// Workers AI · dad joke modeWhat did EU Cloud say? "I've got a conduct code to follow, it's a clouded issue.
A major contributor to this article appears to have a close connection with its subject. (August 2021) |
The EU Cloud Code of Conduct (abbr. "EU Cloud CoC" also known by its extended title "EU Data Protection Code of Conduct for Cloud Service Providers") is a transnational Code of Conduct pursuant Article 40 of the European General Data Protection Regulation (GDPR).[1]
The code defines clear requirements for cloud service providers (CSPs) to implement Article 28 GDPR[2] and all its related articles, which covers the processing activities of every type of personal data.[3]
Encompassing all cloud service layers (including but not limited to IaaS, PaaS, and SaaS), the Code provides a sector-specific framework for cloud service providers acting as processors. Under Article 28(5) GDPR, adherence to an approved code of conduct may be used as an element to demonstrate the "sufficient guarantees" required of processors. Compliance with the Code is overseen by an accredited monitoring body under Article 41 GDPR.[4]
History
[edit]The work on the code started in 2012 when former vice president of the European Commission, Neelie Kroes, launched the European Cloud Strategy.[5][6] In that context, a dedicated working group was created with the task to draft a cloud code of conduct under the Data Protection Directive.
One of the primary goals of drafting such code was to increase trust and amplify the adoption of cloud computing across the European Union.[7] The first draft produced by the working group was submitted to its first assessment in January 2015, which was then performed by the Article 29 Working Party.[8]
With the introduction of the GDPR, the code had to be adapted accordingly and by 2017,[9] the European Commission fully handed over the project to the industry.[10]
Still in 2017, six companies coming from that working group (Alibaba Cloud, Fabasoft, IBM, Oracle, Salesforce and SAP) founded the EU Cloud CoC General Assembly and assigned SCOPE Europe as its monitoring body and secretariat.[11][12]
After several exchanges with supervisory authorities and related revisions,[13] the final version of the EU Cloud CoC was submitted to the Belgian Data Protection Authority for approval in 2019.[13] According to the timestamps of the code versions published on the initiative's website,[13] the code evolved further after submission and until its approval in May 2021. Such continued development of codes of conduct is expected, following the European Data Protection Board's Guidelines 1/2019 on codes of conduct and monitoring bodies under Regulation 2016/679.[14]
The code has been approved[15] by the Belgian Data Protection Authority as of May 20, 2021,[16] following a positive opinion issued by the European Data Protection Board.[17][18]
A second transnational GDPR code for the cloud sector, the CISPE Data Protection Code of Conduct, was approved the 3rd June 2021.[19]
Scope and structure of the code
[edit]The EU Cloud CoC allows CSPs to prove and demonstrate compliance within the scope of Article 28 GDPR and all its related Articles. Therefore, the EU Cloud CoC comprehends CSPs data protection obligations when processing any kind of personal data and its requirements are applicable to all cloud offerings (including but not limited to IaaS, PaaS, SaaS).[20][21]
There are five sections that together compose the core structure of the code, namely, Scope, Data Protection, Security Requirements, Monitoring and Compliance and Internal Governance.[22][23]
Besides the main text, the code is accompanied by a controls catalogue, which was designed to map the code’s requirements to auditable elements, the “Controls”, and to all corresponding GDPR provisions. Additionally, the controls catalogue also provides a mapping to relevant international standards (such as ISO 27001, ISO 27017, SOC 2 and BSI C5).[24]
The Code can also have relevance in the enforcement of the GDPR. Infringements of the controller and processor obligations listed in Articles 25 to 39 GDPR, which include Articles 28 and 32, are subject to the tier of administrative fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher, while certain other GDPR infringements may be subject to the higher €20 million or 4% tier. This distinction is established by the GDPR itself rather than by adherence to the Code. Separately, Article 83(2)(j) requires supervisory authorities to take adherence to approved codes of conduct into account when deciding whether to impose a fine and its amount; the European Data Protection Board has stated that such adherence may, in some circumstances, constitute a mitigating factor.[25][26]
Organizational structure
[edit]The organizational structure of the EU Cloud CoC is covered under its Internal Governance Section, which describes the rules and procedures applied for the code’s management. The referred Section lays out the organizational framework of the code itself, as well as of its bodies, namely, the General Assembly,[27] the Steering Board, and the Secretariat.[22][23]
Dedicated monitoring body
[edit]The GDPR requires an independent monitoring body[28] to guarantee the appropriate implementation of its provisions.
In May 2021, SCOPE Europe has been officially accredited by the Belgian Data Protection Authority as the dedicated monitoring body of the EU Cloud CoC.[29]
According to GDPR, the monitoring body shall be responsible for performing an ongoing due diligence. Under the EU Cloud CoC, besides being subjected to an initial assessment to become adherent to the code, CSPs are reevaluated on an annual basis.
Additional assessments can also be triggered by justified complaints, media reports, new legislations, publications and Guidelines from Data Protection Authorities and any other relevant development that can potentially affect adherence to the code.
A CSP can opt for three Levels of Compliance[30] once declaring adherence to the EU Cloud CoC. Those levels relate solely to the type of evidence that is subjected to the review of the monitoring body. Nevertheless, each of those levels demands compliance to all the code’s requirements.
Membership and supporters
[edit]Membership to the code is open to any CSP as long as they agree with the approach and principles established in the code. In that regard, the EU Cloud CoC offers two main membership options, the first being dedicated to CSPs and the second covering any entity that is not a CSP and wishes to join the initiative as supporter.
Within the CSP membership umbrella, a tailored pricing scheme[31] is in place, which takes into consideration the needs of different company sizes allowing for accessibility for Small and Medium Enterprises (SMEs).
Today, the EU Cloud CoC General Assembly represents a significant share of the European cloud industry market and, as of August 2021, its membership encompasses Alibaba Cloud,[32][33][34] Alight, Arcules,[35][36] Cisco,[37] Dropbox,[38] Epignosis,[39] Fabasoft,[40] Google Cloud,[41] IBM,[42][43] K&L Gates,[44] Microsoft,[45][46] Okta, Oracle,[47] Qompium (Extra Horizon),[48] Salesforce,[49] SAP,[50] Schellman,[51] SecureAppbox,[52] Timelex, TrustArc[53][54] and Workday.[55]
SCOPE Europe maintains a public register of cloud services that have been assessed by the monitoring body. The register identifies the provider and service, its level of compliance and the corresponding public report of adherence.[56]
The third country transfer initiative
[edit]Following the Data Protection Commissioner v Facebook Ireland Ltd Schrems II judgment, the EU Cloud CoC General Assembly began developing a separate Third Country Transfers Module addressing international transfers of personal data. The EU Cloud CoC as approved in 2021 does not itself constitute a safeguard for international transfers under Article 46 GDPR; when approving the Code, the European Data Protection Board stated that it was not to be used in the context of international transfers of personal data.[57][58]
A draft of the Third Country Transfers Module was subsequently published for consultation. The module is intended to complement the existing Code and address the requirements of Chapter V GDPR, while requiring adherence to the EU Cloud CoC as a prerequisite.[59]
In 2025, SCOPE Europe stated that the working group was finalising the draft ahead of submission to the competent supervisory authority. The initiative remained under development in 2026.[60][61]
See also
[edit]References
[edit]- ↑ "Art. 40 GDPR - Codes of conduct". EUR-Lex: EU law. Retrieved 2021-08-20.
- ↑ "Art. 28 GDPR - Processor". EUR-Lex: EU law. Retrieved 2021-08-20.
- ↑ "Belgian DPA Approves First EU Data Protection Code of Conduct for Cloud Service Providers". Privacy & Information Security Law Blog. 2021-05-24. Retrieved 2021-08-26.
- ↑ "Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the EU Data Protection Code of Conduct for Cloud Service Providers submitted by Scope Europe" (PDF). European Data Protection Board. 19 May 2021.
- ↑ "COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS Unleashing the Potential of Cloud Computing in Europe", European Commission, 27-09-2021, Retrieved 20-08-2021
- ↑ "What's behind the EU's new Cloud Code of Conduct?". Retrieved 2021-08-26.
- ↑ "Cloud Select Industry Group | Shaping Europe's digital future". digital-strategy.ec.europa.eu. Retrieved 2021-08-25.
- ↑ "Opinion of the Article 29 Data Protection Working Party on the Code of conduct on data protection for cloud service providers | Shaping Europe's digital future". digital-strategy.ec.europa.eu. Retrieved 2021-08-20.
- ↑ "The Belgian DPA approved the EU Cloud Code of Conduct for cloud service providers acting as a processor". Lexology. 2021-06-03. Retrieved 2021-08-26.
- ↑ "Oversight body handed Code of Conduct for Cloud Service Providers". Retrieved 2021-08-20.
- ↑ "Belgian DPA approves first EU Data Protection Code of Conduct for Cloud Service Providers | privacy-ticker.com". Retrieved 2021-08-26.
- ↑ "Press Release, December 12th, 2017". eucoc.cloud. Archived from the original on 2021-08-26. Retrieved 2021-08-26.
- 1 2 3 "History: EU Cloud CoC". eucoc.cloud. Archived from the original on 2021-08-22. Retrieved 2021-08-25.
- ↑ "Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 - version adopted after public consultation | European Data Protection Board". edpb.europa.eu. Retrieved 2021-08-25.
- ↑ "Subject: Approval decision of the “Eu Data Protection Code of Conduct for Cloud Service Providers” by the General Secretariat of the Belgian Data Protection Authority", Decision n° 05/2021 of 20 May 2021, General Secretariat - Belgian Data Protection Authority, 20-05-2021, Retrieved 26-08-2021.
- ↑ "GDPR: What Cloud Service Providers Should Know - Blog | GlobalSign". GlobalSign GMO Internet, Inc. 2021-07-30. Retrieved 2021-08-26.
- ↑ "Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe", European Data Protection Board, 19-05-2021, Retrieved 19-05-2021.
- ↑ OneTrust. "EU Cloud Code of Conduct Approved by DPA | Blog". OneTrust. Retrieved 2021-08-26.
- ↑ "Codes of conduct". European Data Protection Board.
- ↑ "Privacy, il primo codice di condotta transnazionale è sul cloud: perché è importante". Agenda Digitale. 2021-05-27. Retrieved 2021-08-26.
- ↑ "Simmons & Simmons". www.simmons-simmons.com. Retrieved 2021-08-26.
- 1 2 "Request the EU Cloud Code of Conduct: EU Cloud CoC". eucoc.cloud. Retrieved 2021-08-20.
- 1 2 "EU Data Protection Code of Conduct for Cloud Service Providers - Version 10", EU Cloud Code of Conduct, October 2020, Retrieved 20-08-2021.
- ↑ "Data watchdogs seek 'added value' in GDPR cloud codes". Pinsent Masons. Retrieved 2021-08-26.
- ↑ "Regulation (EU) 2016/679, Article 83". EUR-Lex.
- ↑ "Guidelines 04/2022 on the calculation of administrative fines under the GDPR" (PDF). European Data Protection Board. 24 May 2023.
- ↑ "What you should know about the EU Cloud Code of Conduct". JD Supra. Retrieved 2021-08-26.
- ↑ "Art. 41 GDPR - Monitoring of approved codes of conduct". EUR-Lex: EU law. Retrieved 2021-08-20.
- ↑ "Subject: accreditation of the “Scope Europe” for the monitoring of the “Eu Cloud Code of Conduct” (DOS -2019-03289)", Decision n° 06/2021 of 20 May 2021, Belgian Data Protection Authority, 20-05-2021, Retrieved 20-08-2021.
- ↑ "Levels of Compliance: EU Cloud CoC". eucoc.cloud. Retrieved 2021-08-20.
- ↑ "Pricing: EU Cloud CoC". eucoc.cloud. Retrieved 2021-08-20.
- ↑ "Belgian DPA Approves Code of Conduct for the Cloud Industry". The WSGR Data Advisor. 2021-06-22. Retrieved 2021-08-26.
- ↑ "Alibaba Cloud adheres to the EU Cloud Code of Conduct". eucoc.cloud. Retrieved 2021-08-26.
- ↑ "Alibaba Cloud Joins the EU Code of Conduct for Cloud Service Providers | Alibaba Cloud Press Room". www.alibabacloud.com. Retrieved 2021-08-26.
- ↑ "Arcules joins the EU Cloud Code of Conduct, committing to robust video data protection". eucoc.cloud. Archived from the original on 2021-08-26. Retrieved 2021-08-26.
- ↑ Wolff, Kevin (2018-04-24). "Arcules Joins the European Union Cloud Code of Conduct, Committing to Robust Video Data Protection". Arcules. Retrieved 2021-08-26.
- ↑ "The EU Cloud Code of Conduct becomes first GDPR code of conduct to receive green light from data protection authorities". eucoc.cloud. Retrieved 2021-08-26.
- ↑ "PRESS RELEASE: Dropbox joins the EU Cloud Code of Conduct General Assembly". eucoc.cloud. Retrieved 2021-08-26.
- ↑ "Epignosis joins the EU Cloud Code of Conduct". Epignosis. 2018-03-01. Retrieved 2021-08-26.
- ↑ "PRESS RELEASE: Fabasoft is the first company to reach the highest compliance level available while declaring adherence to the EU Cloud Code of Conduct". eucoc.cloud. Retrieved 2021-08-26.
- ↑ "Google Cloud Addresses the Approval of the EU Cloud Code of Conduct". eucoc.cloud. Retrieved 2021-08-26.
- ↑ "IBM Adds New Cloud Services to EU Data Protection Code of Conduct". THINKPolicy Blog. 2017-06-13. Retrieved 2021-08-26.
- ↑ "IBM Among 1st to Adopt EU's New Code of Conduct for Cloud Computing". THINKPolicy Blog. 2017-03-13. Retrieved 2021-08-26.
- ↑ "EU Cloud Code of Conduct welcomes K&L Gates as new Supporter". eucoc.cloud. Retrieved 2021-08-26.
- ↑ "Microsoft Azure adheres to the EU Cloud Code of Conduct". EU Policy Blog. 2021-05-20. Retrieved 2021-08-26.
- ↑ "GDPR-readiness of EU Cloud Code of Conduct wins backing of European data protection authorities". ComputerWeekly.com. Retrieved 2021-08-26.
- ↑ "Press Release, December 12th, 2017". eucoc.cloud. Archived from the original on 2021-08-26. Retrieved 2021-08-26.
- ↑ "Extra Horizon has joined the EU Cloud Code of Conduct's General Assembly". www.extrahorizon.com. 2021-08-18. Retrieved 2021-08-26.
- ↑ UpCRM (2021-06-07). "Salesforce Adopts European Union's New Cloud Code of Conduct | UpCRM Salesforce Luxembourg". UpCRM | Top partner Salesforce Luxembourg, CRM & Data Solutions. Retrieved 2021-08-26.
- ↑ "SAP Business Technology Platform EU Cloud CoC". SAP. Archived from the original on 2021-08-26. Retrieved 2021-08-26.
- ↑ "PRESS RELEASE: Schellman becomes the newest supporting member of the EU Cloud Code of Conduct". eucoc.cloud. Retrieved 2021-08-26.
- ↑ "EU Cloud Code of Conduct General Assembly welcomes SecureAppbox as newest member". eucoc.cloud. Archived from the original on 2021-08-26. Retrieved 2021-08-26.
- ↑ "EU Cloud Code of Conduct Resources". TrustArc The Leader in Privacy Management Software. Retrieved 2021-08-26.
- ↑ TrustArc. "TrustArc Incorporates EU Cloud Code of Conduct Into PrivacyCentral Platform". Tank Town Media. Archived from the original on 2021-08-26. Retrieved 2021-08-26.
- ↑ "Workday Joins the General Assembly of the EU Cloud Code of Conduct". Workday Blog. Retrieved 2021-08-26.
- ↑ "List of Adherent Services". EU Cloud Code of Conduct.
- ↑ Stolton, Samuel (25 May 2021). "What's behind the EU's new Cloud Code of Conduct?". IAPP.
- ↑ "Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the EU Data Protection Code of Conduct for Cloud Service Providers submitted by Scope Europe" (PDF). European Data Protection Board. 19 May 2021.
- ↑ "The EU Cloud Code of Conduct seeks feedback on Third Country Transfers Module draft". EU Cloud Code of Conduct. 13 September 2023.
- ↑ "Advancing Cross-Border Compliance: The Third Country Transfers Module". EU Cloud Code of Conduct. 7 April 2025.
- ↑ "Data Protection Day". EU Cloud Code of Conduct. 28 January 2026.