Cloud Computing: Between Innovation and Privacy

Innovation as we know it has come to the pace that can no longer be coped and limited. With the advent of technology and information transparency, everyone can simply get into the innovation game and compete on the base of merit. Cloud computing has arrived in the recent years as one of the most talked-about innovation. It is said to be simplifying complex works and elevating efficiency. As canonical as the innovation has brought to human kinds, it is then also utilized in many sectors, including the conduct of smart cities. Smart cities have long been recognized as the way-out in the inconvenience of cities’ disarrayed bureaucracy and lagged efficiency. However, recent concerns have also risen on whether data and privacy can still be safeguarded, in the midst of rising concern about the security breach, sovereignty, and privacy. How shall then privacy and innovation be perceived?

Cloud computing, like a lot of other discourse on contemporary science, does not have any single reference to what it actually is. According to Baun et. al, cloud computing refers to virtual computing and storing technology that provides scalable, network-centric, abstracted IT infrastructures, platforms, and applications as on-demand services.[i] Further, Che (2011) also adds that this supercomputing method allows customers to dynamically share a mass of hardware, software and data resources.[ii] Additionally, the IT research and advisory company Gartner uses a simplified definition and defines cloud computing as a style of computing in which scalable and elastic IT-enabled capabilities are delivered as a service using Internet technologies.[iii] Cloud computing is essentially made up of three types/models. The types include Private Cloud (with private data center), Public Cloud (with public data center) and Hybrid Cloud (with a flexible choice of data center possession and location, or usually the mix of public and private data centers). These types of cloud services come in the forms of Infrastructure as a Service/IaaS (where we ‘build’ the services with shared infrastructure like network equipment, storage system, and the like), Platform as a Service/PaaS (where we buy the platform on which the cloud service is run), and Software as a Service (where we can run the deployed cloud software directly without having to build own infrastructure and develop own software).[iv]

It turns out; cloud computing is compromising a lot of privacy and integrity issues in states. About 64% of organizations, including companies and public institutions, cite that issues of compliance, auditing and privacy are the biggest challenges present on the use of cloud computing.[v] In the digital era, where everything is connected to the internet, a security breach is becoming a lot more visible and stands as one particular threat everyone has been looking out. Cloud computing, which provides data storage that streams the internet, is no exception. Organizations begin to put even more scrutiny on the fact that cloud computing works transcending the international border and jurisdictions, as data centers are scattered around the globe, across the continents. The data center locations affect the legal jurisdictions regarding the data stored in these particular locations; which leads us to the issue of data sovereignty. Data sovereignty is the concept that digital data is subject to the laws or legal jurisdiction of the country in which it is stored.[vi] So cloud service providers may have access to the data stored in their data centers despite the locations being in other countries, and the data belonging to foreign countries. Not only that, the country which hosts the location of the data center may also have access to the data stored in their country, even if this data belongs to other countries. Some perceive this as potential threats to security and privacy breach by foreign cloud service providers and foreign countries. Further, willingness to outsource the need of storage to a third party may be harming the privacy of users in the case of data disclosure under integrated framework. Under this compromise, the vast amount of data that is analyzed on the cloud is fundamentally accessible by the service providers, even much more than what was known and agreed by the users.[vii]

Different countries may have different jurisdictions and legal instruments in regards to data protection and infringement. Australia is one country that begins to put concerns on this matter, as the Australian Privacy Principles (APPs) gravitate towards any offshore data delivery to make sure their national companies’ data are careful in managing data.[viii] The Canadian government, through the Privacy Act, the Personal Information Protection and Electronic Documents Act (PIPEDA) and the recently passed act, Digital Privacy Act (DPA), regulated the conduct of information transfers and disclosures under the mechanism of cloud computing, without limiting its operations, even under foreign companies. The Canadian government has put emphasis on the need for a more careful, wiser, and well-informed conduct of their companies in using cloud computing, especially when it comes to foreign service providers.[ix] Other governments even took bolder actions, by insisting on keeping their data and national information inside the country. In late 2015, Austrian government brought the case of data localization to the Court of Justice of the European Union (CJEU), which then made safe harbour (storing data overseas or to foreign service providers) illegal.[x] Germany also imposed strict data privacy and sovereignty policy through Deutsche Telekom, which oversees all data access. More than that, the country mandates that consumers’ data should stay in the country.[xi]

The controversy surrounding the legitimacy of data protection and access has then escalated into its most prominent position nowadays. In one side, cloud computing clearly revolutionizes economic activities, through its ability to enhance economies of scale and vigorous efficiency. At the same time, people begin to question the very necessity of pursuing one, especially if it costs them their privacy and sovereignty over data, while the undeniably beneficial use of cloud computing should (and can) never be denied and put aside. The line should immediately be drawn, especially by the government. The government holds the role as the regulator in making sure that every laws and jurisdiction are adhered by everyone, including the users and service providers of cloud computing. This is also because the government has to make sure that the interest of its people, both civil and business society, is always protected and upheld. Most cases on cloud computing legality nowadays are indeed majorly centred in policy and compliance, where cloud service providers are not able to provide their services due to legal liability and policy-related circumstances. Hence, the key is in the hands of governments. However, like most dichotomies driven by innovation, policy and regulatory frameworks always arrive late.  

By the time we are waiting for the high-level debates to come up with clear legal jurisdictions, we should be more aware and careful in adopting innovations. Not only on informing ourselves with the ‘cloud computing 101’, but we should also catch up with other more technical issues – for example, interoperability standards and cloud infrastructure – to suppress risks attached to cloud computing. Cloud service providers have also become more accustomed to dealing with legality concerns advocated with governments, as the start to build more data centers in more places to accommodate in-country data storage. Amazon Web Services, for example, is committed to building more data centers in the UK for their operations in the country.[xii] One thing that matters is that innovation shall not be stopped, but be compromised.


[i] Baun, C., Kunze, M., Nimis, J., and Tai, S. (2011). Cloud Computing: Web-Based Dynamic IT Services. Heidelberg: Springer.

[ii] Che, J., Duan, Y., Zhang, T., and Fan, J. (2011). Study on the security models and strategies for cloud computing. Procedia Engineering, 23, pp. 586-593

[iii] Gartner. (2011). Gartner IT Glossary: Cloud Computing. [online] Available at: http://www.gartner.com/it-glossary/cloud-computing [Accessed 16 March 2017]

[iv] Nguyen, D. Q. (2017). Security and Privacy Issues in Cloud Computing. [online] Narga. Avalable at: https://www.narga.net/security-privacy-issues-cloud-computing/ [Accessed 16 March 2017].

[v] Ross, M. (2015). 10 things to know about data security and sovereignty in the cloud. [online] MSPmentor. Available at: http://mspmentor.net/blog/10-things-know-about-data-security-and-sovereignty-cloud [Accessed 16 March 2017]

[vi] Ross, M. (2015). 10 things to know about data security and sovereignty in the cloud. [online] MSPmentor. Available at: http://mspmentor.net/blog/10-things-know-about-data-security-and-sovereignty-cloud [Accessed 16 March 2017]

[vii] De Filippi, P., and McCarthy, S. (2012). Cloud Computing: Centralization and Data Sovereignty’. European Journal for Law and Technology, 3(2), pp. 1-18

[viii] Fresser, D. (2015). Data Sovereignty: What it is and why it matters. [online] r&g technologies. Available at: http://rgtechnologies.com.au/resources/data-sovereignty/ [Accessed 16 March 2017]

[ix] Blue Coat Systems. (2016). Privacy Legislation in Canada. [online]. Available at: https://www.bluecoat.com/resources/cloud-governance-data-residency-sovereignty/canada-data-privacy-laws [Accessed 17 March 2017]

[x] Bradbury, D. (2015). After safe harbour: Navigating data sovereignty. [online] The Register. Available at: https://www.theregister.co.uk/2015/12/17/navigating_data_sovereignty/ [Accessed 17 March 2017]

[xi] Darrow, B. (2016). Microsoft Opens Its First Cloud Data Centers in Germany. [online] Fortune. Available at: http://fortune.com/2016/09/21/microsoft-germany-data-centers/ [Accessed 17 March 2017]

[xii] Richards, D. (2016). What the Brexit vote will mean for data sovereignty.  [online] Cloud Tech. Available at: https://www.cloudcomputing-news.net/news/2016/jul/13/what-brexit-vote-will-mean-data-sovereignty/ [Accessed 17 March 2017]