Le Lézard
Classified in: Science and technology
Subjects: NPT, PSF

Cloud Security Alliance Issues New Code of Conduct for GDPR Compliance


EDINBURGH, Scotland, Nov. 21, 2017 /PRNewswire-USNewswire/ -- The Cloud Security Alliance (CSA), the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today released the CSA Code of Conduct for GDPR Compliance, which provides cloud service providers (CSPs), cloud customers, and potential customers with much-needed guidance in order to comply with the new obligations stemming from the European General Data Protection Regulation (GDPR). As part of this release, the CSA has also launched the CSA GDPR Resource Center, a new, community-driven website with tools and resources to help educate cloud service providers and enterprises on the new European data protection regulation.

Cloud Security Alliance Logo. (PRNewsFoto/Cloud Security Alliance)

"Companies worldwide are struggling to keep pace with shifting regulations affecting personal data protection. The Privacy Level Agreement (PLA) Working Group realized it was critical for cloud providers to have guidance that would enable them to achieve compliance with EU personal data protection legislation," said Francoise Gilbert, CSA Lead Outside Counsel and PLA Working Group co-chair.

"With the introduction of GDPR, data protection compliance becomes increasingly risk-based. Data controllers and processors are accountable for determining and implementing within their organizations appropriate protection levels for the personal data they process," noted Paolo Balboni, European ICT, privacy and data protection lawyer, and co-chair of the Privacy Level Agreement Working Group. "In this scenario, the CSA Code of Conduct for GDPR Compliance is of fundamental importance as it gives guidance for legal compliance and the necessary transparency on the level of data protection offered by the CSPs."

The CSA Code of Conduct for GDPR Compliance is designed to meet both actual, mandatory EU legal personal data protection requirements (i.e., Directive 95/46/EC and its implementations in the EU member states) and the forthcoming requirements of the GDPR.

More precisely, the CSA Code of Conduct for GDPR Compliance specifies the application of the GDPR in the cloud environment, primarily with regard to the following categories:

Additionally, the CSA Code of Conduct for GDPR Compliance contains mechanisms that enable the body referred to in Article 41 (1) GDPR to carry out mandatory compliance monitoring by the controllers or processors who undertake to apply it, without prejudice to the tasks and powers of competent supervisory authorities pursuant to Article 55 or 56 of GDPR.

"The CSA Code of Conduct for GDPR Compliance offers cloud customers a tool to evaluate the level of personal data protection offered by different CSPs and make informed decisions on how they will secure that data," said Daniele Catteddu, Chief Technology Officer, CSA. "We are extremely proud of the work that went into this latest iteration."

The CSA PLA Working Group was formed in 2012 to help transpose the Art. 29 WP and EU National Data Protection Regulators' recommendations on cloud computing into an easy-to-use outline for CSPs to follow when disclosing personal data-handling practices. The scope and objective of the PLA initiative was previously presented to the European Parliament as part of discussions on the potential effect of the proposed General Data Protection Regulation on cloud computing. Since then, the PLA Working Group has been engaged in defining a structured method for communicating the level of privacy that a CSP agrees to maintain.

The PLA Working Group is comprised of independent privacy and data protection subject matter experts, privacy officers, and representatives from data protection authorities.

The CSA Code of Conduct for GDPR Compliance is free and available at: https://gdpr.cloudsecurityalliance.org/resource/csa-code-of-conduct-for-gdpr-compliance/.

For access to the CSA GDPR Resource Center, visit https://gdpr.cloudsecurityalliance.org/.

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA's activities, knowledge and extensive network benefit the entire community impacted by cloud ? from providers and customers, to governments, entrepreneurs and the assurance industry ? and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

SOURCE Cloud Security Alliance


These press releases may also interest you

at 02:45
ASE Technology Holding Co., Ltd. (TWSE: 3711, NYSE: ASX) ("We", "ASEH", or the "Company"), the leading provider of semiconductor assembly and testing services ("ATM") and the provider of electronic manufacturing services ("EMS"), today reported its...

at 02:30
Allied Market Research published a report, titled, "Pension Administration Software Market by Component (Solution and Services), Deployment Mode (On-Premise and Cloud), Type (Public Pension and Private Pension), End User (Employers, Pension Plan...

at 02:22
Swedish Orphan Biovitrum AB (publ) (Sobi®) today announced its report for the first quarter 2024 First Quarter 2024 Total revenue increased 19 per cent, 20 per cent at constant exchange rates, (CER)1, to SEK 6,256 M (5,239)Haematology revenue...

at 02:08
Homestyler, a leading all-in-one 3D Design platform and creative community for global designers invested by Easyhome New Retail Group and Alibaba Group, successfully hosted the Homestyler Global Partners Conference and Gorgeous Home Imported Brand...

at 02:05
AstraZeneca: Revenue and EPS summary     Q1 2024 % Change $m Actual CER1 - Product Sales 12,177 15 18 - Alliance Revenue   457 59 59...

at 02:00
ICEYE, a global leader in satellite-powered disaster management solutions, has announced a new data collaboration with Juniper Re, LLC ("Juniper Re"), the dynamic reinsurance broking arm and indirect subsidiary of BRP Group, Inc. . Juniper Re will...



News published on and distributed by: