Skip to content
Topic Contested in court

Cloud Computing

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Use of cloud services and associated data protection requirements

67 linked items 12 Laws1 Case Law24 Guidance4 Enforcement20 News

Overview

17 sources · Sep 25, 2026

Legal Framework

Cloud computing services are governed by an overlapping set of EU instruments. Under NIS2, cloud computing service providers are classified as essential or important entities subject to cybersecurity risk-management and incident-reporting obligations. Recital 33 defines the scope:

"Cloud computing services should cover digital services that enable on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources"
— NIS2 Recital 33

This definition explicitly encompasses IaaS, PaaS, SaaS, and NaaS, across private, community, public, and hybrid deployment models, aligning with ISO/IEC 17788:2014. Recital 84 confirms that cloud computing service providers are subject to "a high degree of harmonisation at Union level," with implementing acts facilitating cybersecurity risk-management measures. Non-EU providers offering services within the Union must designate an EU representative under Recital 116. Article 23 imposes incident notification duties on essential and important entities, requiring notification to the relevant CSIRT without undue delay.

On the data protection side, the GDPR applies to cloud providers acting as processors or controllers. The EDPB's Opinion 17/2021 recognises that the CISPE Code of Conduct aims to contribute to proper GDPR application "taking into account the specific features of the cloud computing sector."

Key Developments

The General Court in Amazon EU Sàrl v European Commission drew a clear boundary between cloud computing services and online platforms under the Digital Services Act (Regulation 2022/2065). The court upheld that marketplaces cannot be equated with cloud services for systemic-risk purposes:

"cloud computing or web-hosting services should not be considered to be an online platform where dissemination of specific information to the public constitutes a minor and ancillary feature or a minor functionality of such services"
— Amazon EU Sàrl v European Commission ¶140

This distinction matters because it determines which regulatory regime applies: cloud providers fall under NIS2 and GDPR obligations rather than the DSA's platform-specific transparency and risk-mitigation duties.

The EDPB has further clarified the functional differences between service models. For SaaS specifically:

"users are ultimately meant to outsource their data to the individual provider"
— EDPB Opinion 17/2021 §6

This characterisation directly informs the processor-controller analysis under Article 28 GDPR, as the degree of data control varies significantly between IaaS, PaaS, and SaaS arrangements.

Status of the Debate

This topic is actively contested in court. The boundaries between regulatory regimes — NIS2, GDPR, and the DSA — remain in flux, as evidenced by the Amazon litigation challenging whether marketplace services should be treated analogously to cloud computing. No definitive court split has crystallised yet, but the question of when a cloud service crosses into platform regulation under the DSA, and how processor-controller roles are allocated across different cloud service models, would benefit from further CJEU guidance. The EDPB's endorsement of sector-specific codes of conduct (CISPE and Scope Europe) signals a regulator-driven approach to standardising compliance, but these codes do not bind absent formal adoption by supervisory authorities.

Practical Guidance

  • Classify your service model precisely. Determine whether you provide IaaS, PaaS, SaaS, or NaaS under the Recital 33 definition, as this classification drives both NIS2 obligations and the GDPR processor-controller analysis under Article 28.
  • Map NIS2 incident-reporting triggers. Establish internal thresholds for what constitutes a "significant incident" under Article 23 and build notification workflows to the relevant CSIRT, including cross-border escalation procedures.
  • Designate an EU representative if established outside the Union. Under Recital 116, non-EU cloud providers offering services to persons in Member States must appoint a representative — mere website accessibility is insufficient, but use of EU languages or currencies triggers the obligation.
  • Clarify processor vs. controller status contractually. For SaaS models where users outsource data to the provider, ensure Article 28 data processing agreements reflect the actual allocation of data-control responsibilities, particularly for sub-processor chains.
  • Consider adherence to an approved code of conduct. EDPB-endorsed codes such as CISPE provide a practical compliance benchmark aligned with sector-specific cloud characteristics, supporting accountability under Article 24 GDPR.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 04/2021 Codes of Conduct as tools for transfers Guidelines on codes of conduct and monitoring bodies Guidelines ·EDPB Guidance EDPB Feb 2022 Cloud service provider example
why this is here
As the cloud service provider in the third country has adhered to a code of conduct to be used as a tool for transfers relating to cloud services approved under Article 40 - 5, data flows from Company XYZ and its affiliates to the cloud service provider can be framed with the code of conduct

The document provides a concrete example of using codes of conduct for cloud service providers in international transfers.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

The operation of the CLOUD Act in data storage in Europe GreenbergTraurig has assessed the scope of the US CLOUD Act on commission by the Dutch government. The CLOUD Act applies to EU entities that process data outside of the US, even… News NCSC Netherlands Oct 2022 CLOUD Act scope for cloud providers
why this is here
The CLOUD Act applies to EU entities that process data outside of the US, even if the EU entities are located outside of the US.

This document directly addresses how the US CLOUD Act affects cloud data storage and the obligations of EU cloud providers, making it a primary source for cloud computing data protection requirements.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€54,000 Umeå University: Insufficient technical and organisational measures to ensure information security The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures… SWEDEN ·IMY ·Art. 5, 32 Enforcement Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Dec 2020 Cloud storage of sensitive data
why this is here
stored several police reports on such related incidents in the cloud of a U.S. service provider

The case highlights risks of using foreign cloud services for special category data without adequate safeguards, illustrating cloud-specific compliance issues.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Digital Privacy Rights and CLOUD Act Agreements between US and UK The CLOUD Act agreements between the US and UK will likely improve the digital privacy rights of US and UK citizens, but they will further undermine these rights for Third Country… News Brooklyn Law School Sep 2022 Data access and provider obligations
why this is here
These agreements enable law enforcement in one state to directly request data from service providers based in the other state.

It concerns how law enforcement can obtain data from service providers, which relates to cloud data access, though the focus is on legal process rather than cloud technology itself.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

€5,000 Federazione Italiana Sommelier, Albergatori e Ristoratori: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Federazione Italiana Sommelier, Albergatori e Ristoratori. The federation had sent a protocol containing personal data of a… ITALY ·Garante ·Art. 5, 6 Enforcement Italian Data Protection Authority (Garante) Jun 2022 cloud platform publication
why this is here
the disciplinary measure continued to be published on a cloud platform even after the measure was revoked

The document mentions a cloud platform only as the medium of continued publication, not as the central subject of the data protection violation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

The EU’s home affairs chief wants to read your private messages > The CSA Regulation, proposed by European Commissioner Ylva Johansson, could undermine the trust we have in secure and confidential processes like sending work emails,… News European Digital Rights Mar 2023 Mention of cloud storage scanning
why this is here
scan the personal pictures on our phones, the documents on our clouds

Cloud storage is mentioned only as an example of what would be scanned, not as a central subject.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026