<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jackson Attorneys</title>
	<atom:link href="https://jacksonattorneys.co.za/feed/" rel="self" type="application/rss+xml" />
	<link>https://jacksonattorneys.co.za</link>
	<description>Allan Jackson Attorneys</description>
	<lastBuildDate>Thu, 14 Oct 2021 14:22:57 +0000</lastBuildDate>
	<language>en-ZA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://jacksonattorneys.co.za/wp-content/uploads/2021/10/cropped-Allan-Jackson-Favi-icon-FINAL-32x32.png</url>
	<title>Jackson Attorneys</title>
	<link>https://jacksonattorneys.co.za</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cloud License Agreements and Distribution</title>
		<link>https://jacksonattorneys.co.za/cloud-license-agreements-and-distribution/</link>
		
		<dc:creator><![CDATA[Marlie]]></dc:creator>
		<pubDate>Thu, 14 Oct 2021 14:22:57 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://jacksonattorneys.co.za/?p=293</guid>

					<description><![CDATA[Introduction People today utilise the internet for various things. However, one of the principal uses of the internet is maintaining contact with friends and family through social media and keeping abreast with the latest news and information. People access shared files and data anytime from anywhere in the world. Businesses and organisations utilise the internet [&#8230;]]]></description>
										<content:encoded><![CDATA[<h5><strong>Introduction</strong></h5>
<p>People today utilise the internet for various things. However, one of the principal uses of the internet is maintaining contact with friends and family through social media and keeping abreast with the latest news and information. People access shared files and data anytime from anywhere in the world. Businesses and organisations utilise the internet for an ever-increasing variety of functions, including professional commercial applications and advanced technological platforms. Such services are exceedingly simple to start up and use and very frequently with minimal data entry requirements. Benefits of this nature would also accommodate the use of credit cards and associated information. A limited number of keyboard entries to commence with the service ensures full access to the operations of the internet and other applications. Understandably, the cloud environment stands easily reached, which in turn offers multiple business solutions and facilities.<a href="#_ftn1" name="_ftnref1">[1]</a> Linked to these activities is a significant misperception as to the rights, responsibilities and legal implications of what appears to be an open, accessible and relaxed environment. These activities carry extensive consequences for the users, resulting in a complete shock and unforeseen implications for businesses and individual consumers.</p>
<p>An example of such misperception of the cloud arrives in the form of the broad public perception that the community possesses everything available on the internet. Therefore can stand liberally and limitlessly utilised. Understandably, this indulgence is flawed as the small detail of IPRs is predominantly copyright-based in this context and most other cases. It is present in almost every aspect of data loaded on the internet or in the cloud, whether shared, posted or transmitted. Immediately when a user uploads data onto the internet, that upload is invariably subject to terms that define other cloud users’ access and use rights and the ownership retained or relinquished by the uploading user of such data. These rights constitute an actual or constructive contract or license, provided it stands granted to the service or platform provider and potentially other internet users. Although sometimes difficult to discern, the terms of this type of contract define rights of use to the data for particular purposes or within certain limitations.</p>
<p>Regardless of the cloud services involved, license rights define the various parties’ rights in and to data in the cloud environment and other essential rights and obligations, whether the cloud service client is a licensor or licensee or, as is frequently the case, both.</p>
<p>The following are typical scenarios reflecting licensing of the cloud services:</p>
<ol>
<li><em>Client owned data. </em>Primarily where the customer uploads and stores data using cloud storage facilities. Whether that data is a photo, a word document, a soundtrack, logo or other software, they do so with a ‘use features’ of rights, whether express or implied, to the storage service provider. This ‘use features’ extends, at a minimum, to the right to make such copies as may be required to enable the provider to perform the storage, processing, backup and retrieval functions for the servers providing the storage facility. These servers often stand in different locations or jurisdictions, which may vary based on aggregate demand and the provider’s platform and arrangements for data balancing. The ‘use features’ of these rights stand referred to as content licensing. Further, when a client engages a service provider in making available IaaS or PaaS, the client similarly licenses or sub-licenses in the case of third party software uploaded by the customer to the service provider system for integration.<a href="#_ftn2" name="_ftnref2">[2]</a>
<p>The parties may communicate and agree on the exact contractual terms of a license ‘use features’. Still, often they are at least partly implied through the actions and conduct concerning services agreed to by the client at service initiation, and the scope of the licenses may be broad. The fact stands that such terms may extend well beyond the immediate requirements of the services offered or provided. For instance, a relatively common right included under these licenses is ‘use features’ to the provider itself, the right to use the client data for the benefit of the service provider itself, including for the further development of the facilities for all customers of that vendor.<a href="#_ftn3" name="_ftnref3">[3]</a></li>
<li><em>Service provider owned/licensed software.</em> Whenever a client engages a cloud service, the provider must similarly make a ‘use features’ license available for the customer for at least the necessary rights to use the service provider’s software interface and functionality or other components essential to the delivery and use of the relevant services.
<p>Cloud clients, especially in the public cloud, may be unaware that they are provided with content licenses to the service provider’s software at all, much less the actual nature, scope and duration of the rights granted. Even though the clients may retain ultimate ownership of their data, there is a real risk of losing control over it.<a href="#_ftn4" name="_ftnref4">[4]</a> Often equally important other rights or obligations are contained or not included in the contract terms governing the use of the cloud service. These may also be unappreciated by the client.</li>
</ol>
<h5><strong>The Frequent Challenges of Determining Terms</strong></h5>
<p>Ideally, the conditions under which any cloud solution stands delivered should stand explicitly and comprehensively stated in a written, static, readily accessible and understandable agreement. Again ideally, these terms and conditions should be known and understood by both the client and the provider, which is often not the case.</p>
<p>The growth of the cloud services delivery model has been rapid. It has challenged consumers’ ability and willingness to adequately assess and manage the legal implications and risks presented in contracting for and utilising cloud solutions. The sheer ease of initiation and use of cloud services belies the legal significance of the undertaking. From the initial set-up, from the contracting to the operational use of the services and through to termination agreements, cloud services present new but familiar variations on the risk and opportunity trade-offs presented in traditional technology service agreements. Specifically, almost all the significant issues long recognised as complex in IT outsourcing appear in cloud services.<a href="#_ftn5" name="_ftnref5">[5]</a></p>
<p>By their very nature, Cloud solutions are more susceptible, when compared to prior bespoke technology solutions, to the client proceeding with adoption and use without a clear understanding of the entire contractual dimensions of the agreement undertaken. Additionally, this might result from commando-style keyboard click-through practices. The client effectively ‘clicks acceptance’ to online terms without even making an effort to review and understand the contract undertaken. Of course, there have always been those clients who do not read contracts. Still, with the proliferation of ‘click-through’ contracts over the internet, the practical ease of elective ignorance has never been greater, and this has often contributed to reduced vigilance around contracting.<a href="#_ftn6" name="_ftnref6">[6]</a> One of the biggest strengths of the cloud is its sheer ease of use and access and has no doubt contributed to this, sometimes reducing the contracting process to seemingly nothing more than navigating the internet.</p>
<p>The cloud service providers often prepare the terms and conditions of service delivery for cloud solutions and frequently only cover limited issues. Determining actual contract terms applicable to the services is more complicated where items are missing. Those missing contractual terms may stand implied in such cases, where required under the agreement to make commercial sense. Terms may also stand implied in law, such as the provider’s rights or a third party under the copyright or patent law or may stand indicated as necessary to efficacy the cloud agreement. Terms may also stand drawn from what appears as the parties’ reasonable expectations, including as reflected in their actions or conduct. The result is that frequently with cloud solutions, especially public cloud solutions, any comprehensive understanding of terms only starts with those expressly required by the service provider in the ‘accept-before-entering’ gateway and therefore must be supplemented with implied terms. Once established, implied terms can stand enforced, but the burden of proving implied terms can be onerous and raises risks for either or both of the parties.<a href="#_ftn7" name="_ftnref7">[7]</a></p>
<p>The frequent lack of certainty over precise terms may be acceptable and even appropriate for a cloud solution, subject to purely casual use. Think of a strictly personal email service used for non-critical communications. However, to the extent that a cloud service involves critical functions or sensitive data, it becomes increasingly crucial for the client to clearly understand the terms and rights to assess the appropriateness of use. Again, one of the core strengths of the cloud, the practical ease of initiation of use, has led to the situation where the adoption of cloud services has frequently outpaced careful evaluation and management of risk.</p>
<p>The need for the client to evaluate the suitability of available contract terms against their requirements is unambiguous in the case of cloud solutions, especially the public cloud, where there may be a slight opportunity or even no possibility for the client to have an input on the terms available. Often, the customer’s choice is acceptance of the service provider’s standard terms or preceding the adoption of the cloud solution entirely. Such a stark set of alternatives further complicates both the speed and the ease of acceptance and approval. The result is that clients may unwittingly make wrong trade-offs between cost savings and flexibility versus risk.</p>
<p>A further consideration in cloud contracting is that the party seeking to enforce a right or obligation affirmatively inevitably has some more significant threshold burden than the opposing party. Still, this is especially true if the right or duty to be imposed is not expressly part of their agreement and must stand established as an implied term. Again, cloud solutions present a dilemma: their ease of contracting, while a core strength, also presents significant oversight challenges. Opportunities promising quick-fix cost savings and flexibility may drive hasty decisions that have substantial business and risk consequences. Wanting or needing a special right of assurance in a contract is far from establishing it.<a href="#_ftn8" name="_ftnref8">[8]</a></p>
<p>The ‘take-it’ or ‘leave-it’ understanding is a reality of many public cloud solution contracts and is another critical consideration. Service providers are often resistant to any modifications to their contract terms. Some of this resistance may be the traditional opposition of any party in any transaction to changes in their established and most preferred conditions. However, many cloud solutions involve engineering practices or agreements that place convenient limits on the ability of the service provider to accommodate designated consumers’ favoured contracts, much less give contractual assurance of doing so. Additionally, one of the core characteristics of the cloud is the ease of provisioning, including contracting, where service providers are often not set up to spend effort and resources on contracts or accommodating variations in terms of services for individual customers. Even where a vendor may be able and willing to make a client’s costs available, such costs should pass on to the client and adversely impact the cloud solution’s financial benefits. For the customer, achieving absolute value from a cloud solution inevitably demands a careful and responsible balancing between cost savings and functionality benefits with risk and strategy.<a href="#_ftn9" name="_ftnref9">[9]</a></p>
<h5><strong>Cloud Contract Terms</strong></h5>
<p>Beyond the drawbacks and challenges often faced in cloud services contracting, consideration should stand given to the substantive terms of an actual cloud services contract and what it should contain. In doing so, significant leverage may remain resulting from the prior knowledge of technology delivery, namely traditional outsourcing. Outsourcing has been through a critical evolution in contracting over the past decade. The cloud merely represents the latest means of delivery of technology solutions, following on from initial modern outsourcing or offshoring.<a href="#_ftn10" name="_ftnref10">[10]</a> Each of these delivery models involved stabilisation and growth phases intensely driven by contracting models. The contracting pressures were the same in each, developing a model to support a practice that gave clients sufficient assurances to permit the service’s adoption.</p>
<p>Consequently, contracting difficulties can stand evaluated through contrasting cloud licenses, which challenges traditional outsourcing contracts and conditions. Such an exercise provides a means to critically analyse relevant client protection provisions, which remained developed through outsourcing contracts. The practical challenge is how to combine this contracting experience and learning from outsourcing with the flexibility and standardisation essential to cloud computing solutions.</p>
<p>The business environment in which the cloud operates presents many challenges. Business users face new and changing legislation and regulations (such as data protection) impacting the provision and use of cloud databases and computing services. Further, capability and competition within the cloud and outsourcing market are growing as cloud service contract agreements and terms are evolving.</p>
<p>Further enhancing the discussion on cloud contracting, particular attention should stand applied to the following essential contractual issues: license ‘use features’, services commitments and services quality protections, client control rights, compliance obligations, data and security protections, IP protections, benefits continuity protections and end of term assistance.</p>
<p>Most of the discussion will compare and contrast representative approaches to the issues taken in the traditional outsourcing model as a primary point of reference. This traditional approach to services will be compared with the method frequently found in the pure public or utility cloud model, representing the spectrum extreme in cloud services contracting, more towards the actual cloud services approach. Then, a middle-ground view will stand reflected. A discussion on the issues in the context of private or hybrid cloud solution models follows, where the cloud service provider may stand better positioned to be responsive to particular or individual client requirements.<a href="#_ftn11" name="_ftnref11">[11]</a></p>
<p>In the discussion, the terms ‘contract’ and ‘license’ will stand used interchangeably. While acknowledging that all licenses are indeed contracts, but not all agreements are licenses, the interchangeable use of the terms is a method of ease for the discussion and to illustrate the various considerations raised in association with the placement and use of data in the cloud. Nonetheless, because of the significant role that licensing concepts play in many cloud service solutions, the natural tendency is often to refer to the cloud service contract as a license. Hence the reference in the title to two practical aspects of licensing in the cloud.</p>
<h5><strong>Cloud License Utilisation Features</strong></h5>
<p>The first, and in many respects pivotal, set of contract issues associated with any cloud solution contract is the actual license ‘use features’. This set of problems encompasses the subject of the permissible users and the use of the license. Most cloud service agreements involve at least two groups of license ‘use features’:</p>
<p>A cloud service provider ‘use feature’ is granted to the client, and</p>
<p>A client ‘user feature’ accorded to the cloud service provider.</p>
<p>The discussion will focus primarily on the cloud service provider to client ‘use features’, which is the ‘use feature’ establishing the scope and nature of the cloud services. In most cases, the client to cloud service provider ‘use features’ is mainly ancillary to the services and focus on addressing the use to which the client’s data, including software, must be put by the cloud service provider in performing the cloud services.<a href="#_ftn12" name="_ftnref12">[12]</a></p>
<ol>
<li><em>The subject</em><em> of the license.</em> The first consideration in any right of use or license ‘use feature’ is the purpose of the ‘use feature’. In cloud services or cloud computing, the topic matter or service may be software, as in the case of SaaS, or it may be a technology platform as in the case of PaaS. It may also be a combination of a software and technology platform as in the occasion of IaaS. In identifying the subject, it is essential to consider how the topic is defined. For instance, whether the use of software includes the usage of its source code, which may be substantial if the client needs to make modifications or enhancements, including for purposes of interfacing or integrating with other software or processes. Similarly, it is crucial whether the software provided includes updates and new versions and whether the client has the discretion to move to such updates or new releases.
<p>In addition, this is an area where the nature of cloud services or cloud computing often drives limits in the client’s discretion regarding the implementation of software updates or new versions. Often the SaaS model is built as a one-size-fits-all solution, where software updates are uniformly rolled out for all of the services or with limited flexibility for clients to select different releases or version levels for their use. At the same time, this uniformity can be one of the core strengths of the cloud for software services. Enabling clients to keep current with versions and releases without undertaking the upgrade implementation themselves may be a limitation itself of the cloud solution, as clients are taken to updates, whether they are ready or not.</li>
<li><em>Permissible users. </em>The next issue to stand addressed in analysing a cloud solution is determining who has the right to use the solution proposed. The customer’s identity often drives client requirements here. For instance, whether they are an individual or a business enterprise, the purpose or purposes for which the cloud solution stands implemented may be noted in casual personal use or business use. Other significant matters include the number of users permitted (depending on the number of firm staff requiring access) and whether the client may allow third parties (such as their customers or contractors) to access the cloud services.<a href="#_ftn13" name="_ftnref13">[13]</a></li>
<li><em>Permissible use.</em> A license ‘use features’ frequently also address the allowable uses for which the cloud solution may stand set by the user(s). User rights can stand expressed as general or specific, and particular ‘use features’ may explicitly provide that only expressly permitted uses are allowed. Such an exclusivity provision makes defining the scope of the permissible ‘use features’ critical. Use limitations may be based on aspects of the solution such as access, use, execution, reproduction, display, performance, distribution, modification and creation of derivative works of the software/platform; or based on the activities of the client, such as use in operations of a defined business or geography. The customer must clearly understand the scope of service for which they require the cloud solution, ensuring that the user rights provided under the contract terms are sufficient to meet those requirements.<a href="#_ftn14" name="_ftnref14">[14]</a>
<p>The pricing agreements of a cloud solution may be closely parallel to or adequately define the license ‘use features’ terms. For instance, changes may stand based on the particular use of the solution, such as access to and use of different software modules, or numbers of users (named or concurrent) or size of cloud storage. Through such agreements, the client uses the service on a pay-as-you-go system,<a href="#_ftn15" name="_ftnref15">[15]</a> where no particular level or volume of the grade of service delivery stands provided. However, the client may increase and decrease the service usage as needed (and available).</li>
<li><em>Terms and termination.</em> Contract provisions relating to the contract period and circumstances of termination vary dramatically among cloud solutions and drive crucial considerations for the client. These requirements broadly define the extent to which the provider is making a threshold commitment to deliver or provision the cloud solution and, correspondingly, the level of assurance the client may have that the cloud solution will continue to be available for their use. The core issues are how long the cloud solution stands committed as accessible and has a dedicated period of provision. Further, under what circumstances may such provision nonetheless stand terminated by the provider. A closely related issue is the right to partial termination, including suspension of the service for a limited time.
<p>If there is no limited committed term of providing a cloud solution, there is a correspondingly limited reason for termination rights. In many cloud services and computing solutions, the committed contract period is short, with little or no notice of termination required (by either party). If the client has a particular business need, longer committed period contracts and termination periods may be necessary to enable the customer to incorporate the solution into their operations prudently. When cloud service providers seek to offer cloud solutions targeting innovative and energetic business operations, it becomes increasingly important to provide specifically committed contract periods. With a move to fixed service provision determined terms, the issues around early termination become significant.<a href="#_ftn16" name="_ftnref16">[16]</a></p>
<p>One problem with committed conditions in cloud solutions is the active period, which includes renewal rights and are renewal rights automatic or elected? In service agreements, committed periods may range from short notice periods, typically thirty days, to multi-year terms. In evaluating the certainty of a cloud solution’s continued availability, it stands essential for the client to consider the minimum duration that may stand applicable to the contractual agreement.<a href="#_ftn17" name="_ftnref17">[17]</a></p>
<p>Where a cloud contract contains a committed period, the conditions or circumstances under which either party might terminate the arrangement before the expiration of its term become relevant. Classically, service contracts provide that termination rights be available to a party in circumstances of a material breach by the other party, recognising that what constitutes a material breach may vary between the parties. However, some termination rights are parallel to both clients and service providers. The old-style service agreements often provide broader termination rights to the customer for breaches by service providers than to the service provider for violations by the client, in reflecting on the most general scope of (performance) responsibilities of service providers (and thus a more comprehensive range of potential material breaches) in traditional outsourcing agreements. It stands common that the scope of a possible material default by the client giving rise to a termination right by the provider is limited to non-payment. Another traditional default circumstance giving rise to termination rights (typically also a termination right for the client) is multiple non-material breaches that constitute material default to frequency. A terminating party should regard the prevailing circumstances. Its position would stand strengthened if it could lead to a breakdown in relations and the prospect of continuing substandard performance.<a href="#_ftn18" name="_ftnref18">[18]</a> Additionally, termination rights for convenience and circumstances of <em>force majeure</em> remain frequently included in licenses with fixed terms.<a href="#_ftn19" name="_ftnref19">[19]</a></li>
</ol>
<h5><strong>Service Commitments</strong></h5>
<ol>
<li><em>Contract obligations and terms:</em> The issue concerns how the service provider retains the ability to make changes in the services unilaterally and to what extent.</li>
</ol>
<p>In the traditional outsourcing contracting model, terms of service can only stand modified by agreement. Provisions such as <em>force majeure</em> may provide relief from performance obligation in certain circumstances. Still, the service provider generally has no unilateral rights to alter or modify their performance obligation during the agreement term.</p>
<p>The commitment to contract terms is not always present in the standard public cloud contract. Instead, service providers of pure public or utility cloud solutions, like Facebook (cloud-based online social media) and Dropbox (cloud-based online file storage). Have terms of service that often reserve for the service provider the ability to change those terms at any time at their discretion. Sometimes this right is expressly stated as a unilateral right to make changes. Other times, the right stands more indirectly preserved by incorporating external documents (often linked) such as policies and procedures that the provider can vary from time to time.</p>
<p>In some cases, the provider commits to provide some form of notice of changes, but in most cases, clients have to monitor the service provider’s website for changes to the contract terms. To enforce these changes may stand limited to a degree of reasonableness under applicable law. Still, the existence of such a unilateral service provider right in any cloud solution is a significant and defining consideration for the client, inevitably sowing uncertainty for them. Cloud solutions marketed for business adoption, such as a SaaS model for enterprise applications utilising a private or hybrid deployment model, tend to address this issue in a way closer to traditional outsourcing. It provides the client with the assurance that contract terms can be changed only by agreement between the provider and the client.<a href="#_ftn20" name="_ftnref20">[20]</a></p>
<ol>
<li><em>The obligation</em><em> to services.</em> This issue involves the extent to which the cloud service contract commits the service provider to deliver specified and expressly defined services or gives the service provider latitude in the services that may stand performed.</li>
</ol>
<p>The traditional outsourcing contract stands created on the premise of a detailed, customised service definition often contained in all-encompassing, descriptive statements of work. These service descriptions may contain common elements between a service provider’s clients. Still, they are frequently tailored to the customer’s specific operational and practice requirements and therefore, the outsourcing contract and delivery models stand entirely oriented towards this.</p>
<p>Standard public cloud solutions classically provide high-level, general definitions of traditional services common to all clients. Here, the service provider makes no explicit commitment to conforming to high-level public services definitions. The service provider typically takes the middle-ground approach. Frequently seen in SaaS private or hybrid cloud solutions involves contracts that may contain relatively detailed service definitions in definitive statements of functionality or work but not customised service definitions tailored to a client’s specific operational or practice requirements.</p>
<p>This cloud model takes a one-size-fits-all approach to current standard facilities for the representative clients to preserve that efficiency which marks cloud solutions.</p>
<ol>
<li><em>The minimum term obligation</em>. This issue involves the extent to which the cloud service contract commits the service provider and the client to maintain the contract for a particular period, subject to defined termination rights, such as in the case of an uncured default by one of the parties.</li>
</ol>
<p>On this issue, the outsourcing model has traditionally remained founded on a commitment period of years applicable for the service provider. Although the standard term in outsourcing agreements has shortened over the past decade, outsourcing contracts routinely provide an initial active period of three to seven years. They usually include elective extension terms of one to two years exercisable by the client to terminate early (for convenience) with a notice period and the payment of pre-established termination charges. The standard utility cloud contract classically provides little or no minimum term, reflecting (as discussed below) the frequent absence of performance commitments generally by the cloud service provider. In such circumstances, the cloud service provider is unobligated to make the services available. The middle-ground private or hybrid cloud contract often carries a relatively short minimum term, but in some cases, may require a notice period before termination by either party.<a href="#_ftn21" name="_ftnref21">[21]</a></p>
<h5><strong>Quality Protection of Services</strong></h5>
<ol>
<li><em>Testing and acceptance.</em> This issue involves the extent to which the cloud service contract facilitates the client to test and accept the services (or other deliverables) as part of the initial performance or delivery.
<p>The traditional outsourcing contract model often builds a level of user testing and acceptance into the initial implementation of the services. Trial and approval are also commonly constructed into the project methodology around all deliverables following the initial deployment, including service delivery transformations. These procedures are designed to assure the client that the services meet the client’s pre-defined operational and practice requirements and, to some degree, pledge to the provider that the customer will accept (often a prerequisite to payment) if the conditions stand achieved.</p>
<p>Classically, the standard utility cloud solution contract does not provide for testing and acceptance, either at service initiation or subsequent delivery level (such as software upgrades). In some cases, a trial period may allow the client to decide whether to proceed with the actual adoption and production use. Still, often this is adequately accommodated by allowing the customer to terminate the services whenever they determine the solution does not meet their operational or practice requirements.<a href="#_ftn22" name="_ftnref22">[22]</a></p>
<p>The middle-ground private or hybrid model contract often provides testing of the significant transition milestones during initial implementation and subsequent deliverables during the term. These tend to be generic and aimed at permitting the client to make a go-no-go decision rather than confronting a delivery commitment on the part of the service provider.</li>
<li><em>The obligation</em><em> to service levels</em>. Service levels and their related provisions constitute essential contractual devices in establishing, measuring and reporting service performance. This issue involves how the service provider provides contract commitments that the services will conform to specific pre-defined performance requirements.
<p>Service levels typically play a crucial role in a traditional outsourcing contract model. Outsourcing agreements often provide detailed and client-specific service levels. These serve as both a contractual commitment of service performance (for instance, establishing service availability, response time, transaction rate, processing speed, accuracy and the like) and the basis of credits (penalties) for failed performance.<a href="#_ftn23" name="_ftnref23">[23]</a> Typically, these afford the ability to the client to modify service levels and credits to address both problem areas and evolving areas of the customer’s concern, together with detailed reporting of the service provider against the service level requirements. In many cases, certain pre-defined levels of service level failures may be the basis of termination rights, which may be exercisable by the client.<a href="#_ftn24" name="_ftnref24">[24]</a> Recognising that in no event can service levels adequately address the full range of performance, outsourcing contracts classically also provide more general performance requirements, such as the commitment to perform the services with reasonable skill, care and diligence.</p>
<p>Standard cloud solution contracts classically do not include significant service provider commitments to service levels. More often, where service levels may stand included will form a component of the general service description that either does not provide service level credits or establishes unrealistic hurdles to obtaining such service level credits. Understandably, for the standardised and low-cost solutions, the standard cloud service providers are reluctant to guarantee the quality and reliability of duty (with a penalty for non-compliance). As providers seek to broaden the acceptability of public cloud solutions in business environments, many are reconsidering offering some service level commitments as a way to accommodate their client’s needs and attract new business. Even in such cases, the service level provisions often function defensively by being structured to restrict the service provider’s responsibility to limited credits that operate as exclusive remedies, or their equivalent, for failure to attain the defined service level.<a href="#_ftn25" name="_ftnref25">[25]</a></p>
<p>The middle-ground private or hybrid solution contracts more commonly contain service level provisions. However, these service levels tend to be focused more on supplier technology rather than reflecting the particular client’s needs associated with the solution. Nonetheless, these service levels may carry meaningful service credits for failure to attain the service provider’s defined service levels. In general, only those clients with high subscription and upfront payments of significant fees have the power to negotiate for service level commitment.<a href="#_ftn26" name="_ftnref26">[26]</a> In larger cloud service projects, service providers and customers may agree on a substantial list of the key performance metrics to express the degree of performance with which both parties are comfortable. Cloud service projects on a smaller scale will typically cover far fewer performance metrics.<a href="#_ftn27" name="_ftnref27">[27]</a> Therefore, it is essential to select which performance metrics are most crucial in achieving the client’s business needs and objectives and select measurable and auditable metrics, with the metric standards, measurement mechanisms, and reporting requirements documented clearly and concisely.</li>
</ol>
<h5><strong>Control Rights of the Client</strong></h5>
<ol>
<li><em>Rights to determine architecture:</em> This issue involves the extent to which the cloud service contract gives the customers rights on the technical design that the service provider utilises in the performance and delivery of the service.
<p>The traditional outsourcing model contract classically gives the customer the right to approve the design used by the service provider. This approval may be part of the initial contractual agreement, with assurances provided to the client that changes will not stand made in the technical design via modification control protections. The client typically enjoys the right to dictate enhanced technological innovations, although implementation may involve additional services and carry new changes.</p>
<p>The standard utility cloud solution contract invariably gives the client no right to approve technical architecture. Similarly, the middle-ground private or hybrid cloud model also provides the customer with no right to support technological innovations. It is one of the core distinctions of the cloud (over traditional bespoke outsourcing) that it primarily offers clients ‘one-size-fits-all’ solutions.<a href="#_ftn28" name="_ftnref28">[28]</a></li>
<li><em>Modification or change control rights:</em> This issue involves the extent to which the service contract provides consumer protection from modifications or changes made by the service provider in the services; any of these actions that impact those services or the customer’s use of them.
<p>The traditional outsourcing contract model requires that any amendment or change in services, which has a direct or indirect impact on the services or the client’s use of the services, must be contested by the customer. This client protection assures that the services will not stand altered by a method that results in additional costs for the client or diminishes required functionality.</p>
<p>The standard utility cloud contracting model, with solutions driven by a standard one-size-fits-all<a href="#_ftn29" name="_ftnref29">[29]</a> service, typically allows the provider to modify and make changes in the service area without the client’s notice or consent. The middle-ground private or hybrid cloud contract frequently requires that the service provider inform the customer of changes and allows the client to terminate the agreement if the changes adversely impact the services or the client. The service provider has no obligation to obtain the customer’s consent to the changes.</li>
</ol>
<h5><strong>Obligations Towards Legal Compliance</strong></h5>
<ol>
<li><em>Assistance in complying with laws:</em> This issue involves the extent to which the services contract obligates the service provider to assist or accommodate the client in meeting the client’s legal compliance requirements, particularly in the activities and operations of the customer involving the use of the services.
<p>Compliance with laws is an essential element in the traditional outsourcing contract model. Typically provisions oblige the service provider to comply with all the laws applicable to the services, their delivery and performance and assist with the client’s compliance related to the services. These provisions stand based on the recognition that a customer cannot transfer their compliance responsibilities to a third party and therefore necessarily needs to build assurances promoting legal compliance.<a href="#_ftn30" name="_ftnref30">[30]</a></p>
<p>The standard public cloud solution offers limited flexibility to adjust the services to a particular client’s legal requirements. Some of this inflexibility arises from the frequent heavy reliance on third-party contractors in public clouds.<a href="#_ftn31" name="_ftnref31">[31]</a> In reality, it may be almost impossible for the service provider to assist the client in complying with local laws, given the cross-border nature of the cloud offering. Although service providers may endeavour to perform the services in compliance with applicable laws, the contract invariably will not include commitments respecting particular legal acquiescence. They stand coupled with the service provider’s reserved ability to make unilateral changes in the services (often without notice). The result is that a client-facing legal compliance consideration must continually monitor the services and their use to ensure good compliance. In some cases, the customer’s ability to accurately observe the services is not feasible within a cloud solution, rendering some solutions inappropriate for specific uses.</p>
<p>The middle-ground private cloud or hybrid cloud model often provides a certain level of flexibility to configure the service to meet diverse client compliance requirements. These more tailored solutions are also frequently designed and operated to allow the client more assurances on legal compliance.</li>
<li><em>Audit review rights: </em>The issue involves the rights provided to the customer to inspect and assess the service provider and their provision of the services.
<p>In the traditional outsourcing model contract, clients are typically provided with well-defined rights to undertake operational and financial audits of the service provider and the services (including third-party contractors).</p>
<p>The standard utility cloud solution contract commonly provides no audit rights for the client, particularly concerning secondary contractors. The service provider in standard utility cloud solutions frequently does not even disclose whether secondary contractors have stood used.</p>
<p>In this area, middle-ground and private or hybrid cloud solutions often provide some audit rights. Typically, however, these rights do not include any right of territorial access to the service provider’s facilities for audit or review purposes.<a href="#_ftn32" name="_ftnref32">[32]</a><br />
<em><br />
</em></li>
<li><em>Liability:</em> Contractually, one of the core compliance assurance mechanisms is the potential exposure to liability for failure to perform according to the terms.<a href="#_ftn33" name="_ftnref33">[33]</a> Thus, one of the threshold issues in any services contract is the extent to which the service provider may stand exposed to liability for non-performance of contractual obligations.
<p>Industry practice for the traditional outsourcing model is for liability to be limited to direct damages and further restricted to a pre-defined (or calculable) limitation of compensation, subject to specific exclusions for breaches or defaults under the contract.<a href="#_ftn34" name="_ftnref34">[34]</a> Typically indirect and punitive damages are expressly disclaimed, except in cases of significant misconduct, such as gross negligence, fraud or willful abandonment.</p>
<p>The standard public cloud solution provides minimal liability for breaches or failures of any type. It is common practice that the service providers’ standard service contracts will exclude liability as much as possible. In some cases, the cloud service provider will assume that the functions will be executed (if at all) with care and equitable ability<a href="#_ftn35" name="_ftnref35">[35]</a> but will commonly not provide monetary compensation in the event the service provider fails to comply with the given undertaking. In such circumstances, the public cloud contract may state that the service provider will use commercial endeavours to rectify problems of non-performance. Often, this commitment is the client’s sole and exclusive remedy for non-performance.</p>
<p>The middle-ground private or hybrid cloud model often has a narrowly defined scope of potential damages, such as direct costs only, subject to a limited maximum usually determined by the contract price or changes or a fixed sum and subject to specific exclusions from such limitations. All losses that are special, indirect or consequential are most frequently excluded entirely under the contract. Additionally, the service provider will seek to disclaim liabilities for specific events or incidents to limit their potential liability exposure. These will include service outages and data loss, delays, delivery failures or other damage or loss resulting from the transfer of data over communication networks and facilities. The client needs to understand the details of the protection offered under the service contract. Evaluate whether the risks are acceptable in the context of their intended use of the services before entering the contract.</li>
</ol>
<h5><strong>Security and Data Protection</strong></h5>
<ol>
<li><em>a) Location of data:</em> This issue concerns provisions restricting or identifying where the client’s data, used in conjunction with the cloud service, may be stored or processed. The location of the client’s data can have significant implications for both security and legal compliance.
<p>In traditional outsourcing contracts, permissible locations for the service provider’s storage and processing of the client’s data stand defined and approved. Changes to these sites (at least involving material changes, including any transfer to a different country) require the client’s approval or, at a minimum, compliance with the change control processes (which itself likely requires the customer’s approval).</p>
<p>There are typically no restrictions on where the client’s data may be processed or stored in the standard public cloud contracts. In fact, in many cases, the technical infrastructure used by the service providers may itself even limit the service provider’s ability to control, or know, the location of data processing and storage: for instance, where networks of third parties stand utilised to provide storage and processing.</p>
<p>Private or hybrid cloud solutions are more likely to provide assurances about data location by frequently fixing sites by country. Nonetheless, even with such safeguards, broader consideration must be given to the localities from which the service provider may access the client’s data, resulting in the potential for deemed exports or transfers due to access from a foreign jurisdiction.</li>
<li><em>Information security: </em>Information security is a primary consideration in any service contract. With the focus on the extent of the security assurance that the client’s data is provided or created by the service provider in creation with the services, the data will be protected from access, use or alteration by unauthorised third parties.
<p>Outsourcing contracts classically contain detailed information security provisions focused on the safety to meet the client’s specific requirements. Additionally, the client under an outsourcing contract usually has the right to require changes in the service provider’s security practices, subject to the possibility of the additional work constituting new services for which there may be other charges.<a href="#_ftn36" name="_ftnref36">[36]</a></p>
<p>In the case of standard public cloud solutions, information security provisions stand typically included in the contract. These solutions, however, tend to be standardised offerings and based on the use of the service provider’s standard controls, with little or no ability to make modifications to any specific requirements of the client.</p>
<p>Middle-ground private and hybrid cloud solutions tend to treat security as a service and may provide elective or optional arrangements from a pre-established suite of security offerings.</li>
<li><em>Return, disposal or destruction of client data: </em>This issue involves the extent to which the service contract assures that the service provider will return or destroy the client’s data and the timing of that return or destruction.
<p>With traditional outsourcing, the contract gives the client clear and direct commitments from the service provider that client data will be returned or destroyed at the client’s option. Not only at the termination of the agreement. But also when the data has no further use or requirement for the performance of the services. Similarly, outsourcing contracts classically commit the service provider to return the client’s data at any time upon the client’s request.</p>
<p>Standard public cloud contracts classically contain little or no assurance that all of the client’s data will stand found, erased, or returned. As with limitations on some service providers’ control of the location of their client’s data, the technical structure of many standard public cloud solutions places boundaries on the service provider’s ability to provide assurances about return or destruction.</p>
<p>Middle-ground private or hybrid cloud solutions classically provide that data will stand returned or destroyed, although the alternative selected is sometimes at the service provider’s determination.</li>
</ol>
<h5><strong>Intellectual Property Protection</strong></h5>
<ol>
<li><em>IP rights of clients’ data:</em> The data in the cloud can be any data in any form. Each and any data enjoys some level of IP protection (most frequently copyright in this context, but this does not necessarily exclude any other IPRs from the discussion, particularly personal data protection in the cloud as a primary concern).
<p>It is well established that copyright subsists in original works (including electronic data) unless: (i) it is <em>de minimus</em> and hence fails to meet the minimum threshold for copyright protection; (ii) it is copied from others; or (iii) the copyright has already lapsed. In some cases, data, for instance, a drug formula, may also be protected as a trade secret or a potentially patentable subject matter. The issue involves the ownership of IP in the data that clients may provide or produce through the cloud services and the extent to which the service provider is allowed to use such data.<a href="#_ftn37" name="_ftnref37">[37]</a></p>
<p>The traditional outsourcing model stringently protects the client’s data ownership and specifies the service provider’s right to access, store, process, make necessary copies and use the client’s data (and its associated IP rights) to provide the service. Similarly, the outsourcing contract will detail the ownership of any IP developed by the service provider (including jointly with the client). It will allocate these rights through ownership and license rights. Essentially, it is a content license provided by the client to the service provider. It stands commonly seen that such license covers use by the service provider and their third-party contractors and strictly limits use for such purposes.</p>
<p>The standard utility cloud model provides that the client retains his ownership of data he provides and ‘use features’ of a use license to the service provider. The prominent players in the market, such as Hitch<a href="#_ftn38" name="_ftnref38">[38]</a> and Apple (iCloud<a href="#_ftn39" name="_ftnref39">[39]</a>), make it clear in their terms of service utilising their services. The clients ‘use features’ is a worldwide, perpetual and royalty-free license that allows the service provider to use the client’s data. Some service providers specify that the license ‘use features’ is for the use of data to provide, promote, or improve the services, but some are silent on the scope of such content license. More likely than not, the content license is a permanent one that does not end upon termination or expiration of the service. Such broad licensing raise risks for IP owners putting data on a public cloud. These risks include the possibility that trade secrets may lose the necessary element of confidence. As for patent rights, risks arise as the novelty required to register a patent may be compromised by placing the patentable subject matter on a public cloud under such a broad license. The maintenance of innovation novelty may be lost when the data is accessible to many people within an enterprise without proper access controls. It remains to stand seen how courts will approach such a situation, leaving this a considerable business risk. Another issue is the more precarious position of data loss, loss of control of the client’s IP. Suck loss may result in the absence of a clear commitment by the service provider to safeguard access to the data. Additionally, permanent and complete erasure or prompt return of data when such data stands no longer used or of value or need for the services (as discussed further below in connection with the end of term assistance).</p>
<p>The middle-ground private or hybrid model typically provides that the client retains ownership of data (and its associated IP) provided or processed through the cloud services and ‘use features’ a content license to the service provider. It is essential for business clients with high-value IP,<a href="#_ftn40" name="_ftnref40">[40]</a> business data and trade secrets to have an express provision in the contract covering IP ownership, the scope of the content license, termination right of the content license and return and removal of data upon conclusion. Unlike the standard public cloud model, such rights may stand protected in middle-ground private or hybrid model contracts.</p>
<p>IP considerations also drive some other issues previously seen in cloud agreements. For instance, preservation of confidentiality and novelty critical to IP protection highlights the importance of contracts clearly defining access rights. The use of end-to-end encryption to prevent unauthorised access and preserve the data’s privacy and originality can also stand utilised to mitigate risk. Further, because IP protection is primarily territorial (local law determined), the storage location of cloud data or processing significantly impacts the IP rights. Suppose the service provider’s servers storing client data stand in a country where the customer data remains unprotected under local IP laws or where IP rights are difficult to enforce. In that case, risks will increase if the client’s IP is hacked locally or misappropriated. Hence, the location of data storage by the service provider is a significant risk factor for IP-rich clients, making countries with solid IP regimes preferred and assurances that the client’s data will remain there substantial.</li>
<li><em> Developed materials and ownership.</em> Ownership and developed material involve the extent to which the service contract provides that the client retains possession and proprietorship of the IPRs of the data (including metadata) and materials that may stand developed through the provision of the services.
<p>The traditional outsourcing model clearly defines and allocates the client’s and the service provider’s respective rights in the IP developed through the performance of the services. Once ownership is established and set in the developed materials, either restrictive license provisions for such IP or the contact’s general provisions respecting licenses to the parties’ IP may apply.</p>
<p>Standard public cloud solutions classically allow clients to retain ownership of their data. Still, they frequently do not define ownership of data created (even derivative) or IP developed in the provision of the services. Such arrangements raise risks of unauthorised use and potential loss of ownership and control.<a href="#_ftn41" name="_ftnref41">[41]</a></p>
<p>Typically, the middle-ground private or hybrid cloud contract provides that the client retains possession and proprietorship of any data provided, processed, or created through cloud services. These provisions frequently also offer limited rights to ownership of customisations of the services (such as customised software interface), with license-back (to the service provider) privileges.</li>
<li><em>Non-infringement warranty and indemnity</em>. Such issues involve the extent to which the cloud contract requires the service provider to warrant that the cloud services do not violate the IPRs of a third party and guarantee the client against costs and damages associated with third parties party claims of such infringement. This issue encompasses the implied warranty and indemnity by the client to the service provider against claims by a third party that the data or other material provided by the client, or the use to which the client puts the cloud services, oversteps the third party’s IPRs.
<p>The traditional outsourcing contract contains a service provider’s warranty of non-infringement and indemnities against third party claim(s) that the cloud services (at least when used as contemplated under the contract) infringe the third party’s IPRs. Less frequently, the agreement may provide for a warranty and indemnities from the client that data they provide (and make available for use by the service provider), or uses to which they put the services, infringe third party IPRs. Some significant ancillary issues associated with any indemnity arise from outsourcing. An example: Is an extent to which the protection is subjected to, or excluded from some, or all of the limitations of liability contained in the contract and the scope of remedies available to the indemnitee in the event of an actual or alleged infringement, as discussed further below. Indemnities are frequently the subject of meaningful negotiation in any outsourcing transaction.<a href="#_ftn42" name="_ftnref42">[42]</a></p>
<p>The public cloud solution regularly entirely omits warranties and indemnities by the service provider and broadly bends such issues within the general ‘as is’ condition under the provided services.<a href="#_ftn43" name="_ftnref43">[43]</a> Nonetheless, it is more common that standard public cloud solutions include indemnities and even warranties from the client, particularly regarding data or materials provided or used by the client in connection with the cloud services. These aspects come in addition to their appropriate infringement notice and take-down procedures imposed in compliance with the safe harbour provisions of the USA’s DMCA 1998, Electronic Commerce Directive 2000/31/EC<a href="#_ftn44" name="_ftnref44">[44]</a> or other similar legislations.</p>
<p>The middle-ground private or hybrid cloud often includes some level of provider infringement indemnification but less frequently includes warranties of non-infringement. Typically this compensation is limited to transgression associated with the deployment of the cloud services, but it is often narrowly scoped and subject to far-reaching exceptions. As with the standard public cloud solutions, middle-ground private or hybrid cloud solutions frequently impose a greater level of client non-infringement warranties and indemnities, including an arrangement to the service provider’s notice and take-down policy.</li>
<li><em> Remedies for infringement:</em> The issue involves the scope and nature of the solutions provided should there be a claim of infringement against the client (or service provider in the case of a non-infringement warranty or indemnity by the client) arising from the provision or use of the cloud services. The remedies provided under such an indemnity are a critical component of the compensation itself, as they define the scope of potential liability and responsibility of the Indemnitor.
<p>The traditional outsourcing contract typically provides express protection remedies if the services infringe third party rights. These solutions consist of the obligation to indemnify for costs of defence and any judgement or settlement. In addition, it is to either obtain any necessary rights to continue the provision and use of the services or to replace or modify the services so that they do not infringe a party’s rights without a material decrease in functionality. Frequently, the actual choice of these remedies is the election of the service provider. With its primary focus on services, the outsourcing model typically does not allow the service provider the right to cease performance (withdraw the service). This situation leaves the provider obligated to either obtain the necessary rights or modify or replace the infringing portion of the services, at the risk of breaching the contract for its failure to do one or the other. A related issue of significance is whether such defined remedies are the exclusive remedies of the indemnitee for any infringement or if others are available, such as the ability to terminate the agreement or make a claim for other damages. A warranty of non-infringement maybe it’s self-serve as the basis of the exercise of rights under the contract in the event it is breached, including a claim of material default that may give rise to a termination right.<a href="#_ftn45" name="_ftnref45">[45]</a></p>
<p>The standard utility cloud terms of service typically offer little or no committed remedy in case of infringement, which is consistent with the service provider’s natural right to terminate the provision of the services unilaterally.<a href="#_ftn46" name="_ftnref46">[46]</a></p>
<p>The middle-ground private or hybrid cloud contract, more likely than not, includes some remedies in the case of infringement. These solutions typically include the modification or replacement alternatives found in the traditional outsourcing agreement. However, frequently, the service provider has a right to terminate the services if they determine neither of these options to be commercially viable. Usually with a refund to the client of amounts paid, sometimes reduced based upon use up to the time of termination.</li>
</ol>
<h5><strong>Protection of Service Continuousness</strong></h5>
<ol>
<li><em>Personnel continuity:</em> This issue involves how the service contract assures the client that the service provider will seek to maintain key personnel to provide support for the services. Such continuity can be an essential element in guaranteeing the client that the services will stand appropriately performed.
<p>The traditional outsourcing model identifies a group of service provider personnel or positions that the service provider is obliged to maintain for service delivery to the client over a defined period and often offers protection on a service provider’s average personnel turnover.<a href="#_ftn47" name="_ftnref47">[47]</a></p>
<p>The middle-ground private or hybrid model may provide some commitment to continuity for a limited number of key personnel for mainly crucial functions or activities.</li>
<li><em>Non-suspension/interruption.</em> This issue involves the extent to which the contract expressly prohibits the service provider from interrupting or suspending the services.
<p>The traditional outsourcing contract prohibits any suspension of services (subject to defined termination rights by the service provider) and requires detailed business continuity planning. Outsourcing contracts typically also state that under no circumstances can the service provider withhold the client’s data, including specifically to gain an advantage in the event of a dispute.<a href="#_ftn48" name="_ftnref48">[48]</a></p>
<p>Consistent with the lack of overall commitment in respecting service provision, the standard public cloud terms of service frequently expressly acknowledge potential interruptions of services and do not commit to business continuity.</p>
<p>The middle-ground private or hybrid cloud contract regularly provides special rights to limit users to protect the integrity of the services. It may contain provisions regarding business continuity procedures and practices.</li>
</ol>
<h5><strong>Term-end Protection</strong></h5>
<ol>
<li><em>Termination assistance.</em> Exit or termination agreements represent a critical set of considerations associated with adopting services, especially in business operations. It is essential that, as part of a client’s adoption of a cloud solution, they carefully evaluate and provide for a viable exit strategy, considering the support they can expect from the service provider and the demands they expect to face at that time. The provisions in service contracts concerning the parties’ respective obligations when the service or agreement stands terminated are crucial. The client must evaluate such responsibilities in the light of their anticipated options when the facilities end. It is essential in the cloud context where the client may have transferred, shared or stored data in the cloud or developed a degree of reliance on the cloud services as part of their business operations. This issue involves the extent to which the contract commits the service provider to assist the client at the termination of the services in association with the client’s changeover to the facilities in-house or successor service provider.<a href="#_ftn49" name="_ftnref49">[49]</a>
<p>The traditional outsourcing contract contains detailed provisions addressing the service provider’s obligations to support the client in transitioning to successor provision at the termination of all or part of the services (including the extension of services to the extent that additional time stands required for the successor agreements). These provisions aim to ensure the client has access to appropriate support to avoid the disruption of its operations. Such comprehensive requirements address most of the elements of service delivery from the return of the client’s data to the infrastructure (equipment, software and personnel) used in the service delivery.</p>
<p>The standard public cloud terms of service typically provide a right for the client to access its data in cases of termination, except in some cases where the decision is by the service provider for the customer’s default. Consistent with the overall absence of service assurances in the standard public cloud model, contracts do not provide further assistance to avoid disrupting the client’s operations.</p>
<p>The middle-ground private or hybrid cloud model may allow the client to extend services and some reasonable assistance in the transition to a successor agreement.</li>
<li><em>Data transmission format for data return:</em> One of the most critical components of an end of service changeover is the service provider’s hand back, retention and deletion of client data. Client data must stand handed back in a format that is reasonably accessible and compatible with the systems they will be using or at least have access to for conversion purposes during the termination of the cloud services.<a href="#_ftn50" name="_ftnref50">[50]</a></li>
<li><em>Data security for data return:</em> Data security must stand considered at all stages of engaging cloud services, including the termination step. At the time of conclusion, clients should understand the level of information protection applied in the transmission of such data and stand prepared for appropriate remedial action in the event of data leakage. Addressing these issues at the time of termination is probably already too late for practical The client must assess the whole life-cycle risks associated with any cloud solution from the time of initial adoption.</li>
<li><em>Data retention (by service providers):</em> Even where service providers have committed to deleting client data upon termination, and in reality permanently, this process may involve an extended period, often up to three months before such data stands removed. Additionally, service providers may retain backup copies, logs and other information which may have stood shared with other users (such as a photo on Facebook) for a more extended period. However, it is worth noting that data privacy laws in many jurisdictions prohibit the retention of personal data for long periods.<a href="#_ftn51" name="_ftnref51">[51]</a></li>
<li><em>Data deletion and information removal</em>: The removal of information and data in the cloud is a much more complicated process than a mere click of a button. The existing standard terms offered by cloud service providers (particularly public cloud) commonly do not specify in any detail the arrangements for data deletion or information removal upon the termination of the service contract. Even where the provider has offered to delete the client’s data at the client’s request, it’s challenging to achieve complete and permanent erasure.<a href="#_ftn52" name="_ftnref52">[52]</a> Complete deletion of data is even more challenging in a cloud environment where multiple storages and processing locations are involved.<a href="#_ftn53" name="_ftnref53">[53]</a> The challenges associated with securely deleting data and information in the cloud are another consideration that clients must carefully evaluate as part of their decision to adopt cloud services.</li>
<li><em>Other termination support issues. </em>On termination, cloud service providers will offer limited dissolution or termination support. Under the existing market practice, enterprise solution clients should develop and maintain a transformation separation plan through the life-cycle of the cloud services. That plan should stand based on the assistance available from the service provider, giving them adequate assurance that they will stand able to successfully transition the services back in-house or to a successor provider.</li>
</ol>
<h5><strong>Conclusion</strong></h5>
<p>It is essential to recognise that characterisation of a particular cloud offering such as that of the public cloud versus private cloud or hybrid cloud is undoubtedly a significant over-simplification that does not tell the whole story when it comes to license or other contract rights. There is considerable variability among cloud offerings within each category. The result is that the client’s due diligence is essential. The client must read the service descriptions for such vital aspects as processing locations, data backups, redundancy, encryption, security, transition process and options for client control. Even beyond explicit contractual assurances, the service provider’s form of contract often provides significant insight into how the service is structured. In cloud solutions, this structure often defines the ability of the service provider to meet clients’ requirements.</p>
<p>Any service agreement carries certain risks for the parties that may be influenced or driven by practical realities in the solution’s technological structure and operations. These risks can be significantly exacerbated for the client by the lack of certainty (or understanding) of the contract or license terms, leading to poor decision-making in the adoption of cloud solutions. One of the most significant risks associated with accepting any cloud solution by a client is a failure to understand the full range of their rights, responsibilities and requirements related to the solution and its operations. In this sense, cloud computing and cloud services present specific differences from traditional services and licensing driven by technological structure and function. Previous experience, based on prior service and licensing arrangements, offers valuable signposts for charting responsible approaches to the adoption of any cloud solution.</p>
<hr />
<p><a href="#_ftnref1" name="_ftn1">[1]</a> KNAPP, K. <em>Top considerations for choosing a cloud provider.</em> Search Cloud Computing. <a href="http://searchcloudcomputing.techtarget.com/">http://searchcloudcomputing.techtarget.com/</a></p>
<p><a href="#_ftnref2" name="_ftn2">[2]</a> SILALASHI, J.M. <em>Drafting a cloud computing contract</em>. Academia. <a href="http://www.academia.edu/">http://www.academia.edu/</a></p>
<p><a href="#_ftnref3" name="_ftn3">[3]</a> <em>Ibid.</em></p>
<p><a href="#_ftnref4" name="_ftn4"></a> <a href="#_ftnref5" name="_ftn5">[5]</a> MARSH. <em>The cloud risk framework, informing decisions about moving to the cloud</em>. Marsh and McLennan. <a href="http://f.datasrvr.com/">http://f.datasrvr.com/</a></p>
<p><a href="#_ftnref6" name="_ftn6">[6]</a> BRADSHAW, S. et al. <em>The terms they are a –changin’. Watching cloud contracts take shape. The Center for Technology Innovation</em>. The Brookings Institution. <a href="https://www.brookings.edu/">https://www.brookings.edu/</a>.</p>
<p><a href="#_ftnref7" name="_ftn7">[7]</a> <em>Ibid. </em></p>
<p><a href="#_ftnref8" name="_ftn8">[8]</a> FOLEY. <em>Cloud computing: A practical framework for managing cloud computing risk</em>. Foley. <a href="https://www.foley.com/">https://www.foley.com/</a></p>
<p><a href="#_ftnref9" name="_ftn9">[9]</a> SILALASHI, J.M. <em>Drafting a cloud computing contract</em>. Academia. <a href="http://www.academia.edu/">http://www.academia.edu/</a></p>
<p><a href="#_ftnref10" name="_ftn10">[10]</a> CRANE, J. <em>The death of outsourcing and other IT management trends. </em>Forbes. <a href="http://www.forbes.com/">http://www.forbes.com/</a></p>
<p><a href="#_ftnref11" name="_ftn11">[11]</a> Note: For the purpose of the discussion and as a point of reference, a representative private or hybrid cloud solution could be cloud provision of an enterprise application, as seen in business-focused SaaS offerings.</p>
<p><a href="#_ftnref12" name="_ftn12">[12]</a> The client-to-cloud service provider grant is especially important and is filled with critical issues such as potential loss of data or control and regulatory compliance.</p>
<p><a href="#_ftnref13" name="_ftn13">[13]</a> JAEGER, P., LIN, J. and GRIMES, M. <em>Cloud computing and information policy: Computing in a policy cloud?</em> Journal of Information Technology and Politics. <a href="http://www.tandfonline.com/">http://www.tandfonline.com/</a></p>
<p><a href="#_ftnref14" name="_ftn14">[14]</a> <em>Ibid. </em></p>
<p><a href="#_ftnref15" name="_ftn15">[15]</a> HON, W.K. et al. <em>Negotiating cloud contracts, looking at clouds from both sides now.</em> Stanford Technology Law Review. <a href="https://journals.law.stanford.edu/">https://journals.law.stanford.edu/</a></p>
<p><a href="#_ftnref16" name="_ftn16">[16]</a> FOLEY. <em>Cloud computing: A practical framework for managing cloud computing risk</em>. Foley. <a href="https://www.foley.com/">https://www.foley.com/</a></p>
<p><a href="#_ftnref17" name="_ftn17">[17]</a> <em>Ibid.</em></p>
<p><a href="#_ftnref18" name="_ftn18">[18]</a> WALKER, S. and GREENE C. <em>‘What constitutes a material breach’.</em> The Lawyer. [<a href="https://www.thelawyer.com/">https://www.thelawyer.com/</a></p>
<p><a href="#_ftnref19" name="_ftn19">[19]</a> FOLEY. <em>Cloud computing: A practical framework for managing cloud computing risk.</em> Foley. <a href="https://www.foley.com/">https://www.foley.com/</a></p>
<p><a href="#_ftnref20" name="_ftn20">[20]</a> SILALASHI, J.M. (2011) <em>Drafting a cloud computing contr</em>act. Academia. <a href="http://www.academia.edu/">http://www.academia.edu/</a> [Accessed 12 March 2016].</p>
<p><a href="#_ftnref21" name="_ftn21">[21]</a> FOLEY. (n.d.) <em>Cloud computing: A practical framework for managing cloud computing risk.</em> Foley. <a href="https://www.foley.com/">https://www.foley.com/</a></p>
<p><a href="#_ftnref22" name="_ftn22">[22]</a> <em>Ibid.</em></p>
<p><a href="#_ftnref23" name="_ftn23">[23]</a> JAEGER, P., LIN, J. and GRIMES, M. <em>Cloud computing and information policy: Computing in a policy cloud?</em> Journal of Information Technology and Politics. <a href="http://www.tandfonline.com/">http://www.tandfonline.com/</a>.</p>
<p><a href="#_ftnref24" name="_ftn24">[24]</a> Such provisions are based on service levels entitling the client to terminate the service contract which may include such a right when: (i) the service performance level drops below a defined point in any measurement period; or (ii) a certain value of service credit becomes payable within a prescribed period (for example, in one year); or (iii) a service level is not met for a certain number of consecutive measurement periods.</p>
<p><a href="#_ftnref25" name="_ftn25">[25]</a> BRADSHAW, S., MILLARD, C. and WALDEN, I. <em>The terms they are a -changin’. Watching cloud contracts take shape. The Center for Technology Innovation</em>. The Brookings Institution. <a href="https://www.brookings.edu/">https://www.brookings.edu/</a>.</p>
<p><a href="#_ftnref26" name="_ftn26">[26]</a> For example: City of Los Angeles. <em>Professional Services Contract between the City of Los Angeles and Computer Science Corp. for the SaaS E-mail and Collaboration Solution.</em> SECS. <a href="https://sites.google.com/">https://sites.google.com/</a>.</p>
<p><a href="#_ftnref27" name="_ftn27">[27]</a> An example of some of the key service quality metrics such as: (i) availability metrics; (ii) outage duration metric; (iii) mean-time between failures metric; (iv) reliability rate metric; (v) network capacity metric; (vi) storage device capacity metric; (vii) server capacity metric; (viii) web application capacity metric. See also Mc KENDRICK, J. <em>16 key service quality metrics to boost cloud engagements</em>. ZDNET. <a href="http://www.zdnet.com/">http://www.zdnet.com/</a>.</p>
<p><a href="#_ftnref28" name="_ftn28">[28]</a> SILALASHI, J.M. <em>Drafting a cloud computing contract. </em>Academia. <a href="http://www.academia.edu/">http://www.academia.edu/</a>.</p>
<p><a href="#_ftnref29" name="_ftn29">[29]</a> STONEBRAKER, M. “One Size Fits All”: An idea whose time has come and gone. Computer Science and Artificial Intelligence Laboratory. MIT. <a href="https://cs.brown.edu/~ugur/fits_all.pdf">https://cs.brown.edu/~ugur/fits_all.pdf</a>.</p>
<p><a href="#_ftnref30" name="_ftn30">[30]</a> FOLEY. Cloud computing: A practical framework for managing cloud computing risk. <a href="https://www.foley.com/">https://www.foley.com/</a></p>
<p><a href="#_ftnref31" name="_ftn31">[31]</a> CLARKE, G. ‘Apple’s iCloud runs on Microsoft and Amazon services: Who says Azure isn’t cool and trendy now’. The Register. <a href="http://www.theregister.co.uk/">http://www.theregister.co.uk/</a>.</p>
<p><a href="#_ftnref32" name="_ftn32">[32]</a> FOLEY. Cloud computing: A practical framework for managing cloud computing risk. <a href="https://www.foley.com/">https://www.foley.com/</a></p>
<p><a href="#_ftnref33" name="_ftn33">[33]</a> CATTEDDU, D. and HOGBEN, G. <em>Cloud computing, benefits, risks and recommendations for information security. The European Network and Information Security Agency. </em>(ENISA). <a href="https://resilience.enisa.europa.eu/">https://resilience.enisa.europa.eu/</a>. See also <em>Basic guidelines for contracts and contract risk management</em>, Harvard University. <a href="http://rmas.fad.harvard.edu/">http://rmas.fad.harvard.edu/</a>.</p>
<p><a href="#_ftnref34" name="_ftn34">[34]</a> DE SILVA, S. <em>5th</em><em> Meeting of European Commission Expert Group on Cloud Computing Contracts Liability Discussion Paper</em>. EC Europa. <a href="http://ec.europa.eu/">http://ec.europa.eu/</a>.</p>
<p><a href="#_ftnref35" name="_ftn35">[35]</a> For example: We undertake that the Services will be performed with reasonable skill and care. This undertaking shall not apply to the extent of any non-conformance which is caused by your use of the Services contrary to our instructions or these Terms of Service, or any alternation or modification made to the Services or the software used in the provision of the Services by a third party who is not authorised by us. We do not warrant that use of the Services will be error-free, and you agree that it is not our obligation to maintain, support or update the Services (except where necessary to carry out our other obligations under these Terms of Service), HITCH Software Platform. <em>Provider terms of service</em>. Hitch HQ. <a href="https://www.hitchhq.com/">https://www.hitchhq.com/</a>.</p>
<p><a href="#_ftnref36" name="_ftn36">[36]</a> FOLEY. <em>Cloud computing: A practical framework for managing cloud computing risk</em>. Foley. <a href="https://www.foley.com/">https://www.foley.com/</a>.</p>
<p><a href="#_ftnref37" name="_ftn37">[37]</a> HON, W.K. et al. <em>Negotiating cloud contracts, looking at clouds from both sides now</em>. Stanford Technology Law Review. <a href="https://journals.law.stanford.edu/">https://journals.law.stanford.edu/</a>.</p>
<p><a href="#_ftnref38" name="_ftn38">[38]</a> For example: Your Material and Proprietary Rights You Give Us. You shall own all right, title and interest in and to your API, API documentation and any material, information or data you provide or otherwise transmit to us or to others using the Platform or the Services (“Your Material”). We claim no intellectual property rights in and to Your Material; however, we require, and you hereby grant us, a worldwide, non-exclusive, royalty-free license to store, use, reproduce, display and transmit Your Material to the extent necessary to enable your use of the Platform and the Services. This license shall remain in effect until and unless these Terms of Service are terminated by you or us. You shall have sole responsibility for the legality, reliability, integrity, accuracy and quality of Your Material. Hitch Software Platform. <em>Provider terms of service.</em> Hitch HQ. <a href="https://www.hitchhq.com/">https://www.hitchhq.com/</a>.</p>
<p><a href="#_ftnref39" name="_ftn39">[39]</a> For example: License from You. Except for material we may license to you, Apple does not claim ownership of the materials and/or content you submit or make available on the Service. However, by submitting or posting such Content on areas of the Service that are accessible by the public or other users with whom you consent to share such Content, you grant Apple a worldwide, royalty-free, non-exclusive license to use, distribute, reproduce, modify, adapt, publish, translate, publicly perform and publicly display such Content on the Service solely for the purpose for which such Content was submitted or made available, without any compensation or obligation to you. You agree that any Content submitted or posted by you shall be your sole responsibility, shall not infringe or violate the rights of any other party or violate any laws, contribute to or encourage infringing or otherwise unlawful conduct, or otherwise be obscene, objectionable, or in poor taste. By submitting or posting such Content on areas of the Service that are accessible by the public or other users, you are representing that you are the owner of such material and/or have all necessary rights, licenses, and authorization to distribute it. Apple Inc. <em>iCloud terms and conditions</em>. Apple Legal. <a href="http://www.apple.com/">http://www.apple.com/</a>.</p>
<p><a href="#_ftnref40" name="_ftn40">[40]</a> HILLELSON, L. (<em>Making the business case for the media industry transition to IP.</em> Broadcasting and Cable. <a href="https://www.cisco.com/">https://www.cisco.com/</a>.</p>
<p><a href="#_ftnref41" name="_ftn41">[41]</a> FOLEY. <em>Cloud computing: A practical framework for managing cloud computing risk.</em> <a href="https://www.foley.com/">https://www.foley.com/</a>.</p>
<p><a href="#_ftnref42" name="_ftn42">[42]</a> BRADSHAW, S., MILLARD, C. and WALDEN, I. <em>The terms they are a –changin’. Watching cloud contracts take shape. The Center for Technology Innovation</em>. The Brookings Institution. <a href="https://www.brookings.edu/">https://www.brookings.edu/</a>.</p>
<p><a href="#_ftnref43" name="_ftn43">[43]</a> Anonymous. <em>Terms of service,</em> Dropbox. <a href="https://www.dropbox.com/">https://www.dropbox.com/</a>. Section ‘Services “AS IS”.</p>
<p><a href="#_ftnref44" name="_ftn44">[44]</a> <em>The Digital Millennium Copyright Act of 1998. U.S. Copyright Office Summary.</em> Copyright Government. <a href="https://www.copyright.gov/">https://www.copyright.gov/</a>.</p>
<p>Also see <em>Directive 2000/31/EC 2000 Art. 3<strong> Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (&#8216;Directive on electronic commerce&#8217;). </strong></em><strong>Eur-Lex. </strong><a href="http://eur-lex.europa.eu/">http://eur-lex.europa.eu/</a>.</p>
<p><a href="#_ftnref45" name="_ftn45">[45]</a> BRADSHAW, S., MILLARD, C. and WALDEN, I. <em>The terms they are a –changin’. Watching cloud contracts take shape. The Center for Technology Innovation. </em>The Brookings Institution. <a href="https://www.brookings.edu/">https://www.brookings.edu/</a>.</p>
<p><a href="#_ftnref46" name="_ftn46">[46]</a> SILALASHI, J.M. <em>Drafting a cloud computing contract.</em> Academia. <a href="http://www.academia.edu/">http://www.academia.edu/</a>.</p>
<p><a href="#_ftnref47" name="_ftn47">[47]</a> FOLEY. (n.d.) <em>Cloud computing: A practical framework for managing cloud computing risk</em>. Foley. <a href="https://www.foley.com/">https://www.foley.com/</a> [Accessed 10 March 2016].</p>
<p><a href="#_ftnref48" name="_ftn48">[48]</a> <em>Ibid.</em> See also CLOUD STANDARDS CUSTOMER COUNCIL. (2016). <em>Public cloud service agreements: What to expect and what to negotiate, Version 2.0.1.</em> CSCC. <a href="http://www.cloud-council.org/deliverables/CSCC-Public-Cloud-Service-Agreements-What-to-Expect-and-What-to-Negotiate.pdf">http://www.cloud-council.org/deliverables/CSCC-Public-Cloud-Service-Agreements-What-to-Expect-and-What-to-Negotiate.pdf</a> [Accessed 22 September 2016].</p>
<p><a href="#_ftnref49" name="_ftn49">[49]</a> FOLEY. <em>Cloud computing: A practical framework for managing cloud computing risk</em>. Foley. <a href="https://www.foley.com/">https://www.foley.com/</a></p>
<p>See also CLOUD STANDARDS CUSTOMER COUNCIL. <em>Public cloud service agreements: What to expect and what to negotiate, Version 2.0.1. </em>CSCC. <a href="http://www.cloud-council.org/deliverables/CSCC-Public-Cloud-Service-Agreements-What-to-Expect-and-What-to-Negotiate.pdf">http://www.cloud-council.org/deliverables/CSCC-Public-Cloud-Service-Agreements-What-to-Expect-and-What-to-Negotiate.pdf</a>.</p>
<p><a href="#_ftnref50" name="_ftn50">[50]</a> <em>Ibid.</em></p>
<p><a href="#_ftnref51" name="_ftn51">[51]</a> EURO CLOUD. <em>Major mistakes in data privacy – data protection in the cloud</em>. Euro Cloud. <a href="https://www.eurocloud.org/">https://www.eurocloud.org/</a>. Notes from paper. Right to deletion of data and obligation to notify of data breaches. The right to deletion of data is problematic as a result of organisational deficits and the supply chain. 63% of cloud providers maintain data indefinitely or have no provisions for data retention in their terms and conditions. Another 23% of cloud providers maintain the right in their terms and conditions to share data with another third party, making it even more difficult to ensure all copies are deleted, because of the numerous parties with whom a cloud provider shares data.</p>
<p><a href="#_ftnref52" name="_ftn52">[52]</a> Anonymous. <em>Terms of service, security</em>. Dropbox. <a href="https://www.dropbox.com/">https://www.dropbox.com/</a>. Section ‘File recovery and version history’. Dropbox saves a history of all deleted and previous versions of files, and allows you to restore them for up to 30 days. Extended version history is available as a Dropbox Plus subscription add-on. Dropbox Business users have 120 days to recover deleted files.</p>
<p><a href="#_ftnref53" name="_ftn53">[53]</a> <em>Ibid.</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>General Data Protection Regulation (EU) and Protection of Personal Information Act (SA) &#8211; GDPR &#038; POPIA</title>
		<link>https://jacksonattorneys.co.za/general-data-protection-regulation-eu-and-protection-of-personal-information-act-sa-gdpr-popia/</link>
		
		<dc:creator><![CDATA[Allan Jackson]]></dc:creator>
		<pubDate>Mon, 11 Oct 2021 06:26:47 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">http://jacksonattorneys.co.za/?p=271</guid>

					<description><![CDATA[Principals, fines &#38; penalty discussion points (September 2021) In today’s working environment, dealing with data subject information and compliance with local and international regulations is challenging. To add to the challenge of understanding the local and international rules, we face the challenge of laws from other countries and understanding their role locally. The GDPR, in [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><strong>Principals, fines &amp; penalty discussion points (September 2021)</strong> In today’s working environment, dealing with data subject information and compliance with local and international regulations is challenging. To add to the challenge of understanding the local and international rules, we face the challenge of laws from other countries and understanding their role locally. The GDPR, in particular, is one of those regulations which has a long international arm that impacts local operations in respect of how operators and processors handle EU citizens data of the EU. This article aims to introduce the basic principles and data subjects rights of the GDPR and the POPIA conditions. With this in mind, we want to create awareness of the local regulations and introduce some international rules that will impact how we handle offshore data subjects information and the possible issues related to such data breaches. In future articles, we will explore more of these crucial points in detail. <strong>GDPR Principles and Data Subject rights</strong> The GDPR came into operation at the end of May 2018 and stood successfully applied across all EU member states. The impact of the regulation on data handling by controllers and processors has been extensive. In particular, the onus on third-party data processors outside of the EU. The responsibility of these third-party processors is significant as the GDPR applies in all aspects in the handling and processing of EU citizens data. Therefore it is critical to ensure that if you are processing EU citizens data that you comply with the GDPR. The GDPR principles and the data subjects rights stand set out in Article 5 of the GDPR. The six principles that should apply when collecting or processing personal data must stand read in conjunction with data subjects rights. Six Principles:</p>
<ol>
<li>Personal data must be processed lawfully, fairly and transparently.</li>
<li>Personal data can only stand collected for specified, explicit and legitimate purposes.</li>
<li>Personal data must be adequate, relevant and limited to what is necessary for processing.</li>
<li>Personal data must be accurate and kept up to date.</li>
<li>Personal data must be kept in a form such that the data subject can stand identified only as long as necessary for processing.</li>
<li>Personal data must stand processed in a manner that ensures its security.</li>
</ol>
<p>Eight Rights</p>
<ol>
<li>The right to be <strong>Informed</strong></li>
<li>The right of <strong>Access</strong></li>
<li>The right to <strong>Rectification</strong></li>
<li>The right to <strong>Restrict</strong> processing</li>
<li>The right to Data <strong>Portability</strong></li>
<li>The right to <strong>Object</strong></li>
<li>Rights concerning automated decision making and <strong>Profiling</strong></li>
</ol>
<p>It is worth noting that the data controller is responsible for demonstrating that the principles and data subject rights stand implemented, and they must ensure the same for any third-party data processors with whom they contract. <strong>Guide to GDPR penalties tier 1 and tier 2 infringement</strong> Some of the GDPR Articles’ if found to have stood violated, carry the maximum administrative penalty as noted, being <strong>up to four percentage points of annual global turnover or €20 million, whichever is the higher</strong>. NOTE: <strong><em>Infringements of the requirements concerning international transfers are also subject to this higher penalty</em></strong><em>.</em> The higher penalties apply to the following Articles;</p>
<ul>
<li>5 – Principles relating to the processing of personal data</li>
<li>6 – Lawfulness of processing</li>
<li>7 – Conditions for consent</li>
<li>9 – Processing of special categories of personal data</li>
<li>12 – Transparent information, communication and modalities for the exercise of the rights of the data subject</li>
<li>13 – Information to stand provided where personal data stand collected from the data subject</li>
<li>14 – Information to stand provided where personal data have not stood obtained from the data subject</li>
<li>15 – Right of access by the data subject</li>
<li>16 – Right to rectification</li>
<li>17 – Right to erasure (‘right to stand forgotten’)</li>
<li>18 – Right to restriction of processing</li>
<li>19 – Notification obligation regarding rectification or erasure of personal data or restriction of processing</li>
<li>20 – Right to personal data</li>
<li>21 – Right to object</li>
<li>22 – Automated individual decision-making, including profiling</li>
</ul>
<p>The lower tier of penalty for infringing other Articles of the Regulation, which stands calculated at up to <strong>two percentage points of global annual turnover or €10 million</strong> – again, whichever is the higher. The penalty will apply to the following Articles;</p>
<ul>
<li>8 – Conditions applicable to child’s consent concerning information society services</li>
<li>11 – Processing which does not require identification</li>
<li>25 – Data protection by design and by default</li>
<li>26 &#8211; Joint controllers</li>
<li>27 – Representatives of controllers or processors not established in the Union</li>
<li>28 – Processor</li>
<li>29 – Processing under the authority of the controller or processor</li>
<li>30 – Records of processing activities</li>
<li>31 – Cooperation with the supervisory authority</li>
<li>32 – Security of processing</li>
<li>33 – Notification of personal data breach to the supervisory authority</li>
<li>34 – Communication of a personal data breach to the data subject</li>
<li>35 – Data protection impact assessment</li>
<li>36 – Prior consultation</li>
<li>37 – Designation of data protection officer</li>
<li>38 – Position of the data protection officer</li>
<li>39 – Tasks of the data protection officer</li>
<li>42 – Certification</li>
<li>43 – Certification bodies</li>
</ul>
<p><strong>POPIA</strong> In contrast to the GDPR, the POPIA only has eight conditions (or so-called principles) to be adhered to when processing data subjects information. The eight conditions for the lawful processing of Personal Information by or for a responsible party are the following:</p>
<ol>
<li>‘‘<strong>Accountability</strong>’’, as referred to in section 8;</li>
<li>‘‘<strong>Processing limitation</strong>’’, as referred to in sections 9 to 12;</li>
<li>‘‘<strong>Purpose speciﬁcation</strong>’’, as referred to in sections 13 and 14;</li>
<li>‘‘<strong>Further processing limitation</strong>’’, as referred to in section 15;</li>
<li>‘‘<strong>Information quality</strong>’’, as referred to in section 16;</li>
<li>‘‘<strong>Openness</strong>’’, as referred to in sections 17 and 18;</li>
<li>‘‘<strong>Security safeguards</strong>’’, as referred to in sections 19 to 22; and</li>
<li>‘‘<strong>Data subject participation</strong>’’, as referred to in sections 23 to 25.</li>
</ol>
<p>The conditions stand further expanded in the various sections of the Act. The table below is a quick guide to the related sections found in POPIA concerning the eight conditions for lawfully processing personal information.</p>
<ol>
<li>Personal data must be processed lawfully, fairly and transparently.
<ol>
<li>POPI Act: Condition 2 – Lawfulness of processing section 9 to 12</li>
<li>POPI Act: Condition 6 – Openness section 17 and 18</li>
</ol>
</li>
<li>Personal data can only stand collected for specified, explicit and legitimate purposes.
<ol>
<li>POPI Act: Condition 3 – Purpose specific sections 13 and 14</li>
<li>POPI Act: Condition 4 – Further processing limitation section 15</li>
</ol>
</li>
</ol>
<ul>
<li>Personal data must be adequate, relevant and limited to what is necessary for processing.
<ol start="12">
<li>POPI Act: Condition 2 &#8211; Purpose specific section 9 to 12.</li>
<li>POPI Act: Condition 3 – Purpose particular sections 13 and 14</li>
<li>POPI Act: Condition 5 – Information quality section 16</li>
</ol>
</li>
</ul>
<ol>
<li>Personal data must be accurate and kept up to date.
<ol>
<li>POPI Act: Condition 8 – Data subject participation section 23 to 25</li>
</ol>
</li>
<li>Personal data must be kept in a form such that the data subject can stand identified only as long as necessary for processing.
<ol>
<li>POPI Act:</li>
</ol>
</li>
<li>Personal data must stand processed in a manner that ensures its security.
<ol>
<li>POPI Act: Condition 7 &#8211; Security Safeguards section 19 to 22</li>
</ol>
</li>
</ol>
<p><strong>Guide to POPIA Penalties</strong> As with the GDPR, the POPI Act also provides for any infringement of personal data. Such offences or failure of a ‘Duty of Care’ to provide data protection can result in various penalties or fines. Below is an extract of the sections within the POPI Act of offences, penalties, and administrative fines, which may apply if a responsible person processing personal data breaches the regulation.</p>
<ol start="100">
<li>Obstruction of Regulator</li>
<li>Breach of conﬁdentiality</li>
<li>Impediment or obstruction of execution of a warrant</li>
<li>Failure to comply with enforcement or information notices</li>
<li>Offences by witnesses</li>
<li>Unlawful acts by the responsible party in connection with an account number</li>
<li>Unlawful acts by third parties in connection with an account number</li>
<li>Penalties</li>
<li>Magistrate’s Court jurisdiction to impose penalties</li>
<li><strong>Administrative ﬁnes</strong></li>
</ol>
<p>Expanding on section 109 Administrative fines to highlight what possible penalties may stand applied for data breaches.</p>
<ul>
<li>If a responsible party stands alleged to have committed an offence in terms of this Act, the Regulator may cause to be delivered by hand to that person (from now on referred to as the infringer) an infringement notice which must contain the particulars contemplated in subsection (2).</li>
<li>A notice referred to in subsection (1) must
<ul>
<li>specify the name and address of the infringer;</li>
<li>specify the particulars of the alleged offence;</li>
<li>specify the amount of the administrative ﬁne payable, which amount may, subject to subsection (10), not exceed <strong>R10 million</strong>;</li>
<li>inform the infringer that, not later than 30 days after the date of service of the infringement notice, the infringer may
<ul>
<li>pay the administrative ﬁne;</li>
<li>make arrangements with the Regulator to pay the administrative ﬁne in instalments; or</li>
<li>elect to be tried in court on a charge of having committed the alleged offence referred to in terms of this Act; and</li>
</ul>
</li>
<li>state that a failure to comply with the requirements of the notice within the time permitted will result in the administrative ﬁne becoming recoverable as contemplated in subsection (5).</li>
</ul>
</li>
<li>When determining an appropriate ﬁne, the Regulator must consider the following factors:
<ul>
<li>The nature of the personal information involved;</li>
<li>the duration and extent of the contravention;</li>
<li>the number of data subjects affected or potentially affected by the contravention;</li>
<li>whether or not the contravention raises an issue of public importance;</li>
<li>the likelihood of substantial damage or distress, including injury to feelings or anxiety suffered by data subjects;</li>
<li>whether the responsible party or a third party could have prevented the contravention from occurring;</li>
<li>any failure to carry out a risk assessment or a failure to operate good policies, procedures and practices to protect personal information; and</li>
<li>whether the responsible party has previously committed an offence in terms of this</li>
</ul>
</li>
<li>If an infringer elects to be tried in court on a charge of having committed the alleged offence in terms of this Act, the Regulator must hand the matter over to the South African Police Service and inform the infringer accordingly.</li>
<li>If an infringer fails to comply with the requirements of a notice, the Regulator may ﬁle with the clerk or registrar of any competent court a statement certiﬁed by it as correct, setting forth the amount of the administrative ﬁne payable by the infringer, and such statement thereupon has all the effects of a civil judgment lawfully given in that court in favour of the Regulator for a liquid debt in the amount speciﬁed in the statement.</li>
<li>The Regulator may not impose an administrative ﬁne contemplated in this section if the responsible party concerned has been charged with an offence in terms of this Act in respect of the same set of</li>
<li>No prosecution may be instituted against a responsible party if the responsible party concerned has paid an administrative ﬁne in terms of this section in respect of the same set of facts.</li>
<li>An administrative ﬁne imposed in terms of this section does not constitute a previous conviction as contemplated in Chapter 27 of the Criminal Procedure Act, 1977 (Act No. 51 of 1977).</li>
<li>A ﬁne payable in terms of this section must be paid into the National Revenue Fund referred to in section 213 of the Constitution.</li>
<li>The Minister may, from time to time and after consultation with the Regulator, by notice in the Gazette, adjust the amount referred to in subsection (2)(c) in accordance with the average of the consumer price index, as published from time to time in the Gazette, for the immediately preceding period of 12 months multiplied by the number of years that the amount referred to in subsection (2)(c) has remained the same.</li>
</ul>
<p>Numerous organisations and people responsible for handling personal data remain unclear of the impact of the regulation if they suffer a breach. Many of these organisations are still working through the &#8211; How, What, When and Why&#8217;s of the Act. In closing, we trust that this brief introduction was helpful. The main point is to provide an essential awareness of local and international data privacy regulations. In our next article, we will explore the various sections of the regulation how they impact your organisation or personal information. Later we will discuss how to manage and control the data process and flow within your organisation to be compliant with local and international regulations, whichever may apply. &#8220;For more about this subject, please see my next article coming soon.&#8221;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cloud Data Protection Regulation</title>
		<link>https://jacksonattorneys.co.za/cloud-data-protection-regulation/</link>
		
		<dc:creator><![CDATA[Allan Jackson]]></dc:creator>
		<pubDate>Mon, 04 Oct 2021 07:02:38 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">http://jacksonattorneys.co.za/?p=251</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">This article will stand published in three parts.<br />
The introduction<br />
Cloud services and deployment models<br />
Cloud Concerns for Data Protection Authorities</p>
<h4><strong>1.1. Introduction</strong></h4>
<p>The advantages of cloud services make it attractive to an extensive range of business, public, and governmental organisations for all sizes and types of enterprises. Such organisations might lack the resources and skills to manage in-house complex and expensive internal IT platforms.</p>
<p>, through to larger international corporates attracted to each other for potential financial benefits.</p>
<p>Nonetheless, despite the complex administration and economic benefits of using the cloud, there are numerous information security and privacy protection issues, primarily when the cloud is used for processing or handling personal information. The problems result from the various business, public and governmental organisations’ apparent lack of control over and oversight of how personal information is protected and managed within each organisations’ domain.</p>
<p>The discussion covers problem areas that cloud customers should consider when making decisions to engage the services of a cloud service provider. A view of the fundamental data protection principles behind the obligations of data users and data controllers<a href="#_ftn1" name="_ftnref1">[1]</a> and then provides the more common data protection issues which enterprises experience when pursuing the services of a cloud service provider. The discussion outlines some business model characteristics that cloud service providers have adopted and how these characteristics impact the protection of personal data and data privacy.</p>
<p>The inputs provided below should stand deliberated when enterprising customers consider or address engaging the services of a cloud service provider.</p>
<h4><strong>1.2. Cloud Service and Deployment Models</strong></h4>
<p>There are numerous categories and characteristics of the cloud.</p>
<p>This segment focuses on service and deployment models, considering the applicable privacy and personal data protection regulation: private and public cloud service models, incorporating SaaS, PaaS and IaaS, deployment models.</p>
<p><strong>The relevant service models, private and public cloud</strong></p>
<p>The private cloud stands intended for the exclusive use of private organisations. Organisational customers ought to mandate all the necessary controls to safeguard and protect the organisation’s use of personal data by the selected cloud service provider.</p>
<p>In contrast, public cloud models stand predestined to be shared by multiple customers with various individual needs. Hence, public cloud service providers tend to make the cloud platforms generic in design, allowing engagement and drawing as many customers as possible. As such, the level of provision and controls exercised by organisational clients of public clouds is inevitably much lower when compared to that of private cloud service providers.</p>
<p>As far as personal data protection is concerned, the primary distinction between the various deployment models is that in using the SaaS model, the cloud service provider also supplies and frequently operates the related software for the data users. In the SaaS model, the cloud service provider’s software may not be completely customisable to the data customers’ or users’ compliance and security requirements. In addition, it should stand noted that some SaaS cloud service providers cooperate directly with data users’ clients or customers, which renders the roles and responsibilities of each party in respect of <em>‘who is collecting what personal data and for ‘what purpose’</em> even fuzzier. The PaaS and IaaS models, in contrast, allow data users to install their software, which can stand safely assumed to be more readily compliant with a specific business, security and regulatory requirements of the data users.</p>
<h4><strong>1.3. Cloud Concerns for Data Protection Authorities</strong></h4>
<p>Cloud computing is undoubtedly a very attractive business enabler, offering such benefits as a short lead time, minimal investment and ease of use for any business initiative or operation that requires IT support. In 2012, Gartner, a market-leading IT advisory and research firm, had historically estimated that the cloud would grow from 11 billion dollars in 2012 to 244 billion dollars by 2017.</p>
<p>However, the cloud still has inherent risks such as the lack of control and breach of personal data possibilities. The EU had set up a <em>‘Working Party’</em> initialised by Article 29 of the old Data Protection Directive 95/46/EC (1995), which consisted of agents from each Member States Data Protection Authorities and the EU Commission and Data Protection Supervisor. Among its aims are to advise the EC and make recommendations to the EU concerning personal data protection. It considers the lack of control over and the deficiency of information about the cloud operations to be the two critical risks associated with using the cloud.<a href="#_ftn2" name="_ftnref2">[2]</a></p>
<p>South Africa’s interpretation comes via the POPI Act.<a href="#_ftn3" name="_ftnref3">[3]</a> Many of the POPI Acts provisions are similar to those found in the now repealed EU Data Protection Directive 95/46/EC (1995),<a href="#_ftn4" name="_ftnref4">[4]</a> and one can see where the inspiration originates. The Scope of Application of the POPI Act applies to processing data captured on record by a responsible party (1) domiciled in South Africa or (2) making use of means located in South Africa. The scope is similar to that of the EU Directive’s applicable rules, as the POPI Act applies to data processing;</p>
<ul>
<li>Firstly by or on behalf of a South African based ‘organisers’, for instance: by data processors for South African companies or</li>
<li>Secondly, when an organisation uses services and infrastructure means for data processing located in South Africa.</li>
</ul>
<p>EU Regulation 2016/679 Article 50 (Conflict) contrasts with the regulation’s antecedent, the EU Directive 95/46 (1995). Nevertheless, there is a particular provision in circumstances of conflict with supplementary laws.</p>
<p>The POPI Act operates to the exclusion of any other data protection rules or laws that are applicable. Unless such regulations or law provides for circumstances for the lawful handling of personal data that are more common than those set out in the POPI Act’s conditions for the authorised processing, the wide-ranging conditions prevail.</p>
<p>Many other countries provide data protection laws.<a href="#_ftn5" name="_ftnref5">[5]</a> However, data users take the ultimate responsibility for and are accountable for the safekeeping and use of personal data under their control, even when they outsource the processing thereof to other parties.</p>
<p>The data users should take the appropriate measures to ensure that personal data is not processed for anything other than its initial specified purpose. Moreover, to keep it no longer than necessary and protect it against unauthorised or accidental access, processing erasure, loss, or use no matter whether they are processing the data themselves or have entrusted it to a third party to do so. Accordingly, they should fulfil their obligations under the law; data users must safeguard that adequate controls stand specified in their requirements and any agreements they negotiate with the outsourced data processors.</p>
<p>As previously illustrated, cloud services are considered a unique method of outsourced service. Data users will find the various business models somewhat different from the usual outsourced business models, except the private cloud, where cloud services stand dedicated to a single client and their requirements. Data users may be unable to exert the level of control they typically can in the one-on-one relationship with the traditional outsourcer. Data users may also be unaware of some cloud characteristics that potentially negatively impact personal data privacy, particularly when entrusting confidential data to a third party or cloud service provider for data processing or storage.</p>
<hr />
<p><a href="#_ftnref1" name="_ftn1">[1]</a> A number of data protection laws define the data user and data controller as the bodies that gather, use and store such personal data belonging to the data subject or individuals.</p>
<p><a href="#_ftnref2" name="_ftn2">[2]</a> European Commission. (2012)<em> Article 29 Data Protection Working Party</em>. EC Europa.</p>
<p><a href="#_ftnref3" name="_ftn3">[3]</a> <em>The Protection of Personal Information Act No. 4 of 2013 of South Africa, Policy, Law, Economics and Politics</em>.</p>
<p><a href="#_ftnref4" name="_ftn4">[4]</a> <em>Directive 95/46/EC of the European Parliament and the Council of 24 October 1995, on the protection of individuals with regard to the processing of personal data and on the free movement of such data.</em> EC Europa.</p>
<p><a href="#_ftnref5" name="_ftn5">[5]</a> GREENLEAF, G. (2015) <em>Global data privacy laws 2015: 109 countries, with European laws now a minority.</em> Privacy Laws &amp; Business International Report.</div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
