SlideShare a Scribd company logo
“Looking at Clouds from both Sides” –
Risks and Benefits of Cloud Computing

      Employment and Labour Law Conference
                               May 24, 2012

                              Tamara Hunter
What is Cloud Computing?
What is cloud computing?
•   technologies that provide computation, software,
    data access and storage services that do not require
    end-user knowledge of the physical location and
    configuration of the system that delivers the services
    (Wikipedia)


•   delivered over a network (typically, the Internet)
Categories
•   Infrastructure as a Service (“IaaS”) and Storage
    • Delivers computer infrastructure, along with storage and
        networking

•   Software as a Service (“Saas”)
    • Delivers software without the need to install and run
       applications

•   Platform as a Service (“PaaS”)
    • Allows the development and deployment of applications
       without the need to purchase specific hardware or software
Benefits
•   Cost
•   Scalability
•   User mobility
•   Customizability
•   Reliability?
•   Performance?
•   Security?
Cloud Computing:
General Issues and Risks
General Issues and Risks
•   Location and jurisdiction

•   Data ownership

•   Business interruption (service provider)

•   Loss of access (customer)
General Issues and Risks
•   Source code and escrow

•   Migration

•   Who can access?

•   Backup and archiving
General Issues and Risks
•   Security

•   Destruction of data

•   IP infringement
Cloud Computing:
Litigation (E-Discovery)
Key Obligations
•   Disclosure
    •   must disclose every relevant document in possession,
        control or power
    •   “document” is broadly defined

•   Preservation
    •   must preserve all relevant documents

•   Serious consequences for breach
E-Discovery
•   Electronic documents increase scope, complexity and
    cost of discovery process

•   Courts aware of importance of electronic documents
Cloud Computing and Discovery
•   Disclosure and preservation obligations still apply

•   Court does not care if you store data in your building or
    in the cloud – only cares whether you have possession
    or control
Cloud Computing and Discovery
•   Consider risks:

    •   lost data
    •   non-compliant data preservation practices
    •   platform not easily searched
    •   sub-outsourcing
Cloud Computing and Discovery

•   Cloud computing contract is key
•   Maintain legal control over data
•   Due diligence on cloud provider
•   Ability to retrieve data in any circumstance
Cloud Computing:
Privacy Law Compliance
•   When you think about Cloud Computing, consider it
    as “mega-outsourcing”
•   Regular outsourcing is when you store your data on
    your own servers, but you send certain data to an
    outside service provider or a service, so they can
    perform a function with the data and provide a product
    (e.g. send personalized cheques to your customers or
    process your payroll and arrange for direct deposits for
    your employees).
•   Cloud computing means you don’t have your own
    servers anymore – you’ve “out-sourced” that whole
    infrastructure
•   The key privacy law compliance issue is security of
    personal information
•   Geographic location of personal information is a
    significant privacy law issue, especially for public
    bodies in British Columbia (and service providers to
    public bodies) but the concern with geographical
    location of data really boils down to a security issue
Public Bodies in B.C.: Section 30.1 of FOIPPA

•   A public body must ensure that personal information in
    its custody or under its control is stored only in Canada
    and accessed only in Canada, [unless a specific
    exception applies]
•   Breach of s. 30.1 of FOIPPA is an offence
•   Some cloud service providers are aware of this
    requirement and offer cloud services that meet this
    requirement
Québec – Private Sector Privacy Legislation
•   If using service provider outside Québec to store or
    process personal information, must take all reasonable
    steps to ensure that the personal information will not be
    used for purposes not relevant to the object of the file or
    communicated to third persons without consent
•   If cannot be satisfied that the personal information will
    be properly protected, must not communicate the
    information outside Québec (s. 17)
•   What about professionals (e.g., doctors, lawyers,
    accountants, etc.) and businesses handling highly
    sensitive personal information (e.g. banks, credit unions,
    insurance companies)?

•   Ethical and contractual obligations around confidentiality
    may also require specialized cloud computing solutions

•   Community Cloud or Private Cloud may work (e.g. Law
    Society Cloud for lawyers is being considered)
•   Private Sector - still have obligation under PIPEDA,
    PIPA, the Québec Private Sector Privacy Legislation
    (and, possibly, contractual obligations) to make
    reasonable security arrangements to protect personal
    information from risks such as unauthorized access,
    disclosure, destruction, etc.

•   Standard Cloud Computing contracts may not sufficiently
    protect customer/employee personal information

•   Requirement for transparency/notification
    (customers/employees have a right to know)
Security issues:

•   What geographic locations could be involved? Rule
    some out or stipulate acceptable jurisdictions
•   Reputation/history of cloud provider
•   What other data will be mingled with your organization's
    data? Concern re: concentration of high-risk data
•   Will your organization be able to access audit logs?
•   How quickly could you be required to produce a copy of
    your organization’s records? will your organization be
    able to meet that timeframe?

•   What obligations does the cloud provider have in the
    event of an information security breach?
    • Immediate notification to your organization?
    • Indemnity for any damages and professional fees?
•   What happens if the cloud provider goes bankrupt?
    backup/escrow might not be sufficient without access to
    the application software necessary to decode the stored
    data

•   Does the contract provide for a method for your
    organization to audit the cloud provider’s compliance
    with its contractual security obligations?
•   Insurance – does your organization’s insurance
    coverage for information security breaches or data loss
    apply if your data is “in the clouds”?
Thank You


                         Tamara Hunter
                     Associate Counsel,
  Head of Privacy Law Group, Vancouver
                tamara_hunter@davis.ca
                          604.643.2952

More Related Content

PDF
Cloud computing: Legal and ethical issues in library and information services
PDF
Legal ethics & cloud computing
PDF
MISA Cloud Workshop_ ipc privacy in the cloud
PPT
Cloud computing legal issues
PPS
CloudSecurity
PPT
Cloud security
PPTX
Cloud Computing Security
PPT
Cloud security
Cloud computing: Legal and ethical issues in library and information services
Legal ethics & cloud computing
MISA Cloud Workshop_ ipc privacy in the cloud
Cloud computing legal issues
CloudSecurity
Cloud security
Cloud Computing Security
Cloud security

What's hot (20)

PPTX
IT Series: Cloud Computing Done Right CISOA 2011
PPT
Securing Apps & Data in the Cloud by Spyders & Netskope
PPT
Cloud Computing: Legal Issues and Safety Risks by Brian Miller Solicitor
PPTX
gkknwqeq3232,sqSecurity essentials domain 3
PPT
Legal issues in cloud computing
PDF
Cloud Computing and Security - ISACA Hyderabad Chapter Presentation
PPT
Data security in the cloud
PPTX
Cloud computing security
PPTX
Security Issues in Cloud Computing
PPT
Mining IT Summit Nov 6 2014
PDF
Cloud Computing: legal issues
PDF
Security issue in Cloud computing
PDF
Cloud computing security
PPTX
4.5.cloud security
PDF
Know Your Attacker - Core Security
PPT
UTSpeaks Public Lecture: Clearing up the Cloud -19th July 2011 - Rob Living...
PDF
Security and Audit for Big Data
PPTX
Security challenges of cloud computing
PPTX
Cloud computing & security basics
PPTX
Security in cloud computing
IT Series: Cloud Computing Done Right CISOA 2011
Securing Apps & Data in the Cloud by Spyders & Netskope
Cloud Computing: Legal Issues and Safety Risks by Brian Miller Solicitor
gkknwqeq3232,sqSecurity essentials domain 3
Legal issues in cloud computing
Cloud Computing and Security - ISACA Hyderabad Chapter Presentation
Data security in the cloud
Cloud computing security
Security Issues in Cloud Computing
Mining IT Summit Nov 6 2014
Cloud Computing: legal issues
Security issue in Cloud computing
Cloud computing security
4.5.cloud security
Know Your Attacker - Core Security
UTSpeaks Public Lecture: Clearing up the Cloud -19th July 2011 - Rob Living...
Security and Audit for Big Data
Security challenges of cloud computing
Cloud computing & security basics
Security in cloud computing
Ad

Similar to Risks and Benefits of Cloud Computing (20)

PDF
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
PDF
Legal issues in the cloud renzo marchini & gene landy
PDF
Bird&Bird
PPTX
security_and_privacy_in_cloud_computing (1).pptx
PPTX
Cloud Computing in Business and facts
PPT
Securing Apps and Data in the Cloud - July 23 2014 Toronto Board of Trade
PPTX
Cloud Security: A matter of trust?
PDF
Nfp Seminar Series Danny November 18 Emerging Technology Challenges And...
PPTX
Extending security in the cloud network box - v4
PPTX
The Cloud Computing Contract Playbook: Contracting for Cloud Services
PPT
28_Security-Privacy-inxssudusd_Cloud.ppt
PPT
28_Security-Privacy-in_Cloud_AND_real.ppt
PDF
Cloud Security - Emerging Facets and Frontiers
PPTX
Database systems and cloud computing.pptx
PPT
ICRTITCS-2012 Conference Publication
PPTX
Everyone is talking Cloud - How secure is your data?
PPTX
Security in Cloud Computing
PPT
Security Issues of Cloud Computing
PPTX
Securing Your Digital Files from Legal Threats
PPTX
Unit 9 Technological trends in Information Technology By Sulav Acharya
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
Legal issues in the cloud renzo marchini & gene landy
Bird&Bird
security_and_privacy_in_cloud_computing (1).pptx
Cloud Computing in Business and facts
Securing Apps and Data in the Cloud - July 23 2014 Toronto Board of Trade
Cloud Security: A matter of trust?
Nfp Seminar Series Danny November 18 Emerging Technology Challenges And...
Extending security in the cloud network box - v4
The Cloud Computing Contract Playbook: Contracting for Cloud Services
28_Security-Privacy-inxssudusd_Cloud.ppt
28_Security-Privacy-in_Cloud_AND_real.ppt
Cloud Security - Emerging Facets and Frontiers
Database systems and cloud computing.pptx
ICRTITCS-2012 Conference Publication
Everyone is talking Cloud - How secure is your data?
Security in Cloud Computing
Security Issues of Cloud Computing
Securing Your Digital Files from Legal Threats
Unit 9 Technological trends in Information Technology By Sulav Acharya
Ad

More from DLA Piper (Canada) LLP (20)

PPT
Current Issues in Employment Law
PPT
Consumer Protection: Recent Developments and Trends
PDF
Latest Developments in Advertising and Marketing Law and Their Impact on Cana...
PDF
The Need to Know Legalities of Marketing Sponsorships
PDF
The Importance of Documentation in an Employment Relationship
PDF
Operational Information as "Personal Information"
PDF
Background Checks: The Legality of Reference, Credit, Criminal and Qualificat...
PDF
Anatomy of a Failed Termination Process
PDF
Maternity and Parental Leave: Current Issues
PDF
Mental Health as a Safety Issue in the Workplace
PDF
Disclaimer in Ads - Resting Not Dead?
PDF
Employing Contractors and Contracting Employees
PDF
Breaking Up Is Hard to Do!
PDF
What to Do When Regulators Come A-knocking
PDF
Mitigating Legal Risks and Staying Compliant While Running a Successful Onlin...
PDF
To Disclaim or Not and How? Very Big Questions. A Primer for Marketers
PDF
How to Make Litigation Pay
PDF
Notre ami, Anton Piller (l’ordonnance d’injonction)
PDF
Our Friend, Anton Piller (The Injunction)
PDF
Surveillance of Your Electronic Systems
Current Issues in Employment Law
Consumer Protection: Recent Developments and Trends
Latest Developments in Advertising and Marketing Law and Their Impact on Cana...
The Need to Know Legalities of Marketing Sponsorships
The Importance of Documentation in an Employment Relationship
Operational Information as "Personal Information"
Background Checks: The Legality of Reference, Credit, Criminal and Qualificat...
Anatomy of a Failed Termination Process
Maternity and Parental Leave: Current Issues
Mental Health as a Safety Issue in the Workplace
Disclaimer in Ads - Resting Not Dead?
Employing Contractors and Contracting Employees
Breaking Up Is Hard to Do!
What to Do When Regulators Come A-knocking
Mitigating Legal Risks and Staying Compliant While Running a Successful Onlin...
To Disclaim or Not and How? Very Big Questions. A Primer for Marketers
How to Make Litigation Pay
Notre ami, Anton Piller (l’ordonnance d’injonction)
Our Friend, Anton Piller (The Injunction)
Surveillance of Your Electronic Systems

Recently uploaded (20)

PPTX
MYSQL Presentation for SQL database connectivity
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PDF
Machine learning based COVID-19 study performance prediction
PPT
Teaching material agriculture food technology
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Modernizing your data center with Dell and AMD
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
Cloud computing and distributed systems.
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
MYSQL Presentation for SQL database connectivity
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
Machine learning based COVID-19 study performance prediction
Teaching material agriculture food technology
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
“AI and Expert System Decision Support & Business Intelligence Systems”
Diabetes mellitus diagnosis method based random forest with bat algorithm
Modernizing your data center with Dell and AMD
NewMind AI Weekly Chronicles - August'25 Week I
GamePlan Trading System Review: Professional Trader's Honest Take
20250228 LYD VKU AI Blended-Learning.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
The Rise and Fall of 3GPP – Time for a Sabbatical?
Cloud computing and distributed systems.
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...

Risks and Benefits of Cloud Computing

  • 1. “Looking at Clouds from both Sides” – Risks and Benefits of Cloud Computing Employment and Labour Law Conference May 24, 2012 Tamara Hunter
  • 2. What is Cloud Computing?
  • 3. What is cloud computing? • technologies that provide computation, software, data access and storage services that do not require end-user knowledge of the physical location and configuration of the system that delivers the services (Wikipedia) • delivered over a network (typically, the Internet)
  • 4. Categories • Infrastructure as a Service (“IaaS”) and Storage • Delivers computer infrastructure, along with storage and networking • Software as a Service (“Saas”) • Delivers software without the need to install and run applications • Platform as a Service (“PaaS”) • Allows the development and deployment of applications without the need to purchase specific hardware or software
  • 5. Benefits • Cost • Scalability • User mobility • Customizability • Reliability? • Performance? • Security?
  • 7. General Issues and Risks • Location and jurisdiction • Data ownership • Business interruption (service provider) • Loss of access (customer)
  • 8. General Issues and Risks • Source code and escrow • Migration • Who can access? • Backup and archiving
  • 9. General Issues and Risks • Security • Destruction of data • IP infringement
  • 11. Key Obligations • Disclosure • must disclose every relevant document in possession, control or power • “document” is broadly defined • Preservation • must preserve all relevant documents • Serious consequences for breach
  • 12. E-Discovery • Electronic documents increase scope, complexity and cost of discovery process • Courts aware of importance of electronic documents
  • 13. Cloud Computing and Discovery • Disclosure and preservation obligations still apply • Court does not care if you store data in your building or in the cloud – only cares whether you have possession or control
  • 14. Cloud Computing and Discovery • Consider risks: • lost data • non-compliant data preservation practices • platform not easily searched • sub-outsourcing
  • 15. Cloud Computing and Discovery • Cloud computing contract is key • Maintain legal control over data • Due diligence on cloud provider • Ability to retrieve data in any circumstance
  • 17. When you think about Cloud Computing, consider it as “mega-outsourcing”
  • 18. Regular outsourcing is when you store your data on your own servers, but you send certain data to an outside service provider or a service, so they can perform a function with the data and provide a product (e.g. send personalized cheques to your customers or process your payroll and arrange for direct deposits for your employees).
  • 19. Cloud computing means you don’t have your own servers anymore – you’ve “out-sourced” that whole infrastructure
  • 20. The key privacy law compliance issue is security of personal information
  • 21. Geographic location of personal information is a significant privacy law issue, especially for public bodies in British Columbia (and service providers to public bodies) but the concern with geographical location of data really boils down to a security issue
  • 22. Public Bodies in B.C.: Section 30.1 of FOIPPA • A public body must ensure that personal information in its custody or under its control is stored only in Canada and accessed only in Canada, [unless a specific exception applies] • Breach of s. 30.1 of FOIPPA is an offence • Some cloud service providers are aware of this requirement and offer cloud services that meet this requirement
  • 23. Québec – Private Sector Privacy Legislation • If using service provider outside Québec to store or process personal information, must take all reasonable steps to ensure that the personal information will not be used for purposes not relevant to the object of the file or communicated to third persons without consent • If cannot be satisfied that the personal information will be properly protected, must not communicate the information outside Québec (s. 17)
  • 24. What about professionals (e.g., doctors, lawyers, accountants, etc.) and businesses handling highly sensitive personal information (e.g. banks, credit unions, insurance companies)? • Ethical and contractual obligations around confidentiality may also require specialized cloud computing solutions • Community Cloud or Private Cloud may work (e.g. Law Society Cloud for lawyers is being considered)
  • 25. Private Sector - still have obligation under PIPEDA, PIPA, the Québec Private Sector Privacy Legislation (and, possibly, contractual obligations) to make reasonable security arrangements to protect personal information from risks such as unauthorized access, disclosure, destruction, etc. • Standard Cloud Computing contracts may not sufficiently protect customer/employee personal information • Requirement for transparency/notification (customers/employees have a right to know)
  • 26. Security issues: • What geographic locations could be involved? Rule some out or stipulate acceptable jurisdictions • Reputation/history of cloud provider • What other data will be mingled with your organization's data? Concern re: concentration of high-risk data • Will your organization be able to access audit logs?
  • 27. How quickly could you be required to produce a copy of your organization’s records? will your organization be able to meet that timeframe? • What obligations does the cloud provider have in the event of an information security breach? • Immediate notification to your organization? • Indemnity for any damages and professional fees?
  • 28. What happens if the cloud provider goes bankrupt? backup/escrow might not be sufficient without access to the application software necessary to decode the stored data • Does the contract provide for a method for your organization to audit the cloud provider’s compliance with its contractual security obligations?
  • 29. Insurance – does your organization’s insurance coverage for information security breaches or data loss apply if your data is “in the clouds”?
  • 30. Thank You Tamara Hunter Associate Counsel, Head of Privacy Law Group, Vancouver tamara_hunter@davis.ca 604.643.2952