Skip to content
Annuaire
Sections
Communication

The Cloud Act and Personal Data Protection

The Cloud Act and Personal Data Protection
L’essentiel

The Cloud Act, Clarifying Lawful Overseas Use of Data Act, is a US law passed on March 23, 2018, aiming to facilitate personal data collection.

À retenir

The Cloud Act, Clarifying Lawful Overseas Use of Data Act, is a US law passed on March 23, 2018, aiming to facilitate personal data collection.

The Cloud Act, Clarifying Lawful Overseas Use of Data Act, is a law that was passed and enacted on March 23, 2018 by the United States.

The Cloud Act aims to facilitate the collection of personal data hosted by cloud service providers.

The Cloud Act seems to contradict some essential principles of the GDPR[1].

What is the Cloud Act?

The Cloud Act is a law requiring service providers (Amazon, Facebook, Salesforce, Microsoft, IBM, Twitter, Google, Apple) to cooperate with the government by providing their users’ personal data.

From now on, all data hosted by a US provider can be transmitted to police authorities, government agencies, and the entire US administration.

Thus, a French company domiciled in the United States may also be affected by this new measure, even if its activities are French.

For certain multinational US companies (Apple, Google, Oath, Facebook, and Microsoft) the Cloud Act would ensure better consumer protection and facilitate the resolution of legal conflicts.

Are personal data protected?

Many questions can be asked regarding the scope of this new law, especially since the European Union has just strengthened the legal framework for personal data via the GDPR.

Everything suggests that the Cloud Act poses a threat and a risk to the protection and security of data.

The Cloud Act allows the executive to enter into bilateral agreements with other governments to exchange information stored on the servers of US companies without involving a judge to validate the transfers.

At the same time, foreign administrations that have signed the Cloud Act agreement can also have access to the data of US citizens.

Note that seizures of personal data are only authorized within the framework of a criminal investigation and must only serve the purposes of the investigation.

Can we oppose this new measure?

Many digital freedom associations and NGOs contest this new measure and wish to oppose disclosure requests.

In principle, telecommunications or electronic communications operators can oppose disclosure requests if the customer is not a US citizen or a regular permanent resident and if the disclosure of information conflicts with the law

[1]http://eur-lex.europa.eu/legal-content/FR/TXT/PDF/?uri=CELEX%3A32016R0679&from=FR

of a foreign government that has entered into an executive agreement with the US government.

Note that there is a real conflict between the GDPR and the Cloud Act regarding data storage and transfer. Indeed, the General Data Protection Regulation (GDPR) aims to strengthen the protection of personal data within the European Union by ensuring its security and confidentiality.

Regarding data transfers outside the European Economic Area, they can in no case decrease the level of data protection.

Finally, disclosure requests could have serious consequences for the protection of business secrets.

Many questions remain unanswered, particularly regarding the protection of personal data. Will we be able to oppose the Cloud Act?

Case to be continued…

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi

Free, no spam, one-click unsubscribe.