This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here

 

Where your cloud resides matters

20 Apr 2010

View Comments
A Computing logo

Geographic location plays a significant role in establishing data protection obligations in the cloud. And while many cloud services originated within the US, growing demand, global competition, and practical business models drive vendor proliferation of cloud services hosted across diverse geographic locations.

Unfortunately, conversations with end users and vendors suggest many organizations simply aren’t aware of where their cloud data centers reside. This naive lack of information can be quite risky when the location of the data centre triggers a number of privacy and data security requirements that, if not met, may just land you in jail, facing a stiff fine, or at the very least, navigating cumbersome compliance requirements.

Forrester’s research, Infrastructure-As-A-Service (IaaS) Clouds Are Local And So Are Their Implications, sheds some light on the impact of geographic location and provides a working map of today’s Public IaaS data center locations. This initial footprint is likely to change as demand continues to expand and I&O professional are well advised to track just where their data center exists in the cloud to understand how country specific regulations may impact business.

To help you grasp the varying scope of regulatory requirements at a high level, we’ve also created an interactive privacy heat map that denotes the degree of strictness — highlighting scope of protection, affected entities, ‘adequacy’ standards met, and heavily surveilled countries — across national data protection regulation.

Remember, pay attention to where your data centre will reside in the cloud. Country specific regulations governing privacy and data protection vary greatly, and can have an effect on data transfers, choice of security safeguards, and the rights of the data subjects.

James Staten is principal analyst with Forrester Research serving infrastructure & operations professionals. He blogs at http://blogs.forrester.com/james_staten.


Reader comments

blog comments powered by Disqus

Newsletters

Does Google know too much about you?

Google's linked data policy, which came into effect on March 1, allows the company to collect information about its users across all its products, services and websites and store it in one place. This has been criticised by organisations ranging from CNIL to Microsoft, all of whom have expressed concerns that it's difficult to tell which data Google collects and how it's used. Now the Information Commissioner's Office is investigating whether Google's privacy policy is compliant with UK law. Are you worried that Google knows too much about you?

41 %

5 %

15 %

39 %