Why is this relevant for businesses?
Companies that either have an establishment within the EU or process data belonging to EU citizens because they operate in the European market are subject to the General Data Protection Regulation (GDPR). Article 48 stipulates that data may only be transferred to third countries on a legal basis (usually so-called bilateral mutual legal assistance agreements).
In concrete terms, this means for US companies: if they comply with the Cloud Act, they are in breach of the GDPR. If they comply with the GDPR, they are in breach of the Cloud Act. As they face legal consequences in the US that could threaten the company’s continued existence, they opt for the Cloud Act when in doubt.
If your company is a customer of one of the US companies mentioned (or a comparable provider from the US), you can therefore never be certain that your stored data will not be passed on. It is your responsibility to ensure that the data is not accessible to unauthorised parties: according to the European Data Protection Board, the Cloud Act does not provide a sufficient basis for transferring data.
The fact that using these services may breach data protection regulations is not the only risk: your confidential business information may also be disclosed if you store it via a company subject to the Cloud Act. Industrial espionage is a possibility – and you could lose important competitive advantages.
What should you keep in mind when using U.S. providers?
US companies are keen to limit the damage. Most of them now advertise their EU-based data centres, for example:
- Microsoft 365 EU Data Boundary
- Google Sovereign Control
- Amazon European Sovereign Cloud
That is, however, a smokescreen – the Cloud Act also applies to these data centres.
For all these providers, the data collected is worth its weight in gold, which is why they gather it in vast quantities. The State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg (LfDI), in collaboration with the state’s Ministry of Culture, has tested a functionally restricted version of Microsoft 365 designed to comply as closely as possible with data protection regulations for use in schools, and has still identified many issues that argue against its deployment:
- User behaviour is logged in full and in detail.
- Emails are analysed.
- It is not possible to completely disable the processing of personal data – it continues to be carried out to an extent that is not necessary for the provision of the service.
- Even in direct discussions, the LfDI did not receive a complete overview of all processing of personal data from Microsoft representatives.
- Measurements revealed the transmission of data to over 500 Microsoft servers, which could not be prevented; the purposes were documented in only a very small number of cases.
In short: It is not possible to completely prevent data from being transferred to US providers, and in many cases it is not even possible to track such transfers. If your company uses services provided by these providers, there is no reliable way to prevent your data and confidential information from being passed on.
How can a company protect itself from this?
The solution to this dilemma sounds deceptively simple, but it can involve a major change. Use platforms that have no links to the US – in other words:
- are not US companies
- do not have branches in the US
- are not listed on the US stock exchange
- do not use US data storage infrastructure
Such companies are subject exclusively to European compliance and data protection requirements. In addition, the following points are important:
- Ensure that client-side encryption is possible and that the provider itself has no access.
- Choose a provider that allows you to assign access permissions on an individual basis.
- Enter into a detailed data processing agreement with the provider, setting out how data may be processed in accordance with the GDPR.
You should also ensure that the European company has not been acquired by a US corporation: otherwise, it will also be subject to the Cloud Act.
Why are Open Circle solutions not affected by the Cloud Act?
Open Circle is a Swiss company that places great emphasis on independence:
- We offer scalable IT solutions based on open-source technologies.
- Our company is not based in the USA, nor does it use services provided by American corporations.
- We use data centres located exclusively in Switzerland.
- We are ISO-certified and offer the highest standards.
Our solutions make it easier for you to store your data in compliance with the GDPR and, for example, to comply with the German Federal Data Protection Act or the Swiss Federal Act on Data Protection (DSG).
Bottom line: Play it safe
Even though using systems such as Microsoft 365 or iCloud may seem like the only option at first glance, this is not the case. Making the switch is well worth it for the security of your customers’ data and your company’s confidential information. We then ensure further security by providing you with data storage solutions that are not subject to the Cloud Act. Please feel free to contact us.
