30
“Looking at Clouds from both Sides” – Risks and Benefits of Cloud Computing Employment and Labour Law Conference May 24, 2012 Tamara Hunter

Risks and Benefits of Cloud Computing

Embed Size (px)

Citation preview

Page 1: Risks and Benefits of Cloud Computing

“Looking at Clouds from both Sides” – Risks and Benefits of Cloud Computing

Employment and Labour Law Conference

May 24, 2012

Tamara Hunter

Page 2: Risks and Benefits of Cloud Computing

What is Cloud Computing?

Page 3: Risks and Benefits of Cloud Computing

What is cloud computing?

• technologies that provide computation, software, data access and storage services that do not require end-user knowledge of the physical location and configuration of the system that delivers the services (Wikipedia)

• delivered over a network (typically, the Internet)

Page 4: Risks and Benefits of Cloud Computing

Categories

• Infrastructure as a Service (“IaaS”) and Storage• Delivers computer infrastructure, along with storage and

networking

• Software as a Service (“Saas”)• Delivers software without the need to install and run

applications

• Platform as a Service (“PaaS”)• Allows the development and deployment of applications

without the need to purchase specific hardware or software

Page 5: Risks and Benefits of Cloud Computing

Benefits

• Cost• Scalability• User mobility• Customizability• Reliability? • Performance?• Security?

Page 6: Risks and Benefits of Cloud Computing

Cloud Computing: General Issues and Risks

Page 7: Risks and Benefits of Cloud Computing

General Issues and Risks

• Location and jurisdiction

• Data ownership

• Business interruption (service provider)

• Loss of access (customer)

Page 8: Risks and Benefits of Cloud Computing

General Issues and Risks

• Source code and escrow

• Migration

• Who can access?

• Backup and archiving

Page 9: Risks and Benefits of Cloud Computing

General Issues and Risks

• Security

• Destruction of data

• IP infringement

Page 10: Risks and Benefits of Cloud Computing

Cloud Computing:Litigation (E-Discovery)

Page 11: Risks and Benefits of Cloud Computing

Key Obligations

• Disclosure• must disclose every relevant document in possession,

control or power

• “document” is broadly defined

• Preservation• must preserve all relevant documents

• Serious consequences for breach

Page 12: Risks and Benefits of Cloud Computing

E-Discovery

• Electronic documents increase scope, complexity and cost of discovery process

• Courts aware of importance of electronic documents

Page 13: Risks and Benefits of Cloud Computing

Cloud Computing and Discovery

• Disclosure and preservation obligations still apply

• Court does not care if you store data in your building or in the cloud – only cares whether you have possession or control

Page 14: Risks and Benefits of Cloud Computing

Cloud Computing and Discovery

• Consider risks:

• lost data• non-compliant data preservation practices• platform not easily searched• sub-outsourcing

Page 15: Risks and Benefits of Cloud Computing

Cloud Computing and Discovery

• Cloud computing contract is key• Maintain legal control over data• Due diligence on cloud provider• Ability to retrieve data in any circumstance

Page 16: Risks and Benefits of Cloud Computing

Cloud Computing: Privacy Law Compliance

Page 17: Risks and Benefits of Cloud Computing

• When you think about Cloud Computing, consider it as “mega-outsourcing”

Page 18: Risks and Benefits of Cloud Computing

• Regular outsourcing is when you store your data on your own servers, but you send certain data to an outside service provider or a service, so they can perform a function with the data and provide a product (e.g. send personalized cheques to your customers or process your payroll and arrange for direct deposits for your employees).

Page 19: Risks and Benefits of Cloud Computing

• Cloud computing means you don’t have your own servers anymore – you’ve “out-sourced” that whole infrastructure

Page 20: Risks and Benefits of Cloud Computing

• The key privacy law compliance issue is security of personal information

Page 21: Risks and Benefits of Cloud Computing

• Geographic location of personal information is a significant privacy law issue, especially for public bodies in British Columbia (and service providers to public bodies) but the concern with geographical location of data really boils down to a security issue

Page 22: Risks and Benefits of Cloud Computing

Public Bodies in B.C.:  Section 30.1 of FOIPPA

• A public body must ensure that personal information in its custody or under its control is stored only in Canada and accessed only in Canada, [unless a specific exception applies]

• Breach of s. 30.1 of FOIPPA is an offence• Some cloud service providers are aware of this

requirement and offer cloud services that meet this requirement

Page 23: Risks and Benefits of Cloud Computing

Québec – Private Sector Privacy Legislation

• If using service provider outside Québec to store or process personal information, must take all reasonable steps to ensure that the personal information will not be used for purposes not relevant to the object of the file or communicated to third persons without consent

• If cannot be satisfied that the personal information will be properly protected, must not communicate the information outside Québec (s. 17)

Page 24: Risks and Benefits of Cloud Computing

• What about professionals (e.g., doctors, lawyers, accountants, etc.) and businesses handling highly sensitive personal information (e.g. banks, credit unions, insurance companies)?

• Ethical and contractual obligations around confidentiality may also require specialized cloud computing solutions

• Community Cloud or Private Cloud may work (e.g. Law Society Cloud for lawyers is being considered)

Page 25: Risks and Benefits of Cloud Computing

• Private Sector - still have obligation under PIPEDA, PIPA, the Québec Private Sector Privacy Legislation (and, possibly, contractual obligations) to make reasonable security arrangements to protect personal information from risks such as unauthorized access, disclosure, destruction, etc.

• Standard Cloud Computing contracts may not sufficiently protect customer/employee personal information

• Requirement for transparency/notification (customers/employees have a right to know)

Page 26: Risks and Benefits of Cloud Computing

Security issues: 

• What geographic locations could be involved?  Rule some out or stipulate acceptable jurisdictions

• Reputation/history of cloud provider• What other data will be mingled with your organization's

data?  Concern re: concentration of high-risk data • Will your organization be able to access audit logs?

Page 27: Risks and Benefits of Cloud Computing

• How quickly could you be required to produce a copy of your organization’s records? will your organization be able to meet that timeframe?

• What obligations does the cloud provider have in the event of an information security breach?• Immediate notification to your organization?• Indemnity for any damages and professional fees?

Page 28: Risks and Benefits of Cloud Computing

• What happens if the cloud provider goes bankrupt? backup/escrow might not be sufficient without access to the application software necessary to decode the stored data

• Does the contract provide for a method for your organization to audit the cloud provider’s compliance with its contractual security obligations?

Page 29: Risks and Benefits of Cloud Computing

• Insurance – does your organization’s insurance coverage for information security breaches or data loss apply if your data is “in the clouds”?

Page 30: Risks and Benefits of Cloud Computing

Thank You

Tamara HunterAssociate Counsel,

Head of Privacy Law Group, Vancouver

[email protected]

604.643.2952