\u2019s recent decision<\/a>, though, has made its stance crystal clear: the entire Safe Harbor Act and its validity to protect European Union (EU) citizens\u2019 privacy has been dismissed.<\/p>\n<hr \/>\n<p><em>Guest article by\u00a0Daniel Arthursson, CEO of\u00a0Xcerion and CloudMe<br \/>\n<\/em><\/p>\n<hr \/>\n<p><strong>Repercussions of No Longer Having the Safe Harbor Act<\/strong><\/p>\n<p>The court\u2019s latest move brings up another interesting legal implication. With the current EU Data Protection Directive, every EU company needs to <a href=\"http:\/\/ec.europa.eu\/justice\/data-protection\/data-collection\/obligations\/index_en.htm\" target=\"_blank\" rel=\"noopener noreferrer\">have a legally responsible data controller<\/a>. The data controller is fully accountable for what happens with personal data, even if the data storage, or processing, is outsourced to a third party that later discloses that data.<\/p>\n<p>As processing of data in the U.S. has been deemed insecure since a U.S. company cannot guarantee that a third party won\u2019t be able to access data,\u00a0any use of a U.S. service by an EU company will be a breach of the Data Protection Directive. The repercussion for the data controller in every company using a U.S. cloud service can be imprisonment of up to two years. This can leave anyone\u00a0\u2014\u00a0from an end customer using SaaS services to EU SaaS services running their service on top of a U.S. cloud infrastructure\u00a0\u2014\u00a0predisposed.<\/p>\n<p>The court\u2019s decision has clarified what the legislation really means for EU businesses, but from a legal liability perspective, we are still in the same predicament. Every company\u2019s data controller is liable, including whatever the U.S. Government does once they have handed over the data to a U.S. cloud service. This will likely continue and extend to U.S. entities operating overseas: if you\u00a0use and store information in an EU data center controlled by a U.S. entity that later discloses your company\u2019s personal information to a third party, like the U.S. Government, you will also be liable.<\/p>\n<p><strong>Where Do We Go From Here?<\/strong><\/p>\n<p>As a company\u2019s CEO or data controller, you need to adapt to the current situation in the EU. In reality, there is no way you can negotiate out of the European Data Protection Directive,\u00a0and you cannot shift the liability to a U.S. service provider through any type of agreement, regardless of what your supplier says. You have no more protection against the continued use of U.S. services.<\/p>\n<p>So what\u2019s the definition of personal data, when it comes to what the\u00a0data controller is responsible for? It refers to any data that relates to a living individual who can be identified from that\u00a0data or other data handled by the data controller.<\/p>\n<p>According to Skyhigh\u2019s <a href=\"https:\/\/www.skyhighnetworks.com\/cloud-security-blog\/74-of-cloud-services-do-not-meet-european-data-residency-requirements\/\" target=\"_blank\" rel=\"noopener noreferrer\">2014 Cloud Adoption and Risk in Europe Report<\/a> that looks at cloud service providers used by employees in European organizations, 74.3 percent of the providers did not meet basic security stipulations. This\u00a0means that any organization sending personally identifiable information (PII) to these service providers is breaking the EU Data Protection Directive.<\/p>\n<p>Where do you begin? For starters, review all cloud services your company uses and begin protecting privacy and personal data. Consider the following questions when doing this:<\/p>\n<ol>\n<li>Where is the cloud service provider\u2019s data center, and where is my data stored specifically?<\/li>\n<li>Is any data stored or processed outside of the EU?<\/li>\n<li>Is my company\u2019s European SaaS provider employing a U.S. <a href=\"http:\/\/techproessentials.com\/evolving-the-cloud-at-amazons-aws-reinvent\/\" target=\"_blank\" rel=\"noopener noreferrer\">cloud service like Amazon<\/a> or Microsoft Azure as its platform for running their business?<\/li>\n<li>Who has the controlling stake in the cloud service my company uses, and is it majority controlled by U.S. interests?<\/li>\n<\/ol>\n<p>If the answer to any of the above questions is \u2018Yes,\u2019 then you are liable of breaching the European Data Protection Act if you handle any personal data.<\/p>\n<p>European companies have an enormous challenge ahead, and Europe is missing many crucial services provided by U.S. companies. Many new data centers, cloud infrastructure companies, and SaaS services need to be rebuilt or improved within the EU in order to allow a transition into legal compliance by its companies.<\/p>\n<p>As we look forward, we\u2019ll see a growing demand for European cloud and sync storage services that can meet the demands of EU companies <em>and\u00a0<\/em>abide by the European Data Protection Directive. This move to European data centers will certainly take months to complete \u2014 and a great deal of gray area still remains.<\/p>\n<p>The court\u2019s decision has proved to Europeans that the Safe Harbor Act certainly didn\u2019t protect them. However, the European and U.S. governments still need to determine where exactly this leaves its companies in the wake of the decision.<\/p>\n<hr \/>\n<p><em>During the last 18\u00a0years, Daniel Arthursson has been running cloud-related companies, and has founded CloudMe.com, CloudTop.com, iCloud.com and brands like MyCloud.com. He is an inventor or co-inventor of 16 US patents related around the network operating system, and\u00a0is the CEO of the <a href=\"http:\/\/xcerion.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Xcerion<\/a> and\u00a0<a href=\"https:\/\/www.cloudme.com\/en\" target=\"_blank\" rel=\"noopener noreferrer\">CloudMe<\/a> companies.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The court\u2019s latest move brings up another interesting legal implication. With the current EU Data Protection Directive, every EU company needs to have a legally responsible data controller. The data controller is fully accountable for what happens with personal data, even if the data storage, or processing, is outsourced to a third party that later discloses that data.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[2,3,10,4,5,8,9],"tags":[12,46,57,69,70],"post_folder":[],"class_list":["post-692","post","type-post","status-publish","format-standard","category-cloud","category-compliance","category-industry","category-it","category-market","category-security","category-services","tag-12","tag-microsoft","tag-private-cloud","tag-storage","tag-support","czr-hentry"],"jetpack-related-posts":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/posts\/692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/comments?post=692"}],"version-history":[{"count":0,"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/posts\/692\/revisions"}],"wp:attachment":[{"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/media?parent=692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/categories?post=692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/tags?post=692"},{"taxonomy":"post_folder","embeddable":true,"href":"https:\/\/dbj.systems\/kb\/wp-json\/wp\/v2\/post_folder?post=692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}