Data protection compliance in the cloud:
Gespeichert in:
1. Verfasser: | |
---|---|
Format: | Abschlussarbeit Buch |
Sprache: | English |
Veröffentlicht: |
Zürich
[2017?]
|
Schlagworte: | |
Online-Zugang: | Inhaltsverzeichnis |
Beschreibung: | LXII, 434 Seiten Diagramme |
Internformat
MARC
LEADER | 00000nam a2200000 c 4500 | ||
---|---|---|---|
001 | BV044763366 | ||
003 | DE-604 | ||
007 | t| | ||
008 | 180216s2017 xx |||| m||| 00||| eng d | ||
035 | |a (OCoLC)1015285881 | ||
035 | |a (DE-599)GBV1013871510 | ||
040 | |a DE-604 |b ger |e rda | ||
041 | 0 | |a eng | |
049 | |a DE-188 |a DE-12 | ||
100 | 1 | |a Staiger, Dominic Nicolaj |d 1987- |e Verfasser |0 (DE-588)1148434704 |4 aut | |
245 | 1 | 0 | |a Data protection compliance in the cloud |c vorgelegt von Dominic Nicolaj Staiger |
264 | 1 | |a Zürich |c [2017?] | |
300 | |a LXII, 434 Seiten |b Diagramme | ||
336 | |b txt |2 rdacontent | ||
337 | |b n |2 rdamedia | ||
338 | |b nc |2 rdacarrier | ||
502 | |b Dissertation |c Universität Zürich |d 2017 | ||
610 | 2 | 7 | |a Europäische Union |0 (DE-588)5098525-5 |2 gnd |9 rswk-swf |
650 | 0 | 7 | |a Datenschutz |0 (DE-588)4011134-9 |2 gnd |9 rswk-swf |
650 | 0 | 7 | |a Cloud Computing |0 (DE-588)7623494-0 |2 gnd |9 rswk-swf |
655 | 7 | |0 (DE-588)4113937-9 |a Hochschulschrift |2 gnd-content | |
689 | 0 | 0 | |a Europäische Union |0 (DE-588)5098525-5 |D b |
689 | 0 | 1 | |a Datenschutz |0 (DE-588)4011134-9 |D s |
689 | 0 | 2 | |a Cloud Computing |0 (DE-588)7623494-0 |D s |
689 | 0 | |5 DE-604 | |
856 | 4 | 2 | |m HEBIS Datenaustausch |q application/pdf |u http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=030158716&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA |3 Inhaltsverzeichnis |
943 | 1 | |a oai:aleph.bib-bvb.de:BVB01-030158716 |
Datensatz im Suchindex
_version_ | 1820142736420896768 |
---|---|
adam_text |
Data Protection Compliance in the Cloud
Dissertation
der Rechtswissenschaftlichen Fakultat
der Universitat Zurich
vorgelegt von
Dominic Nicolaj Staiger
von Deutschland
genehmigt auf Antrag von
Prof Dr Rolf H Weber
und
Prof Dr Florent Thouvenin
Content
Content
Preface Ill
Content IV
Table of Content VII
List of Abbreviations XVI
Bibliography XIX
Research Project 2
Part 1: Introduction to Data Protection and the Cloud 7
The Concept of Compliance 8
Evolution of Cloud Services 21
Virtual Machines and Types of Cloud Service 28
Types of Cloud Users 36
New Capabilities in the Cloud 40
Privacy and Data Protection Approaches 49
$ P
International Trade Agreements on Data Protection and Privacy 76
Part 2: The EU Data Protection Framework 87
Reform Process 92
Material Scope 97
Territorial Scope 103
Supervisory Authority and Data Protection Board 118
Defining Personal Data 134
Processor and Controller 150
IV
Content
Data Subject Rights 166
Personal Data Processing Authorization 175
Transborder Data Transfer in the Cloud 207
Data Protection Impact Assessments 238
Privacy by Design and Technical Standards 243
Data Protection Management Systems 250
A Right to be Forgotten? 256
Public Agency Access Rights 265
Enforcement, Fines and Penalties 274
Joint and Several Liability 281
Data Breach Notification 283
Data Protection Officer 289
Overview of the Delegated Acts and Room for Manoeuvre 295
Key Compliance Action 302
The ePrivacy Directive (EPD) 306
Par! 3:The Cloud Contract 313
Research Basis 313
Introduction 315
Requirements Imposed by the GDPR 325
Pricing and Payment in the Cloud 328
Terms of Service and Provider Classification 331
Contract Alteration 333
Essential Terms 334
V
Public Sector Contracts 344
Liability of Cloud Providers 350
Ending a Cloud Contract 360
Applicable Law and Choice of Forum 363
Enforcing Rights in the Cloud 371
Electronic Discovery in the Cloud 378
Codes of Conduct, Certifications and Insurance in the Cloud 388
Concluding Remarks 399
Current Developments 402
Future Data Protection Technology 411
Research Outcome 415
Annex 419
Table US Access Framework 419
Draft Non-Compliance and Compliance Procedure Table 421
jCdmparison of Standard Cloud Agreements 423
Electricity Prices in the US 429
Electricity Prices in the EU 432
GDPR Compliance Costs 433
Short CV 434
VI
Table of Content
Table of Content
Preface Ill
Content IV
Table of Content VII
List of Abbreviations XVI
Bibliography XIX
I Books ' XIX
II Journals XXV
III Statutes XXXV
1 USA XXXV
2 EU and EU Member States XXXVI
3 Other Jurisdictions XXXVIII
IV Cases XXXIX
1 USA XXXIX
2 EU, EU Member States and ECHR XL
3 Other Jurisdictions XLII
V Electronic Papers XLIII
VI Command Papers XLVII
VII Conference Papers LIII
V^II fiPress Releases LIV
IX Podcasts LV
X Webpages and Other Electronic Materials LV
Research Project 2
I Compliance Challenges 4
II Future of Data Protection Compliance 6
Part 1: Introduction to Data Protection and the Cloud 7
The Concept of Compliance 8
I Data Protection Compliance 9
Ii Compliance Management Systems 11
VII
Table of Content
III Compliance Risk Assessments 14
IV Compliance Issues in the Cloud 16
V GDPR Compliance Costs 19
Evolution of Cloud Services 21
I Key Characteristics 22
II Virtualization 23
III Drivers and Inhibitors of Cloud Development 25
Virtual Machines and Types of Cloud Service 28
I Infrastructure as a Service (IaaS) 30
II Software as a Service (SaaS) 31
III Platform as a Service (PaaS) 32
IV Data Storage 33
Types of Cloud Users 36
I Horizontal and Vertical Distinction 36
II Private and Public Cloud Users 37
New Capabilities in the Cloud 40
I Introduction to Big Data in the Cloud 40
II Big Data in the EU 42
III Big Data Risks in Third World Countries 46
Privacy and Data Protection Approaches 49
yl EU Treaty and Human Rights Data Protection 58
1 Interaction of EU and Human Rights Law 58
2 Applicability of the EU and Human Rights Law 62
II EU and Swiss Data Protection Laws 66
1 EU Data Protection Law 66
2 Swiss Data Protection Law 67
III US Approach to Data Protection and Privacy 68
1 Data Protection Framework in the US 70
2 Revision of the US Data Protection Framework 72
3 US Mass Data Collection 74
j International Trade Agreements on Data Protection and Privacy 76
I The General Agreement on Trade in Services (GATS) 77
VIII
Table of Content
II Transatlantic Trade and Investment Partnership (TTIP) 83
III The Trans-Pacific Partnership (TPP) Agreement 84
Part 2: The EU Data Protection Framework 87
Reform Process 92
Material Scope 97
I General Rule 97
II Interaction with E-Commerce Directive 98
III Domestic and Household Use Exception 99
IV Special Rules for Freedom of Information Requests 101
Territorial Scope 103
I Introduction to Data Protection Jurisdiction 105
II Advancing a Jurisdictional Claim for Data Protection 111
III Representatives in the EU 114
IV Practical Implications 115
Supervisory Authority and Data Protection Board 118
I European Data Protection Board (EDPB) 121
II Challenges in the Drafting Process 122
1 Initial Compliance Procedure 122
2 Final Coordination Procedure 124
u f
III ' A One-Stop Shop Solution to Enforcement 125
IV Competent Supervisory Authority 126
V Consistency Mechanism 128
VI Mutual Assistance 131
VII Joint Operations 132
VIII Urgency Procedure 132
Defining Personal Data 134
I Definition under the GDPR 134
II Anonymization and Pseudonymization 137
III Encrypted Data 142
IjV IoT Device Data 145
V Solutions to the Identification Issues 146
IX
Table of Content
Processor and Controller 150
I Controller vs Processor 151
II Obligations of the Controller 152
1 Information Requirements 153
2 Records of Processing Activities 157
3 Controller's Ability to Identify Data Subject 159
III Obligations of the Processor 159
1 Information Requirements 162
2 Records ,of Processing Activity 162
3 Sub-Processing 163
IV Processor Exceeding Authority 163
V SaaS Social Media Providers 165
Data Subject Rights 166
I Rectification and Erasure 166
II Right to Restrict Processing 168
III Data Portability 168
IV Profiling and Automated Decisions 169
1 Right to Object 170
2 Form and Procedure of an Objection 171
3 Automated Decision Making 172
Personal Data Processing Authorization 175
? GDPR Processing Authorization 175
II Consent by the Data Subject 179
1 Form of Consent 182
2 Scope of Consent 184
3 Withdrawal of Consent 187
4 Consent of Children 188
III Contract Fulfilment 190
IV Legal Obligations 191
V Vital Interest 192
VI Public Interest and Official Authority 192
1 Processing by EU Member States 193
ft
2 Processing by Swiss Authorities 193
X
Table of Content
VII Legitimate Interest 194
1 Processing for Security and Fraud Prevention 194
2 Processing in the Cloud Context 195
3 Whistleblowing 196
4 Advertisement and Sale of Contact Data 196
5 Information Requirements 197
VIII Processing other than for Initial Purpose 197
IX Special Data Categories 199
1 Professional Secrecy 202
2 Legal Claims and Criminal Convictions 204
3 Employment Data 205
Transborder Data Transfer in the Cloud 207
I Adequacy Decision 208
II Safe Harbor amp; Privacy Shield 209
1 Safe Harbor Reform 209
2 Invalidation of Safe Harbor 212
3 Privacy Shield 213
3 1 Mass Surveillance Issues 216
3 2 Further Inadequacy of the Data Protection Standard 218
3 3 Interaction with the GDPR 220
3 4 Practical Considerations for Cloud Enterprises 222
III Appropriate Safeguards 222
IV ? Approved Contractual Clause Exception 224
V Binding Corporate Rules 225
1 Requirements of the BCR Framework 226
2 Use of BCR by Cloud Providers 232
3 APEC and Binding Corporate Rules 232
VI Transfers under Art 49 in Specific Situations 234
VII Multi-Layered Transborder Transfer 236
Data Protection Impact Assessments 238
I Prior Consultation of Supervisory Authority 241
II Results of the DPIA 241
Privacy by Design and Technical Standards 243
I Privacy by Design 243
XI
Table of Content
II Privacy Enhancing Technologies 245
Data Protection Management Systems 250
I Procedural Data Protection Management Systems 251
II Technological Data Protection Management Systems 252
A Right to be Forgotten? 256
I Google Spain Decision 256
II GDPR Right to be Forgotten 257
III Freedom of Expression vs the Right to be Forgotten 260
IV Post Google Spain Decision 263
Public Agency Access Rights 265
I In the EU 268
II In the USA 271
Enforcement, Fines and Penalties 274
I Redress Through Associations 274
II Fines 276
III Data Breach Claim 278
Joint and Several Liability 281
Data Breach Notification 283
I Contractual Information Policies 285
(jll^ Cooperation Procedure 288
^ Data Protection Officer 289
I Tasks and Position of Data Protection Officer 291
II Selecting the Appropriate Person 294
Overview of the Delegated Acts and Room for Manoeuvre 295
I Restrictions by Member States 296
II Freedom of Expression and Information 297
III Third Country Data Transfer Derogation 298
IV Accreditation Procedures 299
V Data Protection Officer 299
f VI Processing under a Legal Obligation or Public Interest 300
VII Multi-Party Processing 300
XII
Table of Content
VIII Processing Sensitive Data 300
IX Restricting Data Subject's Rights 301
Key Compliance Action 302
I Preparing for the GDPR 302
II Notification Procedures 305
III Processing Authorization 305
The ePrivacy Directive (EPD) 306
I The Reform Process 306
1 Metadata 309
2 Consent Requirements 309
II The Proposed Privacy and Electronic Communication Regulation 311
Part 3:The Cloud Contract 313
Research Basis 313
Introduction 315
I Negotiating Power and Standard Contracts 319
II Necessary Preparation for Cloud Contract Negotiation 321
III Basic Compliance 323
Requirements Imposed by the GDPR 325
L, j Information Requests by Data Subjects 325
Ii Standardized Icons 326
Pricing and Payment in the Cloud 328
Terms of Service and Provider Classification 331
Contract Alteration 333
Essential Terms 334
I Exclusions and Risk Shifting 334
II Data Location and Sub-processing 336
III Licenses and Usage Rights 337
IV Service Level Agreements 337
V Cloud Hardware and Software Updates 339
XIII
Table of Content
VI Migrating Data Into the Cloud 339
VII Acceptable Use Policy 340
VIII Confidentiality 340
Public Sector Contracts 344
Liability of Cloud Providers 350
I Types of Losses in a Cloud Setting 351
II Scope and Extent of Liability 352
III Direct and Indirect Liability 355
IV Tortious Liability 356
V Indemnification by the Cloud Provider and Cloud Customer 358
Ending a Cloud Contract 360
I Termination Right 360
II Form of Termination 361
Applicable Law and Choice of Forum 363
I Contract Law 363
II Choice of Forum and Arbitration 369
Enforcing Rights in the Cloud 371
I Security of Payment Systems 371
II Access to Data and Retention 371
1 Standard Terms 371
§ P
j 2 Limiting Access based on Location 374
3 Logging Access 374
4 Retention of Data 375
5 Migration of Data 376
III Right to Destruction of Data 376
IV Limitation Period 377
Electronic Discovery in the Cloud 378
I The Criminal Procedure Discovery Process 379
II The Civil Procedure Discovery Process 381
III Electronic Discovery Tools 386
'Codes of Conduct, Certifications and Insurance in the Cloud 388
XIV
Table of Content
I Codes of Conduct 388
II Certifications in the GDPR 392
III Insurance 396
1 Ensuring Data Protection Compliance Through Insurance 397
2 Moral Hazard 398
Concluding Remarks 399
Current Developments 402
I Developments in the USA 404
II Internationalization of Data Protection Law 406
Future Data Protection Technology 411
I Big Data, Predictive Analytics and Artificial Intelligence 411
II Data Protection and Compliance Technology 413
Research Outcome 415
Annex 419
Table US Access Framework 419
Draft Non-Compliance and Compliance Procedure Table 421
Comparison of Standard Cloud Agreements 423
Electricity Prices in the US 429
Electricity Prices in the EU 432
GDPR Compliance Costs 433
Short CV 434
XV |
any_adam_object | 1 |
author | Staiger, Dominic Nicolaj 1987- |
author_GND | (DE-588)1148434704 |
author_facet | Staiger, Dominic Nicolaj 1987- |
author_role | aut |
author_sort | Staiger, Dominic Nicolaj 1987- |
author_variant | d n s dn dns |
building | Verbundindex |
bvnumber | BV044763366 |
ctrlnum | (OCoLC)1015285881 (DE-599)GBV1013871510 |
format | Thesis Book |
fullrecord | <?xml version="1.0" encoding="UTF-8"?><collection xmlns="http://www.loc.gov/MARC21/slim"><record><leader>00000nam a2200000 c 4500</leader><controlfield tag="001">BV044763366</controlfield><controlfield tag="003">DE-604</controlfield><controlfield tag="007">t|</controlfield><controlfield tag="008">180216s2017 xx |||| m||| 00||| eng d</controlfield><datafield tag="035" ind1=" " ind2=" "><subfield code="a">(OCoLC)1015285881</subfield></datafield><datafield tag="035" ind1=" " ind2=" "><subfield code="a">(DE-599)GBV1013871510</subfield></datafield><datafield tag="040" ind1=" " ind2=" "><subfield code="a">DE-604</subfield><subfield code="b">ger</subfield><subfield code="e">rda</subfield></datafield><datafield tag="041" ind1="0" ind2=" "><subfield code="a">eng</subfield></datafield><datafield tag="049" ind1=" " ind2=" "><subfield code="a">DE-188</subfield><subfield code="a">DE-12</subfield></datafield><datafield tag="100" ind1="1" ind2=" "><subfield code="a">Staiger, Dominic Nicolaj</subfield><subfield code="d">1987-</subfield><subfield code="e">Verfasser</subfield><subfield code="0">(DE-588)1148434704</subfield><subfield code="4">aut</subfield></datafield><datafield tag="245" ind1="1" ind2="0"><subfield code="a">Data protection compliance in the cloud</subfield><subfield code="c">vorgelegt von Dominic Nicolaj Staiger</subfield></datafield><datafield tag="264" ind1=" " ind2="1"><subfield code="a">Zürich</subfield><subfield code="c">[2017?]</subfield></datafield><datafield tag="300" ind1=" " ind2=" "><subfield code="a">LXII, 434 Seiten</subfield><subfield code="b">Diagramme</subfield></datafield><datafield tag="336" ind1=" " ind2=" "><subfield code="b">txt</subfield><subfield code="2">rdacontent</subfield></datafield><datafield tag="337" ind1=" " ind2=" "><subfield code="b">n</subfield><subfield code="2">rdamedia</subfield></datafield><datafield tag="338" ind1=" " ind2=" "><subfield code="b">nc</subfield><subfield code="2">rdacarrier</subfield></datafield><datafield tag="502" ind1=" " ind2=" "><subfield code="b">Dissertation</subfield><subfield code="c">Universität Zürich</subfield><subfield code="d">2017</subfield></datafield><datafield tag="610" ind1="2" ind2="7"><subfield code="a">Europäische Union</subfield><subfield code="0">(DE-588)5098525-5</subfield><subfield code="2">gnd</subfield><subfield code="9">rswk-swf</subfield></datafield><datafield tag="650" ind1="0" ind2="7"><subfield code="a">Datenschutz</subfield><subfield code="0">(DE-588)4011134-9</subfield><subfield code="2">gnd</subfield><subfield code="9">rswk-swf</subfield></datafield><datafield tag="650" ind1="0" ind2="7"><subfield code="a">Cloud Computing</subfield><subfield code="0">(DE-588)7623494-0</subfield><subfield code="2">gnd</subfield><subfield code="9">rswk-swf</subfield></datafield><datafield tag="655" ind1=" " ind2="7"><subfield code="0">(DE-588)4113937-9</subfield><subfield code="a">Hochschulschrift</subfield><subfield code="2">gnd-content</subfield></datafield><datafield tag="689" ind1="0" ind2="0"><subfield code="a">Europäische Union</subfield><subfield code="0">(DE-588)5098525-5</subfield><subfield code="D">b</subfield></datafield><datafield tag="689" ind1="0" ind2="1"><subfield code="a">Datenschutz</subfield><subfield code="0">(DE-588)4011134-9</subfield><subfield code="D">s</subfield></datafield><datafield tag="689" ind1="0" ind2="2"><subfield code="a">Cloud Computing</subfield><subfield code="0">(DE-588)7623494-0</subfield><subfield code="D">s</subfield></datafield><datafield tag="689" ind1="0" ind2=" "><subfield code="5">DE-604</subfield></datafield><datafield tag="856" ind1="4" ind2="2"><subfield code="m">HEBIS Datenaustausch</subfield><subfield code="q">application/pdf</subfield><subfield code="u">http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=030158716&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA</subfield><subfield code="3">Inhaltsverzeichnis</subfield></datafield><datafield tag="943" ind1="1" ind2=" "><subfield code="a">oai:aleph.bib-bvb.de:BVB01-030158716</subfield></datafield></record></collection> |
genre | (DE-588)4113937-9 Hochschulschrift gnd-content |
genre_facet | Hochschulschrift |
id | DE-604.BV044763366 |
illustrated | Not Illustrated |
indexdate | 2025-01-02T13:09:39Z |
institution | BVB |
language | English |
oai_aleph_id | oai:aleph.bib-bvb.de:BVB01-030158716 |
oclc_num | 1015285881 |
open_access_boolean | |
owner | DE-188 DE-12 |
owner_facet | DE-188 DE-12 |
physical | LXII, 434 Seiten Diagramme |
publishDate | 2017 |
publishDateSearch | 2017 |
publishDateSort | 2017 |
record_format | marc |
spelling | Staiger, Dominic Nicolaj 1987- Verfasser (DE-588)1148434704 aut Data protection compliance in the cloud vorgelegt von Dominic Nicolaj Staiger Zürich [2017?] LXII, 434 Seiten Diagramme txt rdacontent n rdamedia nc rdacarrier Dissertation Universität Zürich 2017 Europäische Union (DE-588)5098525-5 gnd rswk-swf Datenschutz (DE-588)4011134-9 gnd rswk-swf Cloud Computing (DE-588)7623494-0 gnd rswk-swf (DE-588)4113937-9 Hochschulschrift gnd-content Europäische Union (DE-588)5098525-5 b Datenschutz (DE-588)4011134-9 s Cloud Computing (DE-588)7623494-0 s DE-604 HEBIS Datenaustausch application/pdf http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=030158716&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA Inhaltsverzeichnis |
spellingShingle | Staiger, Dominic Nicolaj 1987- Data protection compliance in the cloud Europäische Union (DE-588)5098525-5 gnd Datenschutz (DE-588)4011134-9 gnd Cloud Computing (DE-588)7623494-0 gnd |
subject_GND | (DE-588)5098525-5 (DE-588)4011134-9 (DE-588)7623494-0 (DE-588)4113937-9 |
title | Data protection compliance in the cloud |
title_auth | Data protection compliance in the cloud |
title_exact_search | Data protection compliance in the cloud |
title_full | Data protection compliance in the cloud vorgelegt von Dominic Nicolaj Staiger |
title_fullStr | Data protection compliance in the cloud vorgelegt von Dominic Nicolaj Staiger |
title_full_unstemmed | Data protection compliance in the cloud vorgelegt von Dominic Nicolaj Staiger |
title_short | Data protection compliance in the cloud |
title_sort | data protection compliance in the cloud |
topic | Europäische Union (DE-588)5098525-5 gnd Datenschutz (DE-588)4011134-9 gnd Cloud Computing (DE-588)7623494-0 gnd |
topic_facet | Europäische Union Datenschutz Cloud Computing Hochschulschrift |
url | http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=030158716&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA |
work_keys_str_mv | AT staigerdominicnicolaj dataprotectioncomplianceinthecloud |