SlideShare une entreprise Scribd logo
1  sur  26
Télécharger pour lire hors ligne
19/05/2013
1
New Technologies
& Paradigms,
Old Laws
Kuan Hon
Independent Consultant
PhD Candidate, QMUL
Eduserv Symposium 2013, London 16 May 2013
@kuan∅
Outline
• Introduction
• Cloud
• Open data, big data
19/05/2013
2
@kuan∅
Introduction
• Self
[2 hats 4 clouds 3 weasels]
• Attendees?
@kuan∅
Legal risks of new tech
Risk pyramid
Legal
Reputational
[Public trust] etc etc
19/05/2013
3
@kuan∅
Communication
&
Mindsets
@kuan∅
Technologists
Binary, 1s & 0s
19/05/2013
4
@kuan∅
LawyersLawyers
(Image reproduced by
kind permission of
Firebox.com)
Certainty? Hah!
‘It depends…’
Interpretation
Context
Probabilities
19/05/2013
5
@kuan∅
Skills
For legal (& many other) issues:
Know WHO to ask,
& WHEN,
& WHAT to tell ‘em!
@kuan∅
WHO
Lawyers
19/05/2013
6
@kuan∅
WHEN
ASAP!
@kuan∅
WHAT
Your role
19/05/2013
7
@kuan∅
HOW
Money!
@kuan∅
Cloud
Open data
Big data
19/05/2013
8
@kuan∅
Laws & the internet
@kuan∅
Cloud computing & law
Risk pyramid
Laws
Reputational
[Public trust] etc etc
19/05/2013
9
@kuan∅
Let your lawyer do the
worrying…
@kuan∅
Cloud computing
• Legal risks - brief lawyers on:
– what’s cloud?
•recap
•NB layers
•12 Cs; cf traditional outsourcing
– what do you want to use it for?
•requirements, risk tolerance
User ---- DropBox ---- Amazon
SaaS IaaS
19/05/2013
10
@kuan∅
Cloud legal issues
• Lots! – IP, competition – no time…
– see cloudlegalproject.org + book
• Pre-contract checks + contract
• For public sector:
– government policy
– CloudStore
@kuan∅
Location
19/05/2013
11
@kuan∅
Data location, me & you
• Public sector – Gov ICT Offshoring
(International Sourcing) Guidance -
data location unrestricted, unless:
– national security
– data protection laws
• Data protection – cloud guidance
– Article 29 WP opinion
– UK ICO guidance
@kuan∅
Law vs IT
“Technical &
organisational
measures”
IT security
& IT
“data
protection”
“Data
protection”
(law)
19/05/2013
12
@kuan∅
Data protection laws:
“Personal data”
(cf anonymous data)
@kuan∅
EU Data Protection Directive
Data export restriction
NO transfer of PD outside
European Economic Area
19/05/2013
13
@kuan∅
Unless…
• Exception
• “Adequate protection”
/ “adequate safeguards”
• But problems…
@kuan∅
So, in practice…
• Regional clouds - easy, safe
19/05/2013
14
@kuan∅
EEA, EU, Europe…
http://bit.ly
/eu-venn for
large version
& table
@kuan∅
‘Transfer’ – physical location
• Gear: storage / processing; caches
• People: remote access
19/05/2013
15
@kuan∅
• + Names of all
“sub-contractors”
• Follow this… + other
DP regulators’
recommendations
(eg liability chain)
public cloud!
Gimme gimme gimme
your data locations…
Image from Beeld en Geluidwiki
@kuan∅
Traditional
outsourcing
Cloud
Cook food yourself
Hire caterers to cook
for you on your
instructions
Rent kitchen, cook
food yourself
Get take-out or ready
meal, cook it yourself
19/05/2013
16
@kuan∅
Key tensions
• “Guaranteed” security / liability
– should be possible – but will cost!
– cheap / free public cloud model
• Control of supply / contract chain
– will big players be the winners?
@kuan∅
“It’s unworkable, so just ignore it?”
@kuan∅
19/05/2013
17
@kuan∅
Draft Data Protection Regulation
Up to 2%
annual
global
turnover
@kuan∅
@kuan∅
Good
intentions…
Flames of hell…?
19/05/2013
18
@kuan∅
Cloud contracts
@kuan∅
Cloud contracts
• 3 aspects:
– pre-contract due diligence
– contract terms
– post-contract – monitoring etc
• See negotiated contracts article
– “no names” interviews, FOI etc
– Forbes report
19/05/2013
19
@kuan∅
Standard terms
• Providers’ standard terms
– weighted; customer-appropriate?
• Negotiable? – customer / deal size
• Gov / banks - trad. IT outsourcing
– cloud-appropriate?
• Customer process issue – bypass IT,
legal!
@kuan∅
Pre-contract due diligence
• If personal data – all sub-providers’
names; locations; security
• Lock-in and exit – practical: test data
portability in advance (NB fake data!)
• Security – pen testing, certifications?
• NB backups
• + Post-contract - security audits etc
• ENISA papers (hunt!)
19/05/2013
20
@kuan∅
Contract terms
• If personal data:
– choice of provider (security), contract
requirements: “instructions”, security
• More generally, some key issues:
– provider liability (vs price)
– lock-in – term, termination; exit terms
– security – confidentiality; audit rights?
– right to change terms? (cf G-Cloud…)
@kuan∅
G-Cloud: CloudStore
• Process - no mini-competition,
no negotiation! (though fill in blanks…)
- Price / MEAT
• Info - G-Cloud site, @G_Cloud_UK,
BuyCamp events (Friday; 7 June)
• NB overlay approach & supplier terms:
– get advice on own specific data type/use
– see G-Cloud paper
19/05/2013
21
@kuan∅
Cloud
Open data
Big data
@kuan∅
Protection of Freedoms Act
• s 102 amends FOIA
– datasets – electronic, reusable form
– open licensing – allow reuse (fees?)
• In force May/June…?
– Draft Code of Practice – consultation
– ICO publication scheme, guidance
• What datasets, how to handle?
19/05/2013
22
@kuan∅
Open data vs personal data
• Anonymise any PD before release
• Tricky! eg Sweeney etc research
• Big, eg EE / Ipsos Mori! But worthwhile
• ICO Code of Practice (full disclosure..)
– limited controlled release, vs fully public
• UK Anonymisation Network (2 years)
– anonymisation clinics – 28 June
@kuan∅
STOP PRESS
• Shakespeare review of PSI, 15 May 2013
– Deloitte market assessment
– His summary in the Guardian
• Same ol’ same ol’, words vs action? (eg jail for
unlawfully obtaining personal data…)
– Following 'best practice' guidelines should be enough, so
long as we are willing to prosecute those who misuse
personal data… In considering further legislation we should
institute increased penalties – not only loss of
accreditation and much heavier fines, but also
imprisonment in cases of deliberate and harmful misuses
of data.
19/05/2013
23
@kuan∅
Cloud
Open data
Big data
@kuan∅
Big data vs personal data
• Data protection compliance (eg
security) & anonymisation, again…
• Less data good?
• Other issues? eg IP
19/05/2013
24
@kuan∅
New technologies
and paradigms,
old laws
@kuan∅
Old laws
• Outdated assumptions
• Appropriate to new paradigms??
• But - the law is the law!
• Until laws are updated properly…
• Same ol’ strategy still sensible:
– RRRR + EEEE
19/05/2013
25
@kuan∅
Key takeaways 1
• RRRR:
– requirements evaluation, for
– real life intended use
– review & understand tech / model
– risk assessment – technological,
legal, reputational, public trust etc
(for intended data type/use case)
@kuan∅
Key takeaways 2
• EEEE – get:
– expert input / advice – legal, IT,
risk, security, stats etc
– based on exact data type, use case
– explain the tech / model properly
– early, not last minute or after!
19/05/2013
26
@kuan∅
Thank you!
Kuan Hon
Twitter: @kuan∅
Email: k @ domain below
kuan∅.com/publications.html
blog.kuan∅.com
Half lawyer | half geek | mostly harmless

Contenu connexe

Similaire à Legal Risks of Cloud Computing and Open Data

Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...Heiko Paulheim
 
SoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social MiningSoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social MiningResearch Data Alliance
 
AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024Aurélie Pols
 
Musings about the post covid19 world
Musings about the post covid19 worldMusings about the post covid19 world
Musings about the post covid19 worldAnant Kadiyala
 
Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data DATAVERSITY
 
Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data Data Blueprint
 
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...Bruno Segers
 
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...Heiko Paulheim
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017Ray Bugg
 
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...MicheleNati
 
Data Accountability & Consumer Trust
Data Accountability & Consumer TrustData Accountability & Consumer Trust
Data Accountability & Consumer TrustAurélie Pols
 
Sbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-finalSbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-finalFreek Bomhof
 
What is open data
What is open dataWhat is open data
What is open dataScott Sosna
 
CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018LERNER Consulting
 
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...Usama Fayyad
 
Cloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UKCloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UKCloudera, Inc.
 
Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...eraser Juan José Calderón
 
Open data for UK public sector organisations
Open data for UK public sector organisationsOpen data for UK public sector organisations
Open data for UK public sector organisationsAndrew Mackenzie
 
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...
Blockchain and Data Science:Enabling Data Integrity for Predictions through ...Blockchain and Data Science:Enabling Data Integrity for Predictions through ...
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...SunilKrPandey1
 
Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights ManagementSabrina Kirrane
 

Similaire à Legal Risks of Cloud Computing and Open Data (20)

Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist's Perspec...
 
SoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social MiningSoBigData. European Research Infrastructure for Big Data and Social Mining
SoBigData. European Research Infrastructure for Big Data and Social Mining
 
AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024AI Roles and Risk for election year 2024
AI Roles and Risk for election year 2024
 
Musings about the post covid19 world
Musings about the post covid19 worldMusings about the post covid19 world
Musings about the post covid19 world
 
Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data Data-Ed Webinar: Demystifying Big Data
Data-Ed Webinar: Demystifying Big Data
 
Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data Data-Ed: Demystifying Big Data
Data-Ed: Demystifying Big Data
 
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
Launch of the #OYOD idea at the 2014 Computers, Privacy and Data Protection C...
 
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
Big Data, Smart Algorithms, and Market Power - A Computer Scientist’s Perspec...
 
GDPR Scotland 2017
GDPR Scotland 2017GDPR Scotland 2017
GDPR Scotland 2017
 
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
Personal data and blockchain: Opportunities and Challenges - Michele Nati - L...
 
Data Accountability & Consumer Trust
Data Accountability & Consumer TrustData Accountability & Consumer Trust
Data Accountability & Consumer Trust
 
Sbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-finalSbdc2018 master slidedeck-final
Sbdc2018 master slidedeck-final
 
What is open data
What is open dataWhat is open data
What is open data
 
CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018
 
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
Keynote talk at Financial Times Forum - BigData and Advanced Analytics at SIB...
 
Cloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UKCloudera Cares + DataKind | 7 May 2015 | London, UK
Cloudera Cares + DataKind | 7 May 2015 | London, UK
 
Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...Blockchain based educational certificates as a model for a P2P commons of sch...
Blockchain based educational certificates as a model for a P2P commons of sch...
 
Open data for UK public sector organisations
Open data for UK public sector organisationsOpen data for UK public sector organisations
Open data for UK public sector organisations
 
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...
Blockchain and Data Science:Enabling Data Integrity for Predictions through ...Blockchain and Data Science:Enabling Data Integrity for Predictions through ...
Blockchain and Data Science :Enabling Data Integrity for Predictions through ...
 
Digital Rights Management
Digital Rights ManagementDigital Rights Management
Digital Rights Management
 

Plus de Eduserv

Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionEduserv
 
Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources Eduserv
 
Lightning talk - EBSCO
Lightning talk - EBSCOLightning talk - EBSCO
Lightning talk - EBSCOEduserv
 
Lightning talk - Boopsie
Lightning talk - BoopsieLightning talk - Boopsie
Lightning talk - BoopsieEduserv
 
Lightning talk - Softlink
Lightning talk - SoftlinkLightning talk - Softlink
Lightning talk - SoftlinkEduserv
 
Lightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZineLightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZineEduserv
 
Lightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest AgreementsLightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest AgreementsEduserv
 
Phase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolutionPhase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolutionEduserv
 
Key considerations when mapping your end user experience
Key considerations when mapping your end user experienceKey considerations when mapping your end user experience
Key considerations when mapping your end user experienceEduserv
 
Our product development methodology
Our product development methodologyOur product development methodology
Our product development methodologyEduserv
 
How Readers Discover Content
How Readers Discover ContentHow Readers Discover Content
How Readers Discover ContentEduserv
 
OpenAthens product update
OpenAthens product updateOpenAthens product update
OpenAthens product updateEduserv
 
OpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome addressOpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome addressEduserv
 
Generating leads with content marketing
Generating leads with content marketingGenerating leads with content marketing
Generating leads with content marketingEduserv
 
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016Eduserv
 
Mobius from Maplesoft
Mobius from MaplesoftMobius from Maplesoft
Mobius from MaplesoftEduserv
 
QSR NVivo
QSR NVivo QSR NVivo
QSR NVivo Eduserv
 
How Eduserv are helping local government organisations
How Eduserv are helping local government organisationsHow Eduserv are helping local government organisations
How Eduserv are helping local government organisationsEduserv
 
Is cloud the right fit for your needs?
Is cloud the right fit for your needs?Is cloud the right fit for your needs?
Is cloud the right fit for your needs?Eduserv
 
Planning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing CouncilsPlanning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing CouncilsEduserv
 

Plus de Eduserv (20)

Phase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect optionPhase two of OpenAthens SP evolution including OpenID connect option
Phase two of OpenAthens SP evolution including OpenID connect option
 
Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources Partnership Licensing - allowing access to licensed resources
Partnership Licensing - allowing access to licensed resources
 
Lightning talk - EBSCO
Lightning talk - EBSCOLightning talk - EBSCO
Lightning talk - EBSCO
 
Lightning talk - Boopsie
Lightning talk - BoopsieLightning talk - Boopsie
Lightning talk - Boopsie
 
Lightning talk - Softlink
Lightning talk - SoftlinkLightning talk - Softlink
Lightning talk - Softlink
 
Lightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZineLightning talk - Third Iron BrowZine
Lightning talk - Third Iron BrowZine
 
Lightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest AgreementsLightning talk - Eduserv Chest Agreements
Lightning talk - Eduserv Chest Agreements
 
Phase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolutionPhase one of OpenAthens SP evolution
Phase one of OpenAthens SP evolution
 
Key considerations when mapping your end user experience
Key considerations when mapping your end user experienceKey considerations when mapping your end user experience
Key considerations when mapping your end user experience
 
Our product development methodology
Our product development methodologyOur product development methodology
Our product development methodology
 
How Readers Discover Content
How Readers Discover ContentHow Readers Discover Content
How Readers Discover Content
 
OpenAthens product update
OpenAthens product updateOpenAthens product update
OpenAthens product update
 
OpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome addressOpenAthens Customer Conference - Welcome address
OpenAthens Customer Conference - Welcome address
 
Generating leads with content marketing
Generating leads with content marketingGenerating leads with content marketing
Generating leads with content marketing
 
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
Pre-launch introduction to the new OpenAthens SP dashboard - 13/09/2016
 
Mobius from Maplesoft
Mobius from MaplesoftMobius from Maplesoft
Mobius from Maplesoft
 
QSR NVivo
QSR NVivo QSR NVivo
QSR NVivo
 
How Eduserv are helping local government organisations
How Eduserv are helping local government organisationsHow Eduserv are helping local government organisations
How Eduserv are helping local government organisations
 
Is cloud the right fit for your needs?
Is cloud the right fit for your needs?Is cloud the right fit for your needs?
Is cloud the right fit for your needs?
 
Planning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing CouncilsPlanning your cloud strategy: Adur and Worthing Councils
Planning your cloud strategy: Adur and Worthing Councils
 

Dernier

Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 

Dernier (20)

Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 

Legal Risks of Cloud Computing and Open Data

  • 1. 19/05/2013 1 New Technologies & Paradigms, Old Laws Kuan Hon Independent Consultant PhD Candidate, QMUL Eduserv Symposium 2013, London 16 May 2013 @kuan∅ Outline • Introduction • Cloud • Open data, big data
  • 2. 19/05/2013 2 @kuan∅ Introduction • Self [2 hats 4 clouds 3 weasels] • Attendees? @kuan∅ Legal risks of new tech Risk pyramid Legal Reputational [Public trust] etc etc
  • 4. 19/05/2013 4 @kuan∅ LawyersLawyers (Image reproduced by kind permission of Firebox.com) Certainty? Hah! ‘It depends…’ Interpretation Context Probabilities
  • 5. 19/05/2013 5 @kuan∅ Skills For legal (& many other) issues: Know WHO to ask, & WHEN, & WHAT to tell ‘em! @kuan∅ WHO Lawyers
  • 8. 19/05/2013 8 @kuan∅ Laws & the internet @kuan∅ Cloud computing & law Risk pyramid Laws Reputational [Public trust] etc etc
  • 9. 19/05/2013 9 @kuan∅ Let your lawyer do the worrying… @kuan∅ Cloud computing • Legal risks - brief lawyers on: – what’s cloud? •recap •NB layers •12 Cs; cf traditional outsourcing – what do you want to use it for? •requirements, risk tolerance User ---- DropBox ---- Amazon SaaS IaaS
  • 10. 19/05/2013 10 @kuan∅ Cloud legal issues • Lots! – IP, competition – no time… – see cloudlegalproject.org + book • Pre-contract checks + contract • For public sector: – government policy – CloudStore @kuan∅ Location
  • 11. 19/05/2013 11 @kuan∅ Data location, me & you • Public sector – Gov ICT Offshoring (International Sourcing) Guidance - data location unrestricted, unless: – national security – data protection laws • Data protection – cloud guidance – Article 29 WP opinion – UK ICO guidance @kuan∅ Law vs IT “Technical & organisational measures” IT security & IT “data protection” “Data protection” (law)
  • 12. 19/05/2013 12 @kuan∅ Data protection laws: “Personal data” (cf anonymous data) @kuan∅ EU Data Protection Directive Data export restriction NO transfer of PD outside European Economic Area
  • 13. 19/05/2013 13 @kuan∅ Unless… • Exception • “Adequate protection” / “adequate safeguards” • But problems… @kuan∅ So, in practice… • Regional clouds - easy, safe
  • 14. 19/05/2013 14 @kuan∅ EEA, EU, Europe… http://bit.ly /eu-venn for large version & table @kuan∅ ‘Transfer’ – physical location • Gear: storage / processing; caches • People: remote access
  • 15. 19/05/2013 15 @kuan∅ • + Names of all “sub-contractors” • Follow this… + other DP regulators’ recommendations (eg liability chain) public cloud! Gimme gimme gimme your data locations… Image from Beeld en Geluidwiki @kuan∅ Traditional outsourcing Cloud Cook food yourself Hire caterers to cook for you on your instructions Rent kitchen, cook food yourself Get take-out or ready meal, cook it yourself
  • 16. 19/05/2013 16 @kuan∅ Key tensions • “Guaranteed” security / liability – should be possible – but will cost! – cheap / free public cloud model • Control of supply / contract chain – will big players be the winners? @kuan∅ “It’s unworkable, so just ignore it?” @kuan∅
  • 17. 19/05/2013 17 @kuan∅ Draft Data Protection Regulation Up to 2% annual global turnover @kuan∅ @kuan∅ Good intentions… Flames of hell…?
  • 18. 19/05/2013 18 @kuan∅ Cloud contracts @kuan∅ Cloud contracts • 3 aspects: – pre-contract due diligence – contract terms – post-contract – monitoring etc • See negotiated contracts article – “no names” interviews, FOI etc – Forbes report
  • 19. 19/05/2013 19 @kuan∅ Standard terms • Providers’ standard terms – weighted; customer-appropriate? • Negotiable? – customer / deal size • Gov / banks - trad. IT outsourcing – cloud-appropriate? • Customer process issue – bypass IT, legal! @kuan∅ Pre-contract due diligence • If personal data – all sub-providers’ names; locations; security • Lock-in and exit – practical: test data portability in advance (NB fake data!) • Security – pen testing, certifications? • NB backups • + Post-contract - security audits etc • ENISA papers (hunt!)
  • 20. 19/05/2013 20 @kuan∅ Contract terms • If personal data: – choice of provider (security), contract requirements: “instructions”, security • More generally, some key issues: – provider liability (vs price) – lock-in – term, termination; exit terms – security – confidentiality; audit rights? – right to change terms? (cf G-Cloud…) @kuan∅ G-Cloud: CloudStore • Process - no mini-competition, no negotiation! (though fill in blanks…) - Price / MEAT • Info - G-Cloud site, @G_Cloud_UK, BuyCamp events (Friday; 7 June) • NB overlay approach & supplier terms: – get advice on own specific data type/use – see G-Cloud paper
  • 21. 19/05/2013 21 @kuan∅ Cloud Open data Big data @kuan∅ Protection of Freedoms Act • s 102 amends FOIA – datasets – electronic, reusable form – open licensing – allow reuse (fees?) • In force May/June…? – Draft Code of Practice – consultation – ICO publication scheme, guidance • What datasets, how to handle?
  • 22. 19/05/2013 22 @kuan∅ Open data vs personal data • Anonymise any PD before release • Tricky! eg Sweeney etc research • Big, eg EE / Ipsos Mori! But worthwhile • ICO Code of Practice (full disclosure..) – limited controlled release, vs fully public • UK Anonymisation Network (2 years) – anonymisation clinics – 28 June @kuan∅ STOP PRESS • Shakespeare review of PSI, 15 May 2013 – Deloitte market assessment – His summary in the Guardian • Same ol’ same ol’, words vs action? (eg jail for unlawfully obtaining personal data…) – Following 'best practice' guidelines should be enough, so long as we are willing to prosecute those who misuse personal data… In considering further legislation we should institute increased penalties – not only loss of accreditation and much heavier fines, but also imprisonment in cases of deliberate and harmful misuses of data.
  • 23. 19/05/2013 23 @kuan∅ Cloud Open data Big data @kuan∅ Big data vs personal data • Data protection compliance (eg security) & anonymisation, again… • Less data good? • Other issues? eg IP
  • 24. 19/05/2013 24 @kuan∅ New technologies and paradigms, old laws @kuan∅ Old laws • Outdated assumptions • Appropriate to new paradigms?? • But - the law is the law! • Until laws are updated properly… • Same ol’ strategy still sensible: – RRRR + EEEE
  • 25. 19/05/2013 25 @kuan∅ Key takeaways 1 • RRRR: – requirements evaluation, for – real life intended use – review & understand tech / model – risk assessment – technological, legal, reputational, public trust etc (for intended data type/use case) @kuan∅ Key takeaways 2 • EEEE – get: – expert input / advice – legal, IT, risk, security, stats etc – based on exact data type, use case – explain the tech / model properly – early, not last minute or after!
  • 26. 19/05/2013 26 @kuan∅ Thank you! Kuan Hon Twitter: @kuan∅ Email: k @ domain below kuan∅.com/publications.html blog.kuan∅.com Half lawyer | half geek | mostly harmless