Megaupload and Equinix are in the news today. Apparently the Attorney General of Canada applied to the Ontario Superior Court for an order requiring them to turn over "cloud servers" on behalf was US Government (as reported by Chris Bennett of Davis LLP on Mondaq.com).
What's not clear to me yet is what is actually meant by "cloud servers" and how this could impact cloud computing in particular. We all know how the term "cloud" has been used repeatedly in cases where the service is not actually cloud computing (see my previous posts on the topic of cloudwashing and other posts on nomenclature). Are the servers actually IaaS and fit the NIST definition of cloud computing or are they simply hosted web servers and databases?
It appears that the judicial system could use some clarification as to what cloud computing actually is and the difference between cloud computing and cloud based services.
More to come as this story develops.
The Case for Cloud is an ongoing discussion about cloud computing and how it impacts business and the economy.
Showing posts with label law. Show all posts
Showing posts with label law. Show all posts
Mar 15, 2013
Oct 15, 2012
Live Blog -- CLoud Launch: Martin Kratz
One of the perennial questions around cloud computing is how tio protect intellectual property in a world where everything is offered as a service and scalable.
Martin Kratz, of Bennet Jones LLP, is pointing out that contracts for cloud based services are not the same as traditional outsourcing or service contracts because the cloud vendor you deal with is probably relying on other cloud vendors as well to keep their own costs down by treating every customer the same.
Kratz contradicts Fisher by saying that risk should not necessarily be embraced without appropriate mitigation and that customization is not necessarily de rigueur: "terms of service are often non-negotiable and tend to favour the service provider".
Kratz outlines some legal issues to consider when contracting with cloud service providers:
One of the most common issues related to those Kratz mentioned has to do with information lifecycle management.
Martin Kratz, of Bennet Jones LLP, is pointing out that contracts for cloud based services are not the same as traditional outsourcing or service contracts because the cloud vendor you deal with is probably relying on other cloud vendors as well to keep their own costs down by treating every customer the same.
Kratz contradicts Fisher by saying that risk should not necessarily be embraced without appropriate mitigation and that customization is not necessarily de rigueur: "terms of service are often non-negotiable and tend to favour the service provider".
Kratz outlines some legal issues to consider when contracting with cloud service providers:
- Service security
- Trade secret protection information confidentiality
- Data integrity
- Compliance with privacy laws and regs
- Assurance of data segregation
One of the most common issues related to those Kratz mentioned has to do with information lifecycle management.
- Does the organisation have an ILM policy?
- How is it managed?
- Is it enforced?
- How is data stored in the cloud impacted by this policy?
- Is the cloud service provider adhereing to their customers' ILM requirements?
- Who has ultimate control over the data?
Jun 28, 2011
FBI raid targetted Lulz Group?
Reports from news outlets (NY Times, CBC) suggest that the target of the FBI raid was Lulz Group, a hacker organization that are allegedly responsible for some high profile hacks such as Sony and, possibly, the CIA.
Regardless of the target, the FBI's tactics have been criticized as being heavy handed, though they may be justified in that the target was a purported hacker ring who may have had various assets stored on adjacent equipment hosted by their data center provider. While I am not a lawyer, it is incumbent on the FBI to ensure that all private information remains private and that it is not disclosed publicly, by accident or by design; the warrant should limit their investigation to information that is relevant to the target.
I will continue to look for information related to this event and will post more as it becomes available.
Regardless of the target, the FBI's tactics have been criticized as being heavy handed, though they may be justified in that the target was a purported hacker ring who may have had various assets stored on adjacent equipment hosted by their data center provider. While I am not a lawyer, it is incumbent on the FBI to ensure that all private information remains private and that it is not disclosed publicly, by accident or by design; the warrant should limit their investigation to information that is relevant to the target.
I will continue to look for information related to this event and will post more as it becomes available.
May 2, 2011
What does the election in Canada and cloud computing have in common? Issues with Article 329.
Canada is a big country. Really. Big. So big, it has 6 time zones; by the time the West coast wakes up, the East coast has already had 3-4.5 hours of productive time. So big, in fact, that election results from the East coast are available before polling stations close on the West coast. And, if you Tweet, blog, or post on a wall in Facebook about results in the East before polls have closed in the West, you're breaking the law. Go figure.
In this day and age of social media and ubiquity of computing, the ability to share information is so great, that it can accelerate revolution. You know, the kind that deposes authoritarian governments? Despots aside, this technology can land you in trouble if you share election results. There is a section of the Canada Elections Act that governs "Premature Transmission":
In a sense, social media is the wild west: it is difficult to control and regulate, applicable laws are a grey area at best, and there are as many opinions are there are users. What, then, is the responsibility of the service providers such as Twitter and Facebook? Private information being what it is, and terms of use being what they are, are Twitter and Facebook, US based companies, obligated to divulge private information of users who are being investigated by Elections Canada and/or the RCMP for violations of Section 329? Can Canadian users hide behind US companies?
Assuming that the charges are specific, which they would be considering the infraction, these organizations would simply comply with a subpoena or warrant. Not to mention that your hardware would be confiscated and used to collect evidence against you. What does this mean? Your footprint is out there. Even if you delete an account, data persists in backups and can be used to build a case against you.
Obviously this was intended to keep elections fair and to avoid influencing voters in an era of television and radio broadcasts. Clearly, the Elections Act never contemplated that information could be shared in such an environment as the Internet, and particularly, in social media. Changes to the electoral procedure have reduced this discrepancy between East and West down to 1.5 hours but this gap is sufficient to be in violation of the law.
Legalities and discourse on right and wrong aside, this is a good example of a Government's right to prosecute an individual and obtain private information in an effort to enforce law. However archaic it may be.
In this day and age of social media and ubiquity of computing, the ability to share information is so great, that it can accelerate revolution. You know, the kind that deposes authoritarian governments? Despots aside, this technology can land you in trouble if you share election results. There is a section of the Canada Elections Act that governs "Premature Transmission":
"329. No person shall transmit the result or purported result of the vote in an electoral district to the public in another electoral district before the close of all of the polling stations in that other electoral district."
Assuming that the charges are specific, which they would be considering the infraction, these organizations would simply comply with a subpoena or warrant. Not to mention that your hardware would be confiscated and used to collect evidence against you. What does this mean? Your footprint is out there. Even if you delete an account, data persists in backups and can be used to build a case against you.
Obviously this was intended to keep elections fair and to avoid influencing voters in an era of television and radio broadcasts. Clearly, the Elections Act never contemplated that information could be shared in such an environment as the Internet, and particularly, in social media. Changes to the electoral procedure have reduced this discrepancy between East and West down to 1.5 hours but this gap is sufficient to be in violation of the law.
Legalities and discourse on right and wrong aside, this is a good example of a Government's right to prosecute an individual and obtain private information in an effort to enforce law. However archaic it may be.
Labels:
government,
law,
privacy,
regulation
May 27, 2010
Jurisdiction, or, I have to comply with whose laws?
Judith Hurwitz, of Hurwitz & Associates, has a slide in one of her presentations that refers to protecting data in the cloud and reads, "Government and Industry regulation must be adhered to regardless of the location of your applications and your information."
The first thing that popped into mind was the classic 70s cop show scene where the cops, all sporting mutton chops and polyester leisure suites, are arguing about ownership of the crime scene...
The next thing that popped into mind was how confusing this must be; organizations have to be aware of, and comply with, the laws and/or regulations that apply to their operations in the country where the application(s) and data sit as well as their own country's. There can be no other interpretation of the slide because we know that privacy laws in Europe can be tough and those in the US are different but yet there is an expectation of data privacy in both jurisdictions. The slide deck contains several examples ranging from specific country laws, co-mingling of data, secondary data use, and the next point, data transfer across borders.
What about data in transit? Is data subject to the laws and/or regulations of the jurisdictions through which it passes en route to/from the site hosting the application? There are restrictions on sending data out of some European countries unless the receiving end complies with European requirements on data security, but what of the countries in between? Data stored in Europe usually go through gateways to get to North America and then through a gateway into the US, Canada, or Mexico and vice-versa. I suppose that the argument can be made that data in transit over backbone infrastructure is not susceptible to attack. But then I recall a certain government agency that wanted to snoop Internet data streams not too long ago...
What of the end users' expectation of privacy? If these users are in yet another country, can the requirements of that country be imposed on the applications' owner? Can lawsuits be filed in this case?
The simplest and most efficient solution would be to comply with the common requirements and the most stringent requirements from each country in order to be compliant with all. Not sure if this is the answer but it seems that it could be. Then again, I'm no lawyer so I may be wrong here.
The first thing that popped into mind was the classic 70s cop show scene where the cops, all sporting mutton chops and polyester leisure suites, are arguing about ownership of the crime scene...
The next thing that popped into mind was how confusing this must be; organizations have to be aware of, and comply with, the laws and/or regulations that apply to their operations in the country where the application(s) and data sit as well as their own country's. There can be no other interpretation of the slide because we know that privacy laws in Europe can be tough and those in the US are different but yet there is an expectation of data privacy in both jurisdictions. The slide deck contains several examples ranging from specific country laws, co-mingling of data, secondary data use, and the next point, data transfer across borders.
What about data in transit? Is data subject to the laws and/or regulations of the jurisdictions through which it passes en route to/from the site hosting the application? There are restrictions on sending data out of some European countries unless the receiving end complies with European requirements on data security, but what of the countries in between? Data stored in Europe usually go through gateways to get to North America and then through a gateway into the US, Canada, or Mexico and vice-versa. I suppose that the argument can be made that data in transit over backbone infrastructure is not susceptible to attack. But then I recall a certain government agency that wanted to snoop Internet data streams not too long ago...
What of the end users' expectation of privacy? If these users are in yet another country, can the requirements of that country be imposed on the applications' owner? Can lawsuits be filed in this case?
The simplest and most efficient solution would be to comply with the common requirements and the most stringent requirements from each country in order to be compliant with all. Not sure if this is the answer but it seems that it could be. Then again, I'm no lawyer so I may be wrong here.
Labels:
cloud,
governance,
law,
privacy
Subscribe to:
Posts (Atom)