Google echoes Amazon's assurance on EU data protection compliance

Google echoes Amazon's assurance on EU data protection compliance

Google has joined Amazon Web Services in promising customers of its cloud services that it will be compliant with new European Union data protection r

Tesla Sues Former Worker For Hacking
Tor Project Brings Security Slider Feature to Android App Orfox
P2P Weakness Exposes Millions of IoT Devices

Google has joined Amazon Web Services in promising customers of its cloud services that it will be compliant with new European Union data protection rules due to take effect next year.

Neither company is fully compliant yet, but both have now made public commitments to meet the requirements of the EU General Data Protection Regulation (GDPR) by May 25, 2018, echoing a promise Microsoft made back in February.

The GDPR replaces the 1995 Data Protection Directive. Among its biggest changes are requirements that companies:
– erase personal data on request unless there is a legitimate reason to retain it;
– inform those affected by data breaches, and
– design data protection into their products and services from the earliest stage of development.

It’s not all extra work for businesses: There are some exemptions for small and medium-size businesses (SMEs), and the GDPR’s move to a single set of rules for all of the EU’s 28 (for now) member states puts an end to jurisdiction shopping — litigating privacy cases in the most favorable territory — and makes compliance simpler for companies working across borders.

But some businesses will become liable in ways that they weren’t before: The GDPR applies not just to data controllers — typically those by or for whom the data was collected — but also to data processors, the service providers or middlemen that hold the data or perform the calculations on it. Their customers will want the rights and responsibilities of each party set out clearly before the new rules take effect.

AWS Chief Information Security Officer Stephen Schmidt outlined the company’s progress towards GDPR compliance in a blog post on April 25. “I am happy to announce today that all AWS services will comply with the GDPR when it becomes enforceable,” he wrote.

That surely prompted Wednesday’s blog post from Google Cloud’s director for security, trust and privacy, Suzanne Frey, and its director of data protection and compliance, Marc Crandall. “Google is committed to GDPR compliance across G Suite and Google Cloud Platform (GCP) services when the GDPR takes effect,” they wrote.

But both companies were beaten to the punch by Microsoft Chief Privacy Officer Brendon Lynch. “Microsoft is committing to be GDPR compliant across our cloud services when enforcement begins,” he wrote on Feb. 15 in a blog post about the readiness of services such as Azure, Dynamics 365 and Office 365 for the the new rules.

COMMENTS