What is the GDPR?
The GDPR is a European data protection regulation, aimed to protect the personal data of European Union (EU) citizens.
Any organization storing or processing information about EU citizens must comply with the GDPR. It defines personal data as any information that is related to an identified or identifiable natural person. GDPR applies to any organization that processes or collects personal data of EU citizens, either within data centers in Europe or to/from outside Europe.
These are the main GDPR chapters dealing with technical measures that might be related to cloud services:
- Chapter 2—Principles
- Chapter 3—Rights of the data subject
- Chapter 4—Controller and processor
- Chapter 5—Transfer of personal data to third countries or international organizations
- Chapter 9 —Provisions relating to specific processing situations
Here are some practices for protecting personal data:
- Encrypt all personal...