Cloud and GDPR concerns
Although the GDPR takes a risk-based approach to data protection, it makes no mention of the cloud directly. The regulation, on the other hand, is technology-neutral in that it applies regardless of the method used to treat personal data. The fragmented processing environment of the cloud, where such standards may not always apply, makes it difficult to implement the GDPR. The challenges are broken down in some detail in the following sections.
Security concerns specific to the cloud
The European Data Protection Supervisor (EDPS) and the European Union Agency for Network and Information Security (ENISA) have stated that the specific features and processes linked to the different service and deployment models of a cloud infrastructure imply specific risks compared to a “traditional” on-premises data center.
NIST defines three service models (SaaS, PaaS, and IaaS) and four deployment models: public, private, community, and hybrid (a composition...