4 ms·
Absolutely. And I'd like to strengthen the point you made even further. It's not just standard practice alone - it's the law. For example, from principle 8 of
by summerdown2 11y ago
Absolutely.
And I'd like to strengthen the point you made even further. It's not just standard practice alone - it's the law. For example, from principle 8 of the data protection act:
Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
In my experience (with retail and banks), this means either hosting the data in a place where the law is the same (the EEA or acceptable countries), putting data under contract (EU Model contract), or using an acceptable scheme (such as US safe harbour).
At the moment, companies get around it as you said, by putting into the contract that the hosting has to be in the EU. However, if the US government win this court case, a lot of UK businesses will legally have to reconsider their use of US cloud companies at all.
- tzs 11y agoHow does this work for data that has nothing to do with people in the EU? For instance, suppose I only have US customers, and I have my data primarily in Amazon's cloud in the US West region. I want to have a backup someplace far away from US West. Does the data protection act mean that I cannot use EU Ireland or EU Frankfurt for my backup, because if I ever had to restore from that backup I would be transferring it to a country or territory outside the EEA that does not ensure adequate protection?