Cloud Computing
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Use of cloud services and associated data protection requirements
Overview
17 sources · Jul 23, 2026Legal Framework
Cloud computing services fall within the scope of multiple EU regulatory instruments. Under NIS2 (Recital 33), cloud computing encompasses IaaS, PaaS, SaaS, and NaaS models, all involving on-demand access to scalable, shareable computing resources distributed across locations. Cloud service providers designated as essential or important entities under NIS2 must implement risk management measures and report significant incidents.
The GDPR governs cloud arrangements primarily through Articles 28 and 32. Article 28 mandates that controllers use only processors providing sufficient guarantees of technical and organizational measures, with a binding Article 28(3) contract specifying processing scope, purpose, duration, data type, and obligations. Article 32 requires security measures appropriate to the risk, including encryption, pseudonymization, and regular testing. Where the cloud provider is a sub-processor, Article 28(4) requires equivalent flow-down obligations.
The AI Act (Recital 55) introduces additional obligations where AI systems serve as safety components in critical digital infrastructure, including cloud-based systems listed under Annex I, point 8 of Directive (EU) 2022/2557. Such systems are classified as high-risk, triggering conformity assessment and risk management requirements.
Key Developments
Enforcement actions confirm that inadequate cloud security configurations carry direct financial liability. The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 for failing to apply appropriate technical and organizational measures, demonstrating that cloud deployment without sufficient access controls and encryption violates Article 32 GDPR. The Italian Garante's enforcement against Federazione Italiana Sommelier, Albergatori e Ristoratori further illustrates that even smaller-scale cloud-related data handling failures attract sanctions.
The EDPB Guidelines 07/2020 on controller and processor concepts clarify that cloud providers typically act as processors, but the determination depends on the degree of control exercised over processing purposes and means. The EDPB Guidelines 9/2022 on personal data breach notification establish that cloud-related breaches — including unauthorized access through misconfigured storage — trigger the 72-hour notification obligation under Article 33 when they compromise personal data confidentiality, availability, or integrity.
Practical Guidance
- Execute Article 28(3) GDPR-compliant data processing agreements with all cloud providers, explicitly addressing sub-processor authorization, international transfer mechanisms, and breach notification timelines.
- Implement Article 32-appropriate technical measures before migration: encrypt data at rest and in transit, enforce multi-factor authentication, and configure least-privilege access controls — the Umeå University decision confirms absence of these measures constitutes a violation.
- Conduct and document Transfer Impact Assessments where cloud infrastructure involves non-adequate third countries, relying on SCCs or adequacy decisions as the transfer basis.
- Map cloud-based AI components against the AI Act's high-risk classification where they function as safety components in critical digital infrastructure, triggering risk management and conformity obligations.
- Establish internal breach detection and reporting pipelines capable of meeting the 72-hour Article 33 notification window, accounting for the time cloud providers require to notify controllers of incidents.