With the EU GDPR coming into force in May 2018, requirements for managing personal data and maintaining consumer privacy become significantly more stringent, raising concerns about GDPR compliance when using cloud services. In response, two voluntary Codes of Conduct for Cloud Service Providers (CSPs) were published in early 2017: the CISPE Data Protection Code of Conduct and the EU Cloud Select Industry Group (C‑SIG) Code of Conduct. These codes can help customers compare suppliers by providing a shared baseline of expected practices, but competing codes can also create confusion.
The CISPE code applies only to Infrastructure as a Service (IaaS), while the C‑SIG code is broader, covering multiple cloud service types (including SaaS and PaaS). Both codes require full compliance rather than selective adoption, yet compliance claims to date have relied on self-assessment, which limits credibility. Stronger assurance would require independent audits and monitoring bodies with meaningful enforcement authority. Importantly, neither code overrides cloud contracts or Service Level Agreements (SLAs), which are often written by CSPs on a take-it-or-leave-it basis, and neither code replaces the need for independent certification/attestation against required security standards or regulations.
Both codes stress that security and compliance responsibilities are shared between customer and provider, with CISPE offering more explicit clarity on how responsibilities split—likely because IaaS boundaries are easier to define. In most cases, the customer remains the Data Controller and must ensure GDPR-compliant processing through a legally binding agreement. Key areas covered include transparency, subcontracting, breach notification, audit rights, handling government requests, and mechanisms to demonstrate compliance, balanced against the risk of disclosing sensitive security details.
See All Locations
See All Locations