Skip to main content

Cloud Security and Privacy in the Light of the 2012 EU Data Protection Regulation

  • Conference paper
Cloud Computing (CloudComp 2012)

Abstract

The essential characteristics of cloud computing such as elasticity or broad network access provide many economic benefits for their users, but with these benefits also many security and privacy risks come along. These risks can be generally classified into legal and technical risks. The upcoming general data protection regulation by the European Commission (COM (2012) 11) strengthens the consumer’s rights with changes like a single set of European rules and more data protection obligations for organizations. Once the general data protection regulation becomes effective, organizations will have to fulfill more requirements to comply with the law, especially in situations of security breaches or issues about the life cycle and the processing of data. In this paper we describe a framework for the evaluation of cloud service providers in regard to the upcoming EU data protection regulation. The framework shall help service providers to comply with the new regulation, and shall enable consumers to evaluate the security and privacy competencies of cloud service providers.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 49.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. The NIST Definition of Cloud Computing - SP 800-145, National Institute of Standards and Technology (2011), http://csrc.nist.gov/publications/nistpubs/800-145/SP800-145.pdf

  2. Proposal for a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), European Commission, http://ec.europa.eu/justice/data-protection/document/review2012/com_2012_11_en.pdf

  3. Security Guidance for Critical Areas of Focus in Cloud Computing V3.0, Cloud Security Alliance (2011), https://cloudsecurityalliance.org/guidance/csaguide.v3.0.pdf

  4. Nimis, J., Tai, S., Baun, C., Kunzem, M.: Cloud Computing: Web-basierte dynamische ITServices. Springer, Heidelberg (2011)

    Google Scholar 

  5. Technology Research, Gartner Inc., http://www.gartner.com/technology/home.jsp

  6. National Institute of Standards and Technology (NIST), http://www.nist.gov/index.html

  7. Cloud Security Alliance (CSA), https://cloudsecurityalliance.org/

  8. Securing Europe‘s Information Society (ENISA), http://www.enisa.europa.eu/

  9. Guidelines on Security and Privacy in Public Cloud Computing - SP 800-144, National Institute of Standards and Technology (2011), http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf

  10. Commission proposes a comprehensive reform of the data protection rules, European Commission, http://ec.europa.eu/justice/newsroom/data-protection/news/120125_en.htm

  11. Australian Government (Department of Defense), Cloud Computing Security Considerations, http://www.dsd.gov.au/infosec/cloudsecurity.htm

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2013 ICST Institute for Computer Science, Social Informatics and Telecommunications Engineering

About this paper

Cite this paper

Kronabeter, A., Fenz, S. (2013). Cloud Security and Privacy in the Light of the 2012 EU Data Protection Regulation. In: Yousif, M., Schubert, L. (eds) Cloud Computing. CloudComp 2012. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, vol 112. Springer, Cham. https://doi.org/10.1007/978-3-319-03874-2_12

Download citation

  • DOI: https://doi.org/10.1007/978-3-319-03874-2_12

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-319-03873-5

  • Online ISBN: 978-3-319-03874-2

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics