Cloud, contract, liability, outsourcing
David Navetta Talks About Service Provider Liability
By InfoLawGroup LLP on October 31, 2011
compliance, issa, legal defensibility, Security
ISSA Talk: Legally Defensible, Proactively Protected
By InfoLawGroup LLP on October 28, 2010
Binding Corporate Rules, Canada, Cloud, data protection, EU Data Protection Directive, international, outsourcing, PCI DSS, privacy, privacy impact assessment, security measures
A Privacy Checklist for Global Enterprises
By W. Scott Blackmer on October 21, 2010
Scott Blackmer provides a "discovery" checklist for global enterprises handling personal data from multiple jurisdictions, as well as advice on a global approach to privacy compliance and risk management.
benefits, compliance, contracts, controls, due diligence, mitigate, negotiation, outsourcing, RFP, risks
Lessons Being Learned about Cloud Computing
By InfoLawGroup LLP on July 07, 2010
Dave and I recently spoke with Nymity regarding privacy and data security issues in cloud computing deals. You can read the interview here.
Breach, breach notice, California, fines and penalties, legal defensibility, medical data, notification, Regulation
California Department of Public Health Breach Fines and Legally Defensible Security
By InfoLawGroup LLP on June 17, 2010
Binding Corporate Rules, clauses, cloud computing, consent, contract, controller, EU, EU Data Protection Directive, EU Directive, European Union, offshoring, outsourcing, processor, Safe Harbor, sstandard, standard contractual clauses
Do the New EU Processing Clauses Apply to You?
By W. Scott Blackmer on June 10, 2010
A new set of EU standard contract clauses ("SCCs" or "model contracts") for processing European personal data abroad came into effect on May 15, 2010. Taken together with a recent opinion by the official EU "Article 29" working group on the concepts of "controller" and "processor" under the EU Data Protection Directive, this development suggests that it is time to review arrangements for business process outsourcing, software as a service (SaaS), cloud computing, and even interaffiliate support services, when they involve storing or processing personal data from Europe in the United States, India, and other common outsourcing locations.
AICPA, best practices, BITS, cloud computing, COBIT, contracts, FIPS, information security, ISO 27001, ISO 27002, NIST, outsourcing, PCI DSS, SAS 70, SP 800-53, standards
Information Security Standards and Certifications in Contracting
By W. Scott Blackmer on May 26, 2010
It often makes sense to refer to an information security management framework or standard in an outsourcing contract, but this is usually not very meaningful unless the customer also understands what particular security measures the vendor will apply to protect the customer's data.
compliance, ISO 27001/2, legal defensibility, privacy notice, reasonable, risk, risk assessment, Security, security measures, security program, service provider, standards
The Legal Defensibility Era is Upon Us
By InfoLawGroup LLP on May 04, 2010
Cloud, contracting, contracts, Google, indemnification, Microsoft, outsourcing, SaaS, Security, security schedule
Cloud Providers Competing on Data Security & Privacy Contract Terms
By InfoLawGroup LLP on April 12, 2010
agility, best practices, compliance, IAPP, information governance, IT, Law, legal defensibility, outsourcing, privacy professionals, risk, Security, security breach, technology, whitepaper
Privacy's Trajectory
By InfoLawGroup LLP on March 14, 2010
As many of our readers know, the International Association of Privacy Professionals (IAPP) will celebrate 10 years this Tuesday, March 16. In connection with that anniversary, the IAPP is releasing a whitepaper, "A Call For Agility: The Next-Generation Privacy Professional," tomorrow, March 15. I am honored that the IAPP has given me the opportunity to read and blog about the whitepaper in advance of its official release.
cloud computing, EU Directive, international data transfers, model contracts, outsourcing, standard contract clauses, standard contractual clauses, transborder data flows
EU Adopts New Standard Contract Clauses for Foreign Processors
By W. Scott Blackmer on February 08, 2010
The European Commission has announced a new set of standard contractual clauses to be used in agreements with processors located outside the EU / EEA. The new SCCs represent an effort to better ensure privacy protection when European personal data are passed on to subcontractors in business process outsourcing, cloud computing, and other contexts of successive data sharing.
Breach, contracting, e-Discovery, Electronic evidence, EU Directive, IaaS, outsourcing, PaaS, privacy, SaaS, Security, service provider
Legal Implications of Cloud Computing -- Part One (the Basics and Framing the Issues)
By InfoLawGroup LLP on August 16, 2009
I had the pleasure of hearing an excellent presentation by Tanya Forsheit on the legal issues arising out of cloud computing during the ABA Information Security Committee's recent meeting (at the end of July) in Chicago. The presentation resulted in a spirited debate between several attorneys in the crowd. The conversation spilled over into happy hour and became even more interesting. The end result: my previous misunderstanding of cloud computing as "just outsourcing" was corrected, and now I have a better appreciation of what "the cloud" is and the legal issues cloud computing raises.