Le Lézard
Classified in: Science and technology
Subjects: NPT, PSF

Cloud Security Alliance Issues New Code of Conduct for GDPR Compliance


Significant updates provide actionable guidance to reflect new European personal protection obligations

EDINBURGH, Scotland, Nov. 21, 2017 /PRNewswire/ -- The Cloud Security Alliance (CSA), the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today released the CSA Code of Conduct for GDPR Compliance, which provides cloud service providers (CSPs), cloud customers, and potential customers with much-needed guidance in order to comply with the new obligations stemming from the European General Data Protection Regulation (GDPR). As part of this release, the CSA has also launched the CSA GDPR Resource Center, a new, community-driven website with tools and resources to help educate cloud service providers and enterprises on the new European data protection regulation.

Cloud Security Alliance Logo. (PRNewsFoto/Cloud Security Alliance)

 

 

"Companies worldwide are struggling to keep pace with shifting regulations affecting personal data protection. The Privacy Level Agreement (PLA) Working Group realized it was critical for cloud providers to have guidance that would enable them to achieve compliance with EU personal data protection legislation," said Francoise Gilbert, CSA Lead Outside Counsel and PLA Working Group co-chair.

"With the introduction of GDPR, data protection compliance becomes increasingly risk-based. Data controllers and processors are accountable for determining and implementing within their organizations appropriate protection levels for the personal data they process," noted Paolo Balboni, European ICT, privacy and data protection lawyer, and co-chair of the Privacy Level Agreement Working Group. "In this scenario, the CSA Code of Conduct for GDPR Compliance is of fundamental importance as it gives guidance for legal compliance and the necessary transparency on the level of data protection offered by the CSPs."

The CSA Code of Conduct for GDPR Compliance is designed to meet both actual, mandatory EU legal personal data protection requirements (i.e., Directive 95/46/EC and its implementations in the EU member states) and the forthcoming requirements of the GDPR.

More precisely, the CSA Code of Conduct for GDPR Compliance specifies the application of the GDPR in the cloud environment, primarily with regard to the following categories:

Additionally, the CSA Code of Conduct for GDPR Compliance contains mechanisms that enable the body referred to in Article 41 (1) GDPR to carry out mandatory compliance monitoring by the controllers or processors who undertake to apply it, without prejudice to the tasks and powers of competent supervisory authorities pursuant to Article 55 or 56 of GDPR.

"The CSA Code of Conduct for GDPR Compliance offers cloud customers a tool to evaluate the level of personal data protection offered by different CSPs and make informed decisions on how they will secure that data," said Daniele Catteddu, Chief Technology Officer, CSA. "We are extremely proud of the work that went into this latest iteration."

The CSA PLA Working Group was formed in 2012 to help transpose the Art. 29 WP and EU National Data Protection Regulators' recommendations on cloud computing into an easy-to-use outline for CSPs to follow when disclosing personal data-handling practices. The scope and objective of the PLA initiative was previously presented to the European Parliament as part of discussions on the potential effect of the proposed General Data Protection Regulation on cloud computing. Since then, the PLA Working Group has been engaged in defining a structured method for communicating the level of privacy that a CSP agrees to maintain.

The PLA Working Group is comprised of independent privacy and data protection subject matter experts, privacy officers, and representatives from data protection authorities.

The CSA Code of Conduct for GDPR Compliance is free and available at: https://gdpr.cloudsecurityalliance.org/resource/csa-code-of-conduct-for-gdpr-compliance/.

For access to the CSA GDPR Resource Center, visit https://gdpr.cloudsecurityalliance.org/.

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA's activities, knowledge and extensive network benefit the entire community impacted by cloud ? from providers and customers, to governments, entrepreneurs and the assurance industry ? and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

Logo - https://mma.prnewswire.com/media/608374/CLOUD_SECURITY_ALLIANCE_LOGO.jpg

 


These press releases may also interest you

at 10:25
Aulos Bioscience, an immuno-oncology company working to revolutionize cancer care through the development of potentially best-in-class IL-2 therapeutics, today announced that updated Phase 1/2 data for AU-007 will be presented at the American Society...

at 10:23
D2L Inc. ("D2L" or the "Company"), a global learning technology company, has released its second Sustainability Report. The report highlights progress D2L has made over the past year, including implementing an ethical approach to artificial...

at 10:20
Precigen, Inc. , a biopharmaceutical company specializing in the development of innovative gene and cell therapies to improve the lives of patients, today announced clinical data from the pivotal Phase 2 study of PRGN-2012 AdenoVerse immunotherapy...

at 10:20
The two poster presentations will report -first combination data from the Phase 1/2a study with BI-1808 in combination with MSD's anti-PD-1 therapy, KEYTRUDA® (pembrolizumab), as well as an update on monotherapy armcombination data from the...

at 10:15
It's nearly Small Business Week and T-Mobile is going big for small business customers with deals starting April 25! T-Mobile is launching Business Unlimited Edge and new small business customers that add at least 10 or more lines can get up to a...

at 10:15
Sheppard, Mullin, Richter & Hampton LLP is pleased to announce that Kwan-Ho "Alex" Chung, Ph.D. has joined the firm's Intellectual Property practice group and Life Sciences industry team in Washington, D.C. Chung was most recently a partner at...



News published on and distributed by: