Showing posts with label cloud computing. Show all posts
Showing posts with label cloud computing. Show all posts

28 August 2013

The National Cloud Computing Strategy - clear skies ahead?

Posted by Harry Aitken, Rosie Johnson and Paul Kallenbach

In late May of this year, Senator Stephen Conroy, Minister for Broadband, Communications and the Digital Economy (as he then was) announced The National Cloud Computing Strategy (Strategy) at the Cloud @ CeBIT Conference held in Sydney.  Unfortunately the conference was not held on SKYWALK at the Sydney Tower, which somewhat limits the number of 'sky' and 'cloud' puns we could have otherwise used in this paragraph.  But we digress ...      
cloud computing
noun the provision of services over the internet to allow users to remotely store, process and share electronic information.
Cloud computing is not, as the name might otherwise suggest, using technology to compute the structure, pattern and formation of clouds.  (We apologise in advance to any nephologists who may have stumbled across this blog post.)  Cloud computing, rather, is the use of computer platforms to deliver services over the internet.  Whenever you use your Gmail account, online banking service, Amazon or iTunes, you're engaging with the brave new(ish) world of cloud computing.

Returning to the Strategy, the Government's aim is to address three goals:
  • for the Australian Government to be a leader in the use of cloud technology, creating efficiencies and generating value and to deliver better services and create more agility in the public service;
  • for Australian small business, not-for-profit organisations and consumers to have the protection and tools they need to acquire cloud services with confidence; and
  • for Australia to have a vibrant cloud sector supported by a skilled and cloud-aware information and communication technologies (ICT) workforce, able to create and adopt cloud services, effective competition in cloud services, and regulatory settings that support growth, foster innovation and protect users.
The Strategy goes on to detail steps which the Government considers might be taken in order to achieve these goals.

What is the Government proposing to do?

The Government plans to lead by example and adopt cloud computing in its own enterprise.   It also plans to assist other government agencies and non-government organisations to do the same by identifying training and skill development opportunities to facilitate the adoption of cloud computing and encourage lines of communication between Government agencies about what works and what doesn't.

The Strategy identifies that smaller businesses are likely to obtain the most benefit from the adoption of cloud computing mechanisms.   Consequently, in order to empower small businesses and not-for-profit organisations to utilise cloud computing, the Government will strive to enhance the information in the market in relation to cloud computing and the likely benefits to smaller businesses which might not otherwise take up the opportunity or be able to obtain sufficient information in order to make and informed decision.   The Government identifies that there is a lot of information about cloud computing but that is not easy to understand, and aims to release publications and information in a more digestible format.  The Government also plans to open the lines of communication between cloud service providers and consumers in order to better consider issues which may arise.

In relation to its aim of encouraging a vibrant cloud services sector, reliable internet access is central, and the Government not surprisingly touts the the National Broadband Network as a key aspect in providing the infrastructure necessary to facilitate the expanding use of cloud computing.  Using the tertiary education sector is another way identified by the Government to increase the knowledge and skills of cloud computing, hence a proposal to incorporate cloud computing into the ICT curriculum and encourage further research and development activities in this area.

Impact?

So how might the Strategy impact consumers and business owners?

The Strategy posits that cloud computing can enhance functionality, mobility, scalability and security for businesses, enable them to scale their processing up and down as their capacity changes, and employ a range of diverse services for each task.  The Strategy also suggests that everyday consumers may benefit – 33% of 1,000 sampled small and medium Enterprises (SMEs) who were surveyed in 2012 'indicated they would be quite likely to pass on cost savings achieved through the adoption of cloud services to their consumers'.   For business owners, greater efficiencies may lead to increased profits, which can be invested in things which will assist the growth of the business, including providing consumers with a greater range of goods and services. 

For cloud computing service providers, the Strategy aims to expand their market reach.  Ensuring appropriate measures are taken to protect users will be an area of government and media scrutiny going forward; however there are opportunities for providers with strong data protection mechanisms in place to make a big splash in the Australian market.  IDC predicts that the cloud computing market sector will be valued at $2,030 million by 2015, and by 2020, almost 40% of digital information will be affected by cloud computing in some manner.[1]

The regulatory setting

Presently, there is a complex mix of international, domestic and industry-specific regulations and standards which apply to cloud computing practices. 

Australian consumers and businesses have general contractual, consumer and privacy protection under the law of contract; the Privacy Act 1988 (most relevantly, the new APP 8, which comes into effect in March 2014, and will impose new obligations on government agencies and private sector organisations in relation to the the overseas disclosure of personal information ); the Competition and Consumer Act 2011 and the Australian Consumer Law; the Telecommunications (Interception and Access) Act 1979 and other statutes besides.  On the industry front, the Telecommunications Act 1997 seeks to promote competition and facilitate access to telecommunication infrastructure, while the Australian Prudential Regulatory Authority (APRA) regulates the outsourcing and offshoring activities of banks and other financial institutions through prudential standards, including, most relevantly, Prudential Standards CPS 231 and SPS 231.   

However, none of these instruments have been designed with the cloud in mind, and the emergence of cloud-based providers - who may fall outside existing legislative categorisations and standards - potentially weakens the efficacy of the regulatory framework.  Moreover, the cross-border nature of cloud services raises difficult issues of jurisdiction and enforcement, since national laws may not extend to the conduct of service providers who are based in other countries.

As a consequence, the Australian Communications and Media Authority (ACMA), in a recent paper,[2] has proposed that while the National Cloud Computing Strategy aims to stocktake the current regulatory framework, a 'single coherent framework' should still be sought. 

The Australian Computer Society's Cloud Consumer Protocol discussion paper may be a useful first step in this regard.  The paper aims to elicit feedback from cloud service providers and customers on the tools and protections that they require in order to acquire and deploy cloud services with confidence and trust. 

Submissions on the Cloud Consumer Protocol paper are open until 5 September 2013.  

[1] IDC EMC, The Digital Universe in 2020: Big Data, Bigger Digital Shadows and Biggest Growth in the Far East, cited in Australian Communications and Media Authority, The cloud – services, computing and digital data: Emerging issues in media and communications (Occasional paper 3, June 2013).

[2] Australian Communications and Media Authority, The cloud – services, computing and digital data: Emerging issues in media and communications (Occasional paper 3, June 2013). 

16 March 2012

The seven deadly sins of cloud computing


Image courtesy of paul (dex)
Much has been written about the legal implications and risks associated with cloud computing. Some of the potential risks are large and cloud-specific, while others are simply regular issues associated with obtaining services from a third party. All of them need to be properly managed. However, the level of due diligence, customised terms, and type of cloud solution you need depends on the complexity and business criticality of your systems. That need increases exponentially if complex and business critical systems are sent into the cloud by a regulated entity such as a bank or insurance company.

There are six deadly sins to be avoided, and one which should be committed, in relation to the cloud. Most of them are committed by those who focus too much on protecting their client's or company's position at the expense of delivering business outcomes, or who don't understand the solution their client or company needs for their business model. As a result they may ask for too much, or not enough.

SlothDon't be so lazy you don't move your data out of Australia simply because of data privacy restrictions. Current privacy legislation and even prudential regulation don't mean you can't move your data offshore, but you do need to put in place proper provisions with your cloud providers, particularly in respect of sensitive information. However, be aware that in the future it may be that some types of data simply cannot be moved. For example, currently draft legislation provides that certain health records won't be able to be held or taken out of Australia. 

PrideNot often related to the sin of Sloth, but the sin of pride here might be nationalistic pride. It's fine to keep your data onshore and only use Australian providers because of concern about the US Patriot Act, just remember not only does the Act apply to Australian subsidiaries of US companies, but the US has law enforcement treaties with Australia. You will face similar issues of government access to data in every country (those without legislative power to do so will be of greater risk), so think about whether any cloud is the right solution. 

GluttonyHaving a great availability service level doesn't necessarily mean you get all you can eat from the cloud. Cloud service levels shouldn't be solely about availability and you should also consider disaster, security, and backup related service levels, among others. You also need to pay particular attention to how availability is measured. For example, if the measure is only by reference to infrastructure the service level may be met even if your service, platform or application isn't available (remember Amazon's EC2 outage?).

WrathYou don't need to fight for everything in relation to liability provisions. Does it really matter if an application testing platform isn't working if you have access to another one? If it's not a critical application and you don't miss development milestones then aren't you really only looking for a refund for an unsuitable service? Save your fight for consequential loss for when you are using the cloud to store confidential, sensitive, or important information.

GreedA sin you should commit in relation to the cloud. Be greedy about your data both in terms of its ownership and use but also about your ability to get it back, not only on termination, but also at any time during the contract term. You also need to get it back in a form that is usable and transferable to another provider or back into your own systems. That means getting it in a form you specify or as part of a package which gives you the ability to extract it.

EnvyDon't be envious of others' move to cloud computing. If your solution needs to be heavily customised or an agreement heavily negotiated to meet your business model then it may soon erode the value of moving to a cloud solution. Equally, it might just be that certain of your data and systems should not be in the cloud. At least not yet.

LustDon't lust over a cloud computing contract which covers off every risk. Getting back to my earlier point, you need to assess the business needs (paying appropriate attention to laws/regulations) and then get what is necessary to achieve those business needs while adequately protecting your business. If you really only want to get access to the cloud for some spare capacity to test a non-critical application, then it may be okay to sign the vendor's standard terms and conditions and get on with it. But do make sure you read them.

17 February 2012

Sending data overseas - don't worry, be happy?

Posted by Veronica Scott    Partner: Paul Kallenbach
Image courtesy of lennysan

Any decision to host its email services offshore triggers privacy law compliance issues for Telstra.  Our focus in this blog post is on the transborder data flow requirements of National Privacy Principle 9 (NPP9) of the Privacy Act 1988 (Cth) as they apply to offshore hosting.

Last Friday, Telstra announced that BigPond customers will soon experience its new "BigPond with Windows Live" integrated email service.  It is rumoured that Microsoft will host the service offshore (though Telstra will retain a copy of all BigPond emails locally).

NPP9

NPP9 permits an organisation to transfer personal information about an individual to an organisation outside Australia, but only if the transfer meets one or more of the six conditions in NPP9.  The four conditions relevant to Telstra in this scenario are likely to be:

(a)  it has a reasonable belief  that Microsoft, as the recipient of the personal information, is obliged by law or otherwise to uphold principles substantially similar to the NPPs;

(b)  it has taken reasonable steps to ensure that Microsoft will not use or disclose the information inconsistently with the NPPs;

(c)  its customers consent (expressly or impliedly) to the transfer; and/or

(d)  all of the following apply:
  • the transfer is for the benefit of the customers;
  • it is impracticable to obtain their consent to the transfer; and
  • if it were practicable to obtain their consent, they would be likely to give it.

Telstra's Customer Terms and Conditions (Terms) set out both Telstra's and its customers' rights and obligations in respect of the BigPond email service.

Interestingly, the 60-plus pages of Terms do not expressly confer on Telstra a right to store emails offshore.  Rather, the Terms provide that '[i]nformation concerning you will be held in a database' but without specifying any particular jurisdiction or geography.

The Terms also refer to the Telstra Privacy Statement, which is one of a suite of privacy documents Telstra has for its customers.  The Privacy Statement provides that personal information is disclosed to external organisations so that Telstra may 'deliver the services you require', including 'information technology services' among others.  Telstra has reportedly confirmed that its BigPond customers will need to sign up to a new set of terms and conditions to allow it to host their emails offshore.

If Telstra's current agreement with its customers does not confer on Telstra express or implied consent to transfer their personal information overseas, one of the other conditions in NPP9 must apply to allow the personal information to be transferred overseas.  Microsoft would no doubt argue that it meets condition (a), on the basis that privacy laws in the US are generally similar to, if not more stringent than, the NPPs.

However, is this argument reasonable given that certain US authorities will be able to access personal information held by Microsoft for purposes that would not otherwise be permitted if the data had stayed in Australia?  Such access would be permitted even if Telstra and Microsoft have entered into an agreement to ensure that BigPond customers' personal information is protected in a manner consistent with the NPPs – on the basis that NPP2.1(g) allows an organisation who holds personal information to disclose it if required or authorised by law to do so.  Telstra would no doubt argue that any compelled disclosure by US authorities falls squarely within NPP2.1(g).

Implications

To sidestep the (often difficult) issue of whether local privacy laws are 'substantially similar' to the NPPs, best practice would be to obtain express or implied customer consent for any prospective transborder data transfer (for example, in the organisation's terms and conditions).

Safety in the cloud?

Many businesses are concluding that their customers' personal information is likely to be more secure in the cloud than if stored by the business itself.  Small businesses in particular will generally have far less expertise in cyber and data security than large, professional technology organisations.  Moreover, protection of data for the likes of Telstra, Microsoft, Google and Apple is as much a reputational issue as a legal one.  If companies such as these cannot show that they can be trusted to protect personal data, their brands (and ultimately businesses) are likely to suffer.

Cognisant of this issue, Microsoft's Chief Privacy Officer, Brendan Lynch, said in December on Microsoft's website:

I recently returned from a two-week trip to discuss a range of privacy topics with customers and regulators in Australia and New Zealand. In virtually every conversation, I was asked about Microsoft’s approach to data protection in our cloud services. Microsoft representatives around the world report hearing similar questions regularly in each of their regions. These questions are understandable [...] At Microsoft, we understand that unless we are responsive to our customers’ and to regulators’ questions about data protection in public clouds, we will not earn the trust necessary for our cloud services to satisfy our customers’ needs.
In the next 12 months we'll see the continued rollout of the National Broadband Network (NBN), together with faster and more reliable mobile internet services (such as 4G LTE).  This will no doubt further bolster the adoption of cloud apps by both businesses (think Salesforce.com, Microsoft Windows Live, Google Apps and many more besides) and consumers (think Apple iCloud, Dropbox, Spotify, Evernote, amongst many others).  Indeed, as reported in today's Communications Day, KPMG has estimated that the total GDP impact of cloud computing adoption over the next decade in the finance, property, business services and education sectors, will be around $1.6 billion a year. 

However, with a number of serious data breaches having occurred in 2011, demonstrably strong data protection will be required in order to maintain business, consumer and government confidence in cloud services.

25 November 2011

Litigation, document production and storing data in the cloud

Posted by Sandra Draganich
Image courtesy of lennysan

Litigation issues are often not given the consideration they deserve when negotiating the terms of cloud service provider agreements.  Perhaps this is because negotiation is often undertaken by commercial managers and technical staff to the exclusion of the legal team, or because no-one likes to think they'll end up in litigation.  Even when the legal team is involved, the focus tends to be on regulatory compliance, privacy and data security issues, rather than dispute resolution or litigation.

The recent introduction of civil dispute legislation at the Federal level (the Civil Dispute Resolution Act 2011 (Cth)) and Victoria (Civil Procedure Act 2010 (Vic))  - with similar legislation expected to be introduced in other Australian jurisdictions - provides a timely reminder of the importance of considering the impact that storing data in a cloud might have on any litigation in which the owner of the data is involved.

The legislation aims to encourage the early resolution of disputes and, to that end, the early identification of the real issues in dispute.

At the Federal level, the Civil Dispute Resolution Act obliges an applicant to inform the Court (via the filing of a 'genuine steps statement' when proceedings are issued) of the steps taken to resolve the dispute.   The Act provides, as an example of what might constitute a 'genuine step', the provision of documents to the other person to enable them to understand the issues involved and how the dispute might be resolved.

In Victoria, the Civil Procedure Act applies when proceedings are on foot, and obliges parties to a proceeding to comply with certain 'overarching obligations', including an obligation to disclose critical documents at the earliest reasonable time after the relevant party becomes aware of their existence.

What this means, on a practical level, is that a litigant needs to ensure that it has ready access to its documents, including those stored in the cloud: being able to access and retrieve data quickly and in an admissible form will best position a party to pursue, or defend, any claim, as well as meet any disclosure or discovery obligations it needs to meet should litigation ensue.

Of course, quick access to documents is generally desirable should a person be involved in litigation, irrespective of the application of the recent legislation. For example, notices to produce might be issued on short notice, or a party might be involved in litigation with an expedited timetable so that discovery might need to be completed within a short timeframe.   If documents are stored in the cloud, the party's ability to comply at short notice might be impeded, absent any contractual 'safeguards' with the cloud service provider.

Cloud computing arrangements, while various in nature, typically involve the cloud service provider receiving, processing, holding and storing client data at a location separate from the client (and sometimes overseas).   As the client generally does not have possession of the data or documents (but does have 'control' of the data or documents in the sense of a legally enforceable right to call for production), several key issues arise when litigation looms, including data access, retrieval and integrity.   These issues need to be carefully considered at the time of negotiating a cloud service provider agreement.

Data access and retrieval

The timely retrieval of data will be pivotal in determining a client's ability to pursue or defend any litigation, or comply with any subpoenas to produce (failing which the client will be in contempt of court).

For this reason, provider agreements should expressly address service levels, data availability and turnaround times for requests for access to or the return of data.  As soon as proceedings are issued, the client should think about what data might need to be reviewed (and retrieved), and make an early request from the cloud service provider for the retrieval of the data.  Enquiries should also be made of the cloud service provider before agreeing to any discovery timetable as this will be relevant to the client's ability to comply with any timetable set by a court.  If possible, a contractual indemnity should be obtained from the service provider, so that it is obliged to indemnify its client in respect of any loss occasioned as a result of delays (such as costs associated with a court hearing in relation to non-compliance with a discovery timetable).

Integrity

A client might wish to ensure that its data is stored separately from that of others (eg, if privacy or confidentiality issues are of concern), and that only designated people or groups have access to the data. The issue of ownership might be particularly important if the cloud service provider becomes insolvent.

Contractual protections should also include prohibitions against altering or modifying the data (other than as agreed), as this might raise questions about ownership (including of intellectual property rights) in relation to the modified version of data and, importantly, the integrity and therefore admissibility of the data should the client become involved in litigation and the data is required to be produced to the court or tendered in evidence.

In this regard, whilst the Uniform Evidence Acts contain provisions directed towards facilitating the admissibility of electronic data or documents, it might be prudent to impose a contractual obligation on the cloud service provider to provide all necessary assistance in relation to legal proceedings in which the client is involved, including an obligation to provide evidence as to the manner in which the data has been stored and retrieved should data integrity become an issue on a challenge to admissibility.

Other matters

Cloud service provider agreements should also address the client's rights and obligations in the event that the agreement is terminated by either party, where the agreement naturally comes to an end, or where the cloud provider becomes insolvent.

The location of the data and the cloud provider are also very important.  A client should be mindful of the potential application of foreign laws, for example the application of foreign insolvency laws on the insolvency of the cloud service provider, or the application of general laws of the jurisdiction entitling a third party to access data within its jurisdiction (eg, the USA PATRIOT Act).

Other jurisdictional issues relate to the proper law of the service agreement; the service of proceedings should the client wish to issue proceedings against the cloud service provider for breach of the service agreement; and the enforcement of any judgment in the client's favour should it succeed in any proceedings.

Some more general issues relating to the use of the cloud are canvassed in AGIMO's paper, 'Negotiating the cloud - legal issues in cloud computing agreements', released earlier this month.

Partner: Paul Kallenbach

08 July 2011

Coadec pushes for the UK to adopt progressive IP reforms

Image courtesy of plusonetwo
Posted by Nicholas Stewart

The United Kingdom's Coalition for a Digital Economy (Coadec) is lobbying David Cameron's Government to adopt the recommendations contained in Professor Ian Hargreaves' May 2011 report Digital Opportunity: A Review of Intellectual Property and Growth.

In the context of copyright, Professor Hargreaves is of the opinion that:
… digital technology is transforming copyright, for better and for worse. Infringement is widespread; understanding of the law is poor; millions of works cannot be digitised for conservation or accessed at all and content industry business models are under strain, prompting companies to look to Government for vigorous enforcement action against consumers and suppliers of “pirate” content.
Professor Hargreaves cites examples of inefficiency in copyright licensing in the UK, such as:
  • the BBC taking nearly five years to assemble the rights necessary to launch its iPlayer service;
  • an online business providing on demand streaming of radio shows and DJ mixes undertaking lobbying of collecting societies for about nine months before it could 'make any headway on licensing';
  • other businesses reporting inconsistency in licensing discussions, with some users offered access to licences and others denied access without clear explanation; and
  • some businesses threatened with legal action instead of the opportunity to negotiate terms.
He recommends, among other things, that the United Kingdom should establish a Digital Copyright Exchange. Professor Hargreaves says a Digital Copyright Exchange would, for creators of copyright:
  • improve routes to market;
  • provide a means to record unmistakeably the ownership of rights, and the terms on which they are available;
  • provide a clearer understanding of licensing terms and conditions throughout the market;
  • increase options available to license an individual creator’s works directly;
  • provide a defence against rogue “orphaning” of works, through digital fingerprinting; and
  • provide a single point of access to UK collecting societies and eventually to competitor societies in other territories.
Coadec's open letter to the UK Government of 29 June 2011 expresses a belief that:
… the Hargreaves report represents a watershed for this country’s digital economy. The report recognises - as many digital businesses and entrepreneurs have known for a long time - that the nation’s intellectual property laws, and in particular copyright law, must adapt to business, social and technological change.
With the latest developments in cloud computing in the digital music space in the United States (we're thinking Apple's iCloud and iTunes Match products, Google's Google Music Beta and Amazon's Cloud Player), it will be interesting to observe how the UK approaches the regulation of IP in the context of rapidly evolving technologies and platforms.

Partner: Paul Kallenbach

02 February 2011

Clouding Australian export control laws

Posted by Tim Hewitt - 4.30pm - 2 February 2011

The Department of Defence has announced that it is preparing proposals to amend Australia's export control laws to require licensing for intangible transfers of controlled technology. While these amendments are in recognition of a gap in Australia's export control regime caused by sophisticated transfers of controlled technology via intangible means, they may cause compliance woes for many organisations, particularly cloud computing service providers.

Currently, Australia's export control regime only requires licensing for exports of controlled items listed in the Defence and Strategic Goods List that are exported in a physical form (e.g., CD, DVD, HDD or on paper); whereas exports of controlled data, software or technology (collectively, 'controlled technology') via the internet, telephone lines, satellite and other intangible means are only prohibited if it can be deemed that the transferor believed or suspected that the transferee would or would likely use that controlled technology in connection with a weapon of mass destruction.

At this stage it is not clear what compliance measures will be required and many may be caught off guard. For example, a person in Australia sending encryption and information security software in an email to a colleague, client or other contact overseas will likely be considered to be making an export of controlled technology. The new regime may even extend to organisations providing the means of transfer such as cloud computing service providers.

It may seem an incongruous result that a cloud computing service provider would be considered the exporter of controlled technology given that the transfer is initiated by the cloud user. However, if the cloud users (i.e., the transferor and the transferee) who access an Australian-based cloud to initiate a transfer of controlled technology are both overseas, it may only be possible for Australian authorities to control that transfer by regulating the cloud computing service provider which receives the controlled technology on its server and then "exports" it to the transferee overseas.

Authorities in the U.S – where licensing is already required for intangible exports of controlled technology – are currently grappling with this issue. However, no legislative changes in the U.S have been made yet that can inform developments here in Australia regarding the compliance obligations of cloud computing service providers and other organisations indirectly involved in the export of controlled technology via intangible means.

Until further details of the proposed changes are released, organisations that transfer controlled technology via intangible means, as well as organisations like cloud computing service providers that may be indirectly involved in that transfer, need to "watch this space" for further developments and consider how those developments will impact their operations. If these developments are likely to cause complicated compliance procedures − for example, if it is proposed that every single transfer of controlled technology requires separate authorisation − it may be worth petitioning the Department of Defence and participating in any public consultations.

Special Counsel: Geoff Shelley