Cloud Computing
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Use of cloud services and associated data protection requirements
Overview
17 sources · Sep 25, 2026Legal Framework
Cloud computing services are governed by an overlapping set of EU instruments. Under NIS2, cloud computing service providers are classified as essential or important entities subject to cybersecurity risk-management and incident-reporting obligations. Recital 33 defines the scope:
"Cloud computing services should cover digital services that enable on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources"
— NIS2 Recital 33
This definition explicitly encompasses IaaS, PaaS, SaaS, and NaaS, across private, community, public, and hybrid deployment models, aligning with ISO/IEC 17788:2014. Recital 84 confirms that cloud computing service providers are subject to "a high degree of harmonisation at Union level," with implementing acts facilitating cybersecurity risk-management measures. Non-EU providers offering services within the Union must designate an EU representative under Recital 116. Article 23 imposes incident notification duties on essential and important entities, requiring notification to the relevant CSIRT without undue delay.
On the data protection side, the GDPR applies to cloud providers acting as processors or controllers. The EDPB's Opinion 17/2021 recognises that the CISPE Code of Conduct aims to contribute to proper GDPR application "taking into account the specific features of the cloud computing sector."
Key Developments
The General Court in Amazon EU Sàrl v European Commission drew a clear boundary between cloud computing services and online platforms under the Digital Services Act (Regulation 2022/2065). The court upheld that marketplaces cannot be equated with cloud services for systemic-risk purposes:
"cloud computing or web-hosting services should not be considered to be an online platform where dissemination of specific information to the public constitutes a minor and ancillary feature or a minor functionality of such services"
— Amazon EU Sàrl v European Commission ¶140
This distinction matters because it determines which regulatory regime applies: cloud providers fall under NIS2 and GDPR obligations rather than the DSA's platform-specific transparency and risk-mitigation duties.
The EDPB has further clarified the functional differences between service models. For SaaS specifically:
"users are ultimately meant to outsource their data to the individual provider"
— EDPB Opinion 17/2021 §6
This characterisation directly informs the processor-controller analysis under Article 28 GDPR, as the degree of data control varies significantly between IaaS, PaaS, and SaaS arrangements.
Status of the Debate
This topic is actively contested in court. The boundaries between regulatory regimes — NIS2, GDPR, and the DSA — remain in flux, as evidenced by the Amazon litigation challenging whether marketplace services should be treated analogously to cloud computing. No definitive court split has crystallised yet, but the question of when a cloud service crosses into platform regulation under the DSA, and how processor-controller roles are allocated across different cloud service models, would benefit from further CJEU guidance. The EDPB's endorsement of sector-specific codes of conduct (CISPE and Scope Europe) signals a regulator-driven approach to standardising compliance, but these codes do not bind absent formal adoption by supervisory authorities.
Practical Guidance
- Classify your service model precisely. Determine whether you provide IaaS, PaaS, SaaS, or NaaS under the Recital 33 definition, as this classification drives both NIS2 obligations and the GDPR processor-controller analysis under Article 28.
- Map NIS2 incident-reporting triggers. Establish internal thresholds for what constitutes a "significant incident" under Article 23 and build notification workflows to the relevant CSIRT, including cross-border escalation procedures.
- Designate an EU representative if established outside the Union. Under Recital 116, non-EU cloud providers offering services to persons in Member States must appoint a representative — mere website accessibility is insufficient, but use of EU languages or currencies triggers the obligation.
- Clarify processor vs. controller status contractually. For SaaS models where users outsource data to the provider, ensure Article 28 data processing agreements reflect the actual allocation of data-control responsibilities, particularly for sub-processor chains.
- Consider adherence to an approved code of conduct. EDPB-endorsed codes such as CISPE provide a practical compliance benchmark aligned with sector-specific cloud characteristics, supporting accountability under Article 24 GDPR.
why this is here
As the cloud service provider in the third country has adhered to a code of conduct to be used as a tool for transfers relating to cloud services approved under Article 40 - 5, data flows from Company XYZ and its affiliates to the cloud service provider can be framed with the code of conduct
The document provides a concrete example of using codes of conduct for cloud service providers in international transfers.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The CLOUD Act applies to EU entities that process data outside of the US, even if the EU entities are located outside of the US.
This document directly addresses how the US CLOUD Act affects cloud data storage and the obligations of EU cloud providers, making it a primary source for cloud computing data protection requirements.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
stored several police reports on such related incidents in the cloud of a U.S. service provider
The case highlights risks of using foreign cloud services for special category data without adequate safeguards, illustrating cloud-specific compliance issues.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
These agreements enable law enforcement in one state to directly request data from service providers based in the other state.
It concerns how law enforcement can obtain data from service providers, which relates to cloud data access, though the focus is on legal process rather than cloud technology itself.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the disciplinary measure continued to be published on a cloud platform even after the measure was revoked
The document mentions a cloud platform only as the medium of continued publication, not as the central subject of the data protection violation.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
scan the personal pictures on our phones, the documents on our clouds
Cloud storage is mentioned only as an example of what would be scanned, not as a central subject.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.