How GDPR changes the game for cloud service providers

The effect on businesses of the European General Data Protection Regulation (GDPR) has been widely discussed in recent months, but what has received less attention is the impact of the new laws on cloud platforms.
When GDPR comes into force on May 25, it will require organisations holding personal data to enforce privacy principles. As well as data stored internally, this requirement will cover any external parties that might share or process the data on the organisation’s behalf. Cloud providers fall squarely into this category.
So, what steps does a business using cloud platforms need to take to ensure they can meet the new requirements? How can they be sure they will be able to comply before the May deadline?
Many organisations are of the belief that responsibility for data stored on a cloud platforms rests with the service provider. Indeed, a Vanson Bourne 2017 study commissioned by Veritas found that global business and IT decision makers wrongfully believe data protection, data privacy and compliance are the responsibility of the cloud service provider.
Companies are grappling with GDPR compliance during a time of rising security concerns following some recent massive data breaches such as Equifax and Alteryx/Experian that reinforce the importance of data accountability. Under GDPR, data responsibility sits firmly with the data controller – the organisation that collects the personal data in the first instance and then cascades across the other stakeholders when they process it.
A knee-jerk reaction to this might be to avoid using cloud storage for personal data and turn to on-premise storage instead. Some might opt to adopt a hybrid architecture where non-sensitive data is held on a cloud platform and personal data on in-house servers.
Other organisations might instead consider the cloud to be the most effective and secure way to meet the challenges of new data privacy legislation. However, they will then need to be more thorough in their cloud procurement process, to make sure both parties understand the risks, responsibilities, and requirements that need to be fulfilled.
Some organisations might not even have the ability to proactively choose between the two strategies to their legacy systems. According to the Cloud Industry Forum, an average European company is effectively using 608 cloud apps, but due to shadow IT, is underestimating this number by 90%. A similar situation could well exist in other regions.
Making sure that all the cloud applications that hold personal data are referenced becomes the first and foremost challenge.


