Skip to content
Topic Contested in court

Cloud Computing

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Use of cloud services and associated data protection requirements

66 linked items 12 Laws1 Case Law24 Guidance4 Enforcement19 News

Overview

17 sources · Jul 23, 2026

Legal Framework

Cloud computing services fall within the scope of multiple EU regulatory instruments. Under NIS2 (Recital 33), cloud computing encompasses IaaS, PaaS, SaaS, and NaaS models, all involving on-demand access to scalable, shareable computing resources distributed across locations. Cloud service providers designated as essential or important entities under NIS2 must implement risk management measures and report significant incidents.

The GDPR governs cloud arrangements primarily through Articles 28 and 32. Article 28 mandates that controllers use only processors providing sufficient guarantees of technical and organizational measures, with a binding Article 28(3) contract specifying processing scope, purpose, duration, data type, and obligations. Article 32 requires security measures appropriate to the risk, including encryption, pseudonymization, and regular testing. Where the cloud provider is a sub-processor, Article 28(4) requires equivalent flow-down obligations.

The AI Act (Recital 55) introduces additional obligations where AI systems serve as safety components in critical digital infrastructure, including cloud-based systems listed under Annex I, point 8 of Directive (EU) 2022/2557. Such systems are classified as high-risk, triggering conformity assessment and risk management requirements.

Key Developments

Enforcement actions confirm that inadequate cloud security configurations carry direct financial liability. The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 for failing to apply appropriate technical and organizational measures, demonstrating that cloud deployment without sufficient access controls and encryption violates Article 32 GDPR. The Italian Garante's enforcement against Federazione Italiana Sommelier, Albergatori e Ristoratori further illustrates that even smaller-scale cloud-related data handling failures attract sanctions.

The EDPB Guidelines 07/2020 on controller and processor concepts clarify that cloud providers typically act as processors, but the determination depends on the degree of control exercised over processing purposes and means. The EDPB Guidelines 9/2022 on personal data breach notification establish that cloud-related breaches — including unauthorized access through misconfigured storage — trigger the 72-hour notification obligation under Article 33 when they compromise personal data confidentiality, availability, or integrity.

Practical Guidance

  • Execute Article 28(3) GDPR-compliant data processing agreements with all cloud providers, explicitly addressing sub-processor authorization, international transfer mechanisms, and breach notification timelines.
  • Implement Article 32-appropriate technical measures before migration: encrypt data at rest and in transit, enforce multi-factor authentication, and configure least-privilege access controls — the Umeå University decision confirms absence of these measures constitutes a violation.
  • Conduct and document Transfer Impact Assessments where cloud infrastructure involves non-adequate third countries, relying on SCCs or adequacy decisions as the transfer basis.
  • Map cloud-based AI components against the AI Act's high-risk classification where they function as safety components in critical digital infrastructure, triggering risk management and conformity obligations.
  • Establish internal breach detection and reporting pipelines capable of meeting the 72-hour Article 33 notification window, accounting for the time cloud providers require to notify controllers of incidents.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 12
Art. 6(30) ‘cloud computing service’ means a digital service that enables on-demand administration and broad remote access to a scalable and elastic pool of shar… NIS2 Art. 6(34) ‘representative’ means a natural or legal person established in the Union explicitly designated to act on behalf of a DNS service provider, a TLD name… NIS2 Art. 21(5) By 17 October 2024, the Commission shall adopt implementing acts laying down the technical and the methodological requirements of the measures referre… NIS2 Art. 23(11)(cont)(1) By 17 October 2024, the Commission shall, with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre se… NIS2 rec 33 Recital 33 — cloud computing services definition and models NIS2 Dec 2022 rec 117 Recital 117 — ENISA registry of digital service entities NIS2 Dec 2022 rec 116 Recital 116 — non-EU digital service provider EU representative NIS2 Dec 2022 rec 114 Recital 114 — single Member State jurisdiction for digital service providers NIS2 Dec 2022 rec 84 Recital 84 — harmonised cybersecurity rules for digital service providers NIS2 Dec 2022 rec 35 Recital 35 — data centre services coverage NIS2 Dec 2022 rec 113 Recital 113 — member state jurisdiction over entities NIS2 Dec 2022 rec 13 Recital 13 — online platform subcategory definition and scope DSA Oct 2022 rec 34 Recital 34 — emerging distributed cloud and edge models NIS2 Dec 2022 rec 28 Recital 28 — new online technologies intermediary services DSA Oct 2022 rec 29 Recital 29 — online intermediary service categories and examples DSA Oct 2022 rec 55 Recital 55 — high-risk AI in critical infrastructure AI Act Jun 2024
Case Law 1
¶139 Third, the applicant submits that, as regards ‘the dissemination of speech, content or information’, marketplaces should be treated in the same way as… Judgment of the General Court (Seventh Chamber, Extended Composition) of 19 November 2025.#Amazon EU Sàrl, venant aux droits de Amazon Services Europe Sàrl v European Commission.#Digital services – Regulation (EU) 2022/2065 – Designation as a very large online platform – Plea of illegality – Admissibility – Article 33(1) and (4) of Regulation 2022/2065 – Right to respect for private and family life – Freedom to conduct a business – Right to property – Equal treatment – Freedom of expression – Da ¶140 In that regard, it should be noted that recital 13 of Regulation 2022/2065 states that ‘cloud computing or web-hosting services should not be consider… Judgment of the General Court (Seventh Chamber, Extended Composition) of 19 November 2025.#Amazon EU Sàrl, venant aux droits de Amazon Services Europe Sàrl v European Commission.#Digital services – Regulation (EU) 2022/2065 – Designation as a very large online platform – Plea of illegality – Admissibility – Article 33(1) and (4) of Regulation 2022/2065 – Right to respect for private and family life – Freedom to conduct a business – Right to property – Equal treatment – Freedom of expression – Da ¶3 3.1. Grand Relocation vordert, na eiswijziging, om bij uitvoerbaar bij voorraad verklaard vonnis: I. gedaagden, zowel gezamenlijk als ieder voor zich,… Rechtbank Amsterdam, 24-06-2026 (C/13/787825) ¶2 13. In de bijlage is het wettelijk kader opgenomen. 14. Solvinity heeft volgens de staatssecretaris door de inhoud van haar dienstverlening en haar ro… Rechtbank Rotterdam, 14-07-2026 (ROT 26/5003) 367/23 Judgment of the General Court (Seventh Chamber, Extended Composition) of 19 November 2025.#Amazon EU Sàrl, venant aux droits de Amazon Services Europe Sàrl v European Commission.#Digital services – Regulation (EU) 2022/2065 – Designation as a very large online platform – Plea of illegality – Admissibility – Article 33(1) and (4) of Regulation 2022/2065 – Right to respect for private and family life – Freedom to conduct a business – Right to property – Equal treatment – Freedom of expression – Da General Court Nov 2025
Guidance 24
§84 Advisable measures: ( The list of the following measures is by no means exclusive or comprehensive. Rather, the goal is to provide prevention ideas an… Guidelines 01/2021 §7 It should also be noted that a code intended for transfers adhered to by a data importer in a third country can be relied on by controllers/processors… Guidelines 04/2021 on Codes of Conduct as tools for transfers §57 In addition, personal data stored on vehicles and/or at external locations (e.g., in cloud computing infrastructures) may not be adequately secured ag… Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications §72 Local data processing should be considered by car manufacturers and service providers, whenever possible to mitigate the potential risks of cloud proc… Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications on processing of personal data through blockchain technologies Guidelines on processing of personal data through blockchain technologies EDPB Jul 2026 guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 012020 on processing personal data in the context of connected Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Mar 2021 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines 202402 article48 v2 Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 012020 on measures that supplement transfer tools to Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data EDPB Jun 2021 172021 on the draft decision of the french Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE) EDPB May 2021 82026 on the draft decision of the dutch supervisory Opinion 8/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the IBM Group EDPB Mar 2026 72024 on the draft decision of the german north rhine Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria EDPB Apr 2024 162021 on the draft decision of the belgian Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe EDPB May 2021 edps joint opinion 032021 on the proposal for a regulation of EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act) EDPB Mar 2021 guidelines interplay between digital Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation EDPB Oct 2025 statement 202504 commission s draftmcts dataact Statement 4/2025 on the European Commission’s Recommendation on draft non-binding model contractual terms on data sharing under the Data Act EDPB Jul 2025 report 20250313 support pool experts programme 2024 Report on the use of SPE external experts in 2024 EDPB Mar 2025 082024 on valid consent in the context of consent or Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms EDPB Apr 2024 Show 4 more →
Enforcement 4
Persónuvernd (Island) Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive Persónuvernd (Island) Jul 2026 APD/GBA (Belgium) Belgian DPA rules on competence in cross-border cookie consent complaint involving APD/GBA (Belgium) Jan 2022 Italian Data Protection Authority (Garante) Federazione Italiana Sommelier, Albergatori e Ristoratori: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Jun 2022 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Umeå University: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Dec 2020
News 19
EDPB Support the EDPB’s work as an expert EDPB Nov 2025 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 EDPB Support the work of the EDPB as an expert. EDPB Nov 2025 NCSC Netherlands The operation of the CLOUD Act in data storage in Europe NCSC Netherlands Oct 2022 NCSC Netherlands De werking van de CLOUD Act met betrekking tot dataopslag in Europa. NCSC Netherlands Oct 2022 NL Brooklyn Law School Digital Privacy Rights and CLOUD Act Agreements between US and UK Brooklyn Law School Sep 2022 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 EDPB EDPB adopts statement on European Police Cooperation Code & picks topic for next coordinated action EDPB Sep 2022 Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL Brooklyn Law School Rechten met betrekking tot digitale privacy en overeenkomsten in het kader van de CLOUD Act tussen de Verenigde Staten en het Verenigd Koninkrijk. Brooklyn Law School Sep 2022 NL European Digital Rights The EU’s home affairs chief wants to read your private messages European Digital Rights Mar 2023 Fair Trials Europol wordt gevraagd om persoonlijke gegevens over te dragen aan een Nederlandse activist. Fair Trials Sep 2022 NL Fair Trials Europol told to hand over personal data to Dutch activist Fair Trials Sep 2022 Hunton Andrews Kurth De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming). Hunton Andrews Kurth Aug 2022 NL Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022 EDPB Het EDPB (Europees Comité voor de Bescherming van Persoonsgegevens) heeft een verklaring aangenomen over de Europese Code voor politiecoöperatie en heeft een onderwerp gekozen voor de volgende gecoördineerde actie. EDPB Sep 2022 NL The Markup Who Is Collecting Data from Your Car?Who Is Collecting Data from Your Car? The Markup Jul 2022 Hunton Andrews Kurth De Ierse autoriteit voor gegevensbescherming heeft Instagram een boete van 405 miljoen euro opgelegd vanwege schendingen van de privacy van kinderen. Hunton Andrews Kurth Sep 2022 NL
Literature 6
IJARCCE Challenges of Cloud Data Privacy in Surveillance: Legal, Technical, and Ethical Implications IJARCCE Jul 2026 Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 As-Syar i Jurnal Bimbingan & Konseling Keluarga Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia As-Syar i Jurnal Bimbingan & Konseling Keluarga Jul 2026 Comparative Law Review General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens? Comparative Law Review Feb 2018 European Journal of Privacy Law & Technologies Dalla guida assistita alle driverless cars: rischio tecnologico e responsabilità civile European Journal of Privacy Law & Technologies Jan 2026 i-lex Perspectives for Open Source AI i-lex Jul 2026