From: CloudPro
Cloud firms make a lot of noise about data sovereignty: don’t be fooled, they don’t want you looking at security too closely
Daniel Beazer, Director of Strategy, FireHost
Data protection and the Patriot Act are two favourite marketing tools of European hosting and cloud providers seeking to ward off the threat of US companies that set up shop in this part of the world. “How can you trust a US provider to protect you from the Patriot Act?”they like to say. And “don’t you know that EU regulations mean data must be held in country and cannot be exported?”We’ll leave The Patriot Act for another day, but the claims made about data sovereignty in the EU are widely bandied about at conferences and in blogs with in the industry to the point where they have almost become universally accepted truths. It’s strange these assertions are accepted at face value, and no one has thought of checking with the people that actually make the regulations in Brussels.
If anyone had undertaken that simple exercise the results would have been a bit of a surprise.
A quick quiz: who do you think said this? “The cloud does not stop at national boundaries. You shouldn’t care where the data is as long as it is secure and meets regulatory requirements, so now the question is how to ensure that; how to make sure that when we use cloud resources, personal data does meet those requirements.”
You’d think it would be a Google or Amazon behind those comments. The message is ‘it’s the cloud, your data could be anywhere’. In fact it was the European Commission. Megan Richards, the acting deputy director-general of the Information Society and Media Directorate-General at the European Commission, was telling anyone who would listen (that doesn’t seem to apply to the hosting and cloud industry) data location is not that important especially when compared to security.
It’s not widely understood, but the European Union’s data regime freely allows the transfer of personal data from country to country in the EU and also the export to a whole roster of other jurisdictions such as Canada and Australia. Under Safe Harbor, export to the US is possible. But the European Union has such a bad reputation for burdening businesses with red tape, people will readily believe the worst.
The EU’s position here doesn’t fit in with everyone’s fireside view of Brussels. But it doesn’t matter because those inconvenient truths about data sovereignty are effectively buried beneath the noise made by the local hosting and cloud industry. The motive is pretty apparent, to scare customers off using a provider with headquarters over the other side of the Atlantic.
Over the last year, I’ve even heard some US companies looking to expand into the EU grumble about how Brussels is deliberately creating laws that make it impossible to export data out of country in an effort to protect its own hosting and cloud industries; an impressive example of someone swallowing marketing FUD from the competition, building some unwarranted and unchecked assumptions on top of it and then throwing it back into the public domain.
It’s interesting to speculate why the European hosting and cloud industry likes to make a lot of noise about data location, but not very much about the importance of making sure that data is secure. My hunch is that hosting companies in the region don’t have much to shout about in terms of security, but all of them have – by definition – an EMEA presence.
I am very happy to take to the ring to argue the point on the poor state of security in the EMEA hosting industry if anyone wants to argue the contrary, but I doubt anyone will want to take me on.
Leave a Reply