Data protection and security with cloud providers
Cloud and Data protection according to "Schrems II”; does that even make sense anymore? Yes, as long as certain rules are followed, it’s still possible. What exactly needs to be taken into account in the area of „data protection—Cloud“—provider," as this blog post briefly outlines.
„Schrems II“ and the New Standard Contractual Clauses
With the "Schrems II judgment", the European Court of Justice ruled that the GDPR also applies in cases where, for reasons of national security, a country’s authorities or intelligence agencies may gain access to the data. This applies to the United States, the home country of the major Cloud-provider, and is diametrically opposed to the fundamental principle of data protection.
A first step toward solving the problem is to use the data importer Standard contractual clauses to conclude. Data protection, Cloud and GDPR will be merged after all. By implementing decision on 4.6.2021, the EU Commission adopted new Standard contractual clauses published and found that additional measures such as Anonymization or Encryption, provided that the key is held by the data exporter, an effective level of protection can be achieved.
Contents of the new standard contractual clauses
In the new Standard contractual clauses General clauses are combined with a modular approach. This is of interest to companies that prioritize data protection and Data security in the Cloud Module 2: EU Controller to Processor in a Single Market is particularly important. Third country.
In addition to the 18 clauses in total, Annexes I–III must also be taken into account. Among other things, these require a comprehensive and specific description of the data transfer, a detailed description of the data importer’s technical and organizational measures, and a list of any subcontracted processors.
In module 2, the data importer is set to the specifications of the GDPR is obligated. In accordance with its role as a processor, its central obligation to the data exporter is emphasized above all.
Transfer Impact Assessment
One of the central innovations of the new Standard contractual clauses can be found in Clause 14: „Local laws and customs that affect compliance with the clauses.“ There is now a requirement to conduct a „Transfer Impact Assessment,“ that is, a comprehensive, case-by-case Data Protection Impact Assessment. In doing so, the following guiding question must be answered: Can and will the Cloud-The provider (data importer) must comply with its contractually imposed obligations under the GDPR actually comply?
Assessment criteria include the following
- Circumstances of the Transmission, the parties involved, the categories of personal data transferred, the transmission channels used, and the storage location.
- Relevant laws and practices of the third country, in particular those provisions governing the disclosure of data to government authorities and intelligence agencies or their access to personal data allow.
- According to the second sentence of Recital 19 of the Implementing Decision, a Standard contractual clauses The fact that the third country's legislation is contrary to the law does not per se mean that the transfer must not take place. Through Encryption or Anonymization This penalty can be „remedied.“.
And now?
By 27.12.2022, all data transfers must be transferred to a Third countryif no Appropriateness decision or an exemption is available, to the new Standard contractual clauses and supplementary, additional measures. 2B Advice is happy to support you with this challenge. We will help you to GDPR consistently. We support you in this, even in the Cloud, data protection and Data security at all times.





