# Cloud Computing — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/cloud-computing
> Sources are cited per item. Verify against the official texts before relying on them.

Use of cloud services and associated data protection requirements

## Overview

## Legal Framework

Cloud computing services fall within the scope of multiple EU regulatory instruments. Under NIS2 (Recital 33), cloud computing encompasses IaaS, PaaS, SaaS, and NaaS models, all involving on-demand access to scalable, shareable computing resources distributed across locations. Cloud service providers designated as essential or important entities under NIS2 must implement risk management measures and report significant incidents.

The GDPR governs cloud arrangements primarily through Articles 28 and 32. Article 28 mandates that controllers use only processors providing sufficient guarantees of technical and organizational measures, with a binding Article 28(3) contract specifying processing scope, purpose, duration, data type, and obligations. Article 32 requires security measures appropriate to the risk, including encryption, pseudonymization, and regular testing. Where the cloud provider is a sub-processor, Article 28(4) requires equivalent flow-down obligations.

The AI Act (Recital 55) introduces additional obligations where AI systems serve as safety components in critical digital infrastructure, including cloud-based systems listed under Annex I, point 8 of Directive (EU) 2022/2557. Such systems are classified as high-risk, triggering conformity assessment and risk management requirements.

## Key Developments

Enforcement actions confirm that inadequate cloud security configurations carry direct financial liability. The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 for failing to apply appropriate technical and organizational measures, demonstrating that cloud deployment without sufficient access controls and encryption violates Article 32 GDPR. The Italian Garante's enforcement against Federazione Italiana Sommelier, Albergatori e Ristoratori further illustrates that even smaller-scale cloud-related data handling failures attract sanctions.

The EDPB Guidelines 07/2020 on controller and processor concepts clarify that cloud providers typically act as processors, but the determination depends on the degree of control exercised over processing purposes and means. The EDPB Guidelines 9/2022 on personal data breach notification establish that cloud-related breaches — including unauthorized access through misconfigured storage — trigger the 72-hour notification obligation under Article 33 when they compromise personal data confidentiality, availability, or integrity.

## Practical Guidance

- Execute Article 28(3) GDPR-compliant data processing agreements with all cloud providers, explicitly addressing sub-processor authorization, international transfer mechanisms, and breach notification timelines.
- Implement Article 32-appropriate technical measures before migration: encrypt data at rest and in transit, enforce multi-factor authentication, and configure least-privilege access controls — the Umeå University decision confirms absence of these measures constitutes a violation.
- Conduct and document Transfer Impact Assessments where cloud infrastructure involves non-adequate third countries, relying on SCCs or adequacy decisions as the transfer basis.
- Map cloud-based AI components against the AI Act's high-risk classification where they function as safety components in critical digital infrastructure, triggering risk management and conformity obligations.
- Establish internal breach detection and reporting pipelines capable of meeting the 72-hour Article 33 notification window, accounting for the time cloud providers require to notify controllers of incidents.

## Legislation (full text of key provisions)

### Recital 33 — cloud computing services definition and models

*Source: NIS2, nis2-rec-33-en, 2022-12-14 — https://overview.legal/posts/96594*

Cloud computing services should cover digital services that enable on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources, including where such resources are distributed across several locations. Computing resources include resources such as networks, servers or other infrastructure, operating systems, software, storage, applications and services. The service models of cloud computing include, inter alia, Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS) and Network as a Service (NaaS). The deployment models of cloud computing should include private, community, public and hybrid cloud. The cloud computing service and deployment models have the same meaning as the terms of service and deployment models defined under ISO/IEC 17788:2014 standard. The capability of the cloud computing user to unilaterally self-provision computing capabilities, such as server time or network storage, without any human interaction by the cloud computing service provider could be described as on-demand administration. The term ‘broad remote access’ is used to describe that the cloud capabilities are provided over the network and accessed through mechanisms promoting use of heterogeneous thin or thick client platforms, including mobile phones, tablets, laptops and workstations. The term ‘scalable’ refers to computing resources that are flexibly allocated by the cloud service provider, irrespective of the geographical location of the resources, in order to handle fluctuations in demand. The term ‘elastic pool’ is used to describe computing resources that are provided and released according to demand in order to rapidly increase and decrease resources available depending on workload. The term ‘shareable’ is used to describe computing resources that are provided to multiple users who share a common access to the service, but where the processing is carried out separately for each user, although the service is provided from the same electronic equipment. The term ‘distributed’ is used to describe computing resources that are located on different networked computers or devices and which communicate and coordinate among themselves by message passing.

### Recital 117 — ENISA registry of digital service entities

*Source: NIS2, nis2-rec-117-en, 2022-12-14 — https://overview.legal/posts/96762*

In order to ensure a clear overview of DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms, which provide services across the Union that fall within the scope of this Directive, ENISA should create and maintain a registry of such entities, based on the information received by Member States, where applicable through national mechanisms established for entities to register themselves. The single points of contact should forward to ENISA the information and any changes thereto. With a view to ensuring the accuracy and completeness of the information that is to be included in that registry, Member States can submit to ENISA the information available in any national registries on those entities. ENISA and the Member States should take measures to facilitate the interoperability of such registries, while ensuring protection of confidential or classified information. ENISA should establish appropriate information classification and management protocols to ensure the security and confidentiality of disclosed information and restrict the access, storage, and transmission of such information to intended users.

### Recital 114 — single Member State jurisdiction for digital service providers

*Source: NIS2, nis2-rec-114-en, 2022-12-14 — https://overview.legal/posts/96756*

In order to take account of the cross-border nature of the services and operations of DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms, only one Member State should have jurisdiction over those entities. Jurisdiction should be attributed to the Member State in which the entity concerned has its main establishment in the Union. The criterion of establishment for the purposes of this Directive implies the effective exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect. Whether that criterion is fulfilled should not depend on whether the network and information systems are physically located in a given place; the presence and use of such systems do not, in themselves, constitute such main establishment and are therefore not decisive criteria for determining the main establishment. The main establishment should be considered to be in the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken in the Union. This will typically correspond to the place of the entities’ central administration in the Union. If such a Member State cannot be determined or if such decisions are not taken in the Union, the main establishment should be considered to be in the Member State where cybersecurity operations are carried out. If such a Member State cannot be determined, the main establishment should be considered to be in the Member State where the entity has the establishment with the highest number of employees in the Union. Where the services are carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings.

### Recital 116 — non-EU digital service provider EU representative

*Source: NIS2, nis2-rec-116-en, 2022-12-14 — https://overview.legal/posts/96760*

Where a DNS service provider, a TLD name registry, an entity providing domain name registration services, a cloud computing service provider, a data centre service provider, a content delivery network provider, a managed service provider, a managed security service provider or a provider of an online marketplace, of an online search engine or of a social networking services platform, which is not established in the Union, offers services within the Union, it should designate a representative in the Union. In order to determine whether such an entity is offering services within the Union, it should be ascertained whether the entity is planning to offer services to persons in one or more Member States. The mere accessibility in the Union of the entity’s or an intermediary’s website or of an email address or other contact details, or the use of a language generally used in the third country where the entity is established, should be considered to be insufficient to ascertain such an intention. However, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering services in that language, or the mentioning of customers or users who are in the Union, could make it apparent that the entity is planning to offer services within the Union. The representative should act on behalf of the entity and it should be possible for the competent authorities or the CSIRTs to address the representative. The representative should be explicitly designated by a written mandate of the entity to act on the latter’s behalf with regard to the latter’s obligations laid down in this Directive, including incident reporting.

### Recital 84 — harmonised cybersecurity rules for digital service providers

*Source: NIS2, nis2-rec-84-en, 2022-12-14 — https://overview.legal/posts/96696*

Taking account of their cross-border nature, DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, of online search engines and of social networking services platforms, and trust service providers should be subject to a high degree of harmonisation at Union level. The implementation of cybersecurity risk-management measures with regard to those entities should therefore be facilitated by an implementing act.

### Recital 113 — member state jurisdiction over entities

*Source: NIS2, nis2-rec-113-en, 2022-12-14 — https://overview.legal/posts/96754*

Entities falling within the scope of this Directive should be considered to fall under the jurisdiction of the Member State in which they are established. However, providers of public electronic communications networks or providers of publicly available electronic communications services should be considered to fall under the jurisdiction of the Member State in which they provide their services. DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms should be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union. Public administration entities should fall under the jurisdiction of the Member State which established them. If the entity provides services or is established in more than one Member State, it should fall under the separate and concurrent jurisdiction of each of those Member States. The competent authorities of those Member States should cooperate, provide mutual assistance to each other and, where appropriate, carry out joint supervisory actions. Where Member States exercise jurisdiction, they should not impose enforcement measures or penalties more than once for the same conduct, in line with the principle of ne bis in idem.

### Recital 35 — data centre services coverage

*Source: NIS2, nis2-rec-35-en, 2022-12-14 — https://overview.legal/posts/96598*

Services offered by data centre service providers may not always be provided in the form of a cloud computing service. Accordingly, data centres may not always constitute a part of cloud computing infrastructure. In order to manage all the risks posed to the security of network and information systems, this Directive should therefore cover providers of data centre services that are not cloud computing services. For the purposes of this Directive, the term ‘data centre service’ should cover provision of a service that encompasses structures, or groups of structures, dedicated to the centralised accommodation, interconnection and operation of information technology (IT) and network equipment providing data storage, processing and transport services together with all the facilities and infrastructures for power distribution and environmental control. The term ‘data centre service’ should not apply to in-house corporate data centres owned and operated by the entity concerned, for its own purposes.

### Recital 13 — online platform subcategory definition and scope

*Source: DSA, dsa-rec-13-en, 2022-10-19 — https://overview.legal/posts/95423*

Considering the particular characteristics of the services concerned and the corresponding need to make the providers thereof subject to certain specific obligations, it is necessary to distinguish, within the broader category of providers of hosting services as defined in this Regulation, the subcategory of online platforms. Online platforms, such as social networks or online platforms allowing consumers to conclude distance contracts with traders, should be defined as providers of hosting services that not only store information provided by the recipients of the service at their request, but that also disseminate that information to the public at the request of the recipients of the service. However, in order to avoid imposing overly broad obligations, providers of hosting services should not be considered as online platforms where the dissemination to the public is merely a minor and purely ancillary feature that is intrinsically linked to another service, or a minor functionality of the principal service, and that feature or functionality cannot, for objective technical reasons, be used without that other or principal service, and the integration of that feature or functionality is not a means to circumvent the applicability of the rules of this Regulation applicable to online platforms. For example, the comments section in an online newspaper could constitute such a feature, where it is clear that it is ancillary to the main service represented by the publication of news under the editorial responsibility of the publisher. In contrast, the storage of comments in a social network should be considered an online platform service where it is clear that it is not a minor feature of the service offered, even if it is ancillary to publishing the posts of recipients of the service. For the purposes of this Regulation, cloud computing or web-hosting services should not be considered to be an online platform where dissemination of specific information to the public constitutes a minor and ancillary feature or a minor functionality of such services. Moreover, cloud computing services and web-hosting services, when serving as infrastructure, such as the underlying infrastructural storage and computing services of an internet-based application, website or online platform, should not in themselves be considered as disseminating to the public information stored or processed at the request of a recipient of the application, website or online platform which they host.

### Recital 34 — emerging distributed cloud and edge models

*Source: NIS2, nis2-rec-34-en, 2022-12-14 — https://overview.legal/posts/96596*

Given the emergence of innovative technologies and new business models, new cloud computing service and deployment models are expected to appear in the internal market in response to evolving customer needs. In that context, cloud computing services may be delivered in a highly distributed form, even closer to where data are being generated or collected, thus moving from the traditional model to a highly distributed one (edge computing).

### Recital 28 — new online technologies intermediary services

*Source: DSA, dsa-rec-28-en, 2022-10-19 — https://overview.legal/posts/95453*

Since 2000, new technologies have emerged that improve the availability, efficiency, speed, reliability, capacity and security of systems for the transmission, ‘findability’ and storage of data online, leading to an increasingly complex online ecosystem. In this regard, it should be recalled that providers of services establishing and facilitating the underlying logical architecture and proper functioning of the internet, including technical auxiliary functions, can also benefit from the exemptions from liability set out in this Regulation, to the extent that their services qualify as ‘mere conduit’, ‘caching’ or ‘hosting’ services. Such services include, as the case may be, wireless local area networks, domain name system (DNS) services, top-level domain name registries, registrars, certificate authorities that issue digital certificates, virtual private networks, online search engines, cloud infrastructure services, or content delivery networks, that enable, locate or improve the functions of other providers of intermediary services. Likewise, services used for communications purposes, and the technical means of their delivery, have also evolved considerably, giving rise to online services such as Voice over IP, messaging services and web-based email services, where the communication is delivered via an internet access service. Those services, too, can benefit from the exemptions from liability, to the extent that they qualify as ‘mere conduit’, ‘caching’ or ‘hosting’ services.

## Case law

### Judgment of the General Court (Seventh Chamber, Extended Composition) of 19 November 2025.#Amazon EU Sàrl, venant aux droits de Amazon Services Europe Sàrl v European Commission.#Digital services – Regulation (EU) 2022/2065 – Designation as a very large online platform – Plea of illegality – Admissibility – Article 33(1) and (4) of Regulation 2022/2065 – Right to respect for private and family life – Freedom to conduct a business – Right to property – Equal treatment – Freedom of expression – Da

*Source: General Court, T-367/23, 2025-11-19 — https://overview.legal/posts/132131 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023TJ0367*

Amazon EU Sàrl challenged the European Commission's decision designating Amazon Store as a very large online platform under Article 33(4) of the Digital Services Act (Regulation 2022/2065), raising pleas alleging the illegality of Articles 33(1), 38, and 39 of the regulation on grounds including violations of fundamental rights to privacy, freedom to conduct a business, property, equal treatment, and freedom of expression. The General Court (Seventh Chamber, Extended Composition) ruled on the admissibility of the plea challenging Article 33(1), finding that the application's scope was sufficiently clear and precise to permit assessment of its merits, thereby rejecting the Council's argument that the plea was inadmissible for lack of clarity.

## Guidance

### Statement 4/2025 on the European Commission’s Recommendation on draft non-binding model contractual terms on data sharing under the Data Act

*Source: EDPB, edpb-statement-202504-commission-s-draftmcts-dataact-en, 2025-07-14 — https://overview.legal/posts/51075 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-42025-on-the-european-commissions-recommendation_en*

1 Adopted Statement 4 /2025 on the European Commission’s Recommendation on draft non - binding model contractual terms on data sharing under the Data Act (version of 22 May 2025) Adopted on 8 July 2025 The European Data Protection Board has adopted the following statement: The European Commission has shared the draft non - binding model contractual terms on data sharing (‘MCTs’) and non - binding standard contractual clauses for cloud computing contracts pursuant to Article 41 of the Data Act…

### Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE)

*Source: EDPB, opinion-172021-on-the-draft-decision-of-the-french-en, 2021-05-19 — https://overview.legal/posts/126026 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-172021-on-the-draft-decision-of-the-french_en*

Adopted Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE) Adopted on 19 May 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)( b ) and Article 4 0 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal…

### Guidelines on processing of personal data through blockchain technologies

*Source: EDPB, guidelines-on-processing-of-personal-data-through-blockchain-technologies-en, 2026-07-07 — https://overview.legal/posts/125668 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-on-processing-of-personal-data-through-blockchain-technologies_en*

Guidelines 02/2025 on processing of personal data through blockchain technologies Version 2.0 Adopted on 07 July 2026 1 | Adopted Version history Version Date Adoption information version 1.1 08 April 2025 adoption of the guidelines before public consultation version 2.0 07 July 2026 adoption of the guidelines after public consultation 3 | Adopted 4 | Adopted The European Data Protection Board Having regard to Article 70 (1)(e) of the Regulation 2016/679/EU of the European Parliament and of the…

### Opinion 8/2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the IBM Group

*Source: EDPB, opinion-82026-on-the-draft-decision-of-the-dutch-supervisory-en, 2026-03-10 — https://overview.legal/posts/125686 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-82026-on-the-draft-decision-of-the-dutch-supervisory_en*

Opinion 8 / 2026 on the draft decision of the Dutch Supervisory Authority regarding the Controller Binding Corporate Rules of the IBM Group Adopted on 10 March 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)(f) and Article 47 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such…

### Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation

*Source: EDPB, joint-guidelines-interplay-between-digital-en, 2025-10-13 — https://overview.legal/posts/51268 — original: https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2025/joint-guidelines-interplay-between-digital_en*

Executive summary The Digital Markets Act (DMA) and the General Data Protection Regulation (GDPR) pursue different purposes and objectives and have different scopes. While the GDPR aims to protect natural persons with regard to the processing of personal data and ensure the free flow of personal data in the U nion covering all data controllers and processors, the DMA aims to tackle unfair prac tices, and their potential harmful effects for business users, by laying down harmonised rules…

### Guidelines 02/2024 on Article 48 GDPR

*Source: EDPB, edpb-guidelines-022024-on-article-48-gdpr, 2025-06-05 — https://overview.legal/posts/38045 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022024-on-article-48-gdpr_en*

Article  48  GDPR  provides  that:  ' Any  judgment  of  a  court  or  tribunal  and  any  decision  of  an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data  may  only  be  recognised  or  enforceable  in  any  manner  if  based  on  an  international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer...

### Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria

*Source: EDPB, opinion-72024-on-the-draft-decision-of-the-german-north-rhine-en, 2024-04-19 — https://overview.legal/posts/125759 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-72024-on-the-draft-decision-of-the-german-north-rhine_en*

Adopted 1 Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria Adopted on 17 April 2024 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64(1)(c) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal…

### Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority

*Source: EDPB, edpb-guidelines-for-identifying-a-controller-or-processors-lead-supervisory-authority, 2023-04-17 — https://overview.legal/posts/38046 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82022-on-identifying-a-controller-or-processors-lead-supervisory_en*

The European Data Protection Board (EDPB) adopted Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority, providing updated guidance on the criteria for determining main establishment and the one-stop-shop mechanism under the GDPR. The guidelines address key concepts including cross-border processing, the "substantially affects" threshold, and the steps controllers and processors must follow to identify their lead supervisory authority. This document serves as interpretive guidance with no fines or enforcement outcomes, replacing the prior WP244 guidelines endorsed by the EDPB in 2018.

## Enforcement decisions

### Belgian DPA rules on competence in cross-border cookie consent complaint involving

*Source: APD/GBA (Belgium), 2022-01-21 — https://overview.legal/posts/122841 — original: https://gdprhub.eu/index.php?title=APD/GBA_(Belgium)_-_11/2022*

Facts — The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they can control which non-essential (e.g. for advertising purposes) cookies they accept or refuse. If they choose to turn off interest-based advertising, they still see advertisements on the internet, but these are not adapted to their suspected interests or preferences. The Belgian DPA received a complaint via the Internal Market Information (IMI) system from the Berlin DPA regarding the illegitimate use of cookies on a website. More specifically, the complainant stated that (i) the tool for selecting advertising preferences did not work (cookie opt-out option for third parties does not work) and that consent was therefore not freely given; (ii) the website forced users to accept cookies in order to be able to select their advertising preferences. Holding — On cross-border processing - competence of the Belgian DPA The DPA first had to determine whether it was competent. According to Article 56 GDPR "the supervisory authority of the main establishment[...] of the controller shall be competent to at as lead supervisory authority for cross-border processing[...]". The Belgian DPA was found to be competent because the defendant had its sole place of business in Belgium, although its activities were deemed to substantially affect or be likely to affect data subjects in several Member States, including Germany. Obligation to set cookies in order to select advertising preferences on the website & "Cookie wall" practice (violation of Article 7 GDPR) - Complaint not upheld Second, the DPA had to determine whether the operator of the website lawfully placed a cookie on the complainant's device. The complainant argued that their consent was not freely given because they could not have used the website without giving it. Indeed, in its recent guidelines, the EDPB condemned the practice of making the provision of a service or access to a website conditional on accepting the placement of non-necessary cookies on the user's device. However, in this case the cookie in question was strictly necessary for the functioning of the website. The respondent indeed showed that the fact that the cookie needed to be placed in order to use certain parts of the website (namely the homepage / terms and conditions / Protecting your privacy-page) and thus the legal basis in order to process this personal data and place this cookie was not consent, but legitimate interest of the data controller (Article 6(1)(f) GDPR) Use of cookies without prior information given to the user (violation of the transparency principle - Article 5 GDPR) - Complaint upheld Third, the DPA assessed whether it was lawful to place the aforementioned cookie without providing certain information about such processing. The DPA restated that the purpose of the transparency principle is that the data subject should be able to determine what the scope and consequences of the processing encompass before it occurs. Thus, controllers are required to at least provide information on (i) the duration of the operation of cookies and (ii) whether the cookie is a first or third party one. When viewing the website, the DPA's investigation showed that even before any information could be delivered to the user, a cookie was loaded in the browser because it was otherwise technically impossible to display the necessary information in the user's language. The DPA held that due to the absence of language selection by the user, it would have been appropriate to display the information regarding the use of cookies in English, a widespread language commonly used by other websites. Thus, the Belgian DPA issued a reprimand to the operator of 'YourOnlineChoices.com' for violating Article 12 GDPR and Article 13 GDPR and ordered them to comply with their processing register - specifically to mention the third party countries personal data was sent to. Additionally, the Belgian DPA also shares some interesting insights regarding the processing of cookies: definition of 'trackers'; different types of cookies; valid consent under GDPR and ePrivacy Directive - transparency obligations

### Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive

*Source: Persónuvernd (Island), 2026-07-01 — https://overview.legal/posts/83499 — original: https://gdprhub.eu/index.php?title=Persónuvernd_(Island)_-_2025010358*

Facts — The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT department. The controller had a Microsoft Office 365 subscription, which included OneDrive and Delve for each employee. OneDrive is a cloud storage service linked to a user account, where files may be stored online rather than only locally. The data subject lodged a complaint with the Icelandic DPA (Persónuvernd) against the controller. She argued that she had been subject to unlawful electronic surveillance during her employment and that colleagues had gained unauthorised access to her computer. According to the data subject, the controller had configured her work computer and the software installed on it in such a way that colleagues and supervisors could monitor her work and view personal data stored on her desktop. She claimed that all of her data was automatically saved to a shared OneDrive of the controller and integrated into Delve. According to the data subject, through Delve her personal data was accessible to her colleagues, including passwords, personal work documents, employee-related documents, payslips and a medical certificate. She also claimed that she had witnessed a colleague opening those documents on the colleague’s own work computer. The controller denied that it had subjected the data subject to electronic surveillance or that the access controls for her file storage areas were inadequate. It argued that OneDrive was a personal file storage area assigned to each employee, that employees could access other employees’ documents only if those documents had been shared with them, and that the data subject’s personal data had been adequately secured through access controls. Holding — The DPA found no evidence that a shared enterprise OneDrive existed to which the data subject’s personal data had been automatically copied or linked. Instead, it found that the relevant OneDrive was the data subject’s personal OneDrive, assigned to her as an employee under the controller’s corporate Microsoft 365 subscription. The DPA also discovered no indication that the data subject’s colleagues or supervisors had access to her OneDrive desktop folder through permissions in the folder’s security settings. Although the “Everyone” group appeared in the list of users or groups in the security settings, the evidence submitted with the complaint did not show that this group had any defined access rights. Nor did the fact that the data subject had access to a colleague’s file prove that the controller’s access controls were defective, since the evidence indicated that employees could grant each other access to files stored in their respective file storage areas. The DPA further held that Delve view counts could not, on their own, prove that unauthorised third parties had viewed the data subject’s documents. The view count was not broken down by user and could include views by the document owner herself. It could therefore only show that the relevant document had been opened a certain number of times by users who had access to it, not that unauthorised access had occurred. The DPA therefore concluded that it was unproven that the controller had carried out electronic monitoring of the data subject or that unauthorised colleagues had accessed personal data stored in her file storage areas. It also held that the controller had ensured appropriate security of the data subject’s personal data through access controls, in accordance with Article 5(1)(f) GDPR, Article 5(2) GDPR and Article 32(1) GDPR.

### Federazione Italiana Sommelier, Albergatori e Ristoratori: Non-compliance with general data processing principles

*Source: Italian Data Protection Authority (Garante), 2022-06-30 — https://overview.legal/posts/47504 — original: https://www.enforcementtracker.com/ETid-1389*

The Italian DPA has imposed a fine of EUR 5,000 on Federazione Italiana Sommelier, Albergatori e Ristoratori. The federation had sent a protocol containing personal data of a member to all other members. The protocol revealed information about a disciplinary measure against the member concerned, although the measure was not yet legally binding and was later revoked. In addition, the disciplinary measure continued to be published on a cloud platform even after the measure was revoked.

### Umeå University: Insufficient technical and organisational measures to ensure information security

*Source: Data Protection Authority of Sweden (Integritetsskyddsmyndigheten), 2020-12-11 — https://overview.legal/posts/46597 — original: https://www.enforcementtracker.com/ETid-482*

The Swedish DPA (Integritetsskyddsmyndigheten) fined Umeå University SEK 550,000 (EUR 54,000) as a result of its failure to apply appropriate technical and organizational measures to protect data. As part of a research project on male rape, the university had stored several police reports on such related incidents in the cloud of a U.S. service provider. The reports contained the names, ID numbers and contact details of the data subjects, as well as information about their health and sex lives,

## Recent developments

### The operation of the CLOUD Act in data storage in Europe

*Source: NCSC Netherlands, 2022-10-26 — https://overview.legal/posts/6325 — original: https://www.ncsc.nl/documenten/publicaties/2022/augustus/16/cloud-act-memo#entry-1157*

GreenbergTraurig has assessed the scope of the US CLOUD Act on commission by the Dutch government. The CLOUD Act applies to EU entities that process data outside of the US, even if the EU entities are located outside of the US. To completely avoid being subject to the CLOUD Act, an EU entity would need to process data using a non-U.S. entity, which either does not have a corporate relation to any company with a presence in the US (such as a U.S. subsidiary) or if it does have a corporate relatio

### De werking van de CLOUD Act met betrekking tot dataopslag in Europa.

*Source: NCSC Netherlands, 2022-10-26 — https://overview.legal/posts/51789*

GreenbergTraurig heeft op verzoek van de Nederlandse overheid de reikwijdte van de Amerikaanse CLOUD Act beoordeeld. De CLOUD Act is van toepassing op EU-organisaties die data verwerken buiten de Verenigde Staten, zelfs als deze organisaties zich buiten de VS bevinden. Om volledig te voorkomen dat men onder de CLOUD Act valt, zou een EU-organisatie data moeten verwerken via een entiteit die niet in de VS gevestigd is, en die ofwel geen bedrijfsrelatie heeft met een bedrijf dat een vestiging in de VS heeft (zoals een Amerikaanse dochteronderneming), of, indien er wel een bedrijfsrelatie bestaat...

### Support the EDPB’s work as an expert

*Source: EDPB, 2025-11-28 — https://overview.legal/posts/49124 — original: https://www.edpb.europa.eu/news/news/2025/support-edpbs-work-expert_en*

Brussels, 28 November - The EDPB launched a call for expression of interest to establish a new reserve list for the Support Pool of Experts (SPE) programme. The objective is set up a reserve list of legal and technical experts. The legal expertise sought includes a wide range of fields, such as data protection, policy monitoring, technology, cybersecurity, competition, healthcare, online intermediary services and content moderation. As for the technical expertise, the relevant areas include IT a

### Digital Privacy Rights and CLOUD Act Agreements between US and UK

*Source: Brooklyn Law School, 2022-09-26 — https://overview.legal/posts/6272 — original: https://brooklynworks.brooklaw.edu/bjil/vol47/iss1/1/#entry-804*

The CLOUD Act agreements between the US and UK will likely improve the digital privacy rights of US and UK citizens, but they will further undermine these rights for Third Country Persons (eg from EU). The US and UK should voluntarily extend Fourth Amendment and Article 8 protections to these persons, according to an article in the Brooklyn Journal of International Law.

### Support the work of the EDPB as an expert.

*Source: EDPB, 2025-11-28 — https://overview.legal/posts/52059*

Brussels, November 28th - The European Data Protection Board (EDPB) has published a call for expressions of interest for the creation of a new reserve pool for the "Support Pool of Experts" (SPE) program. The objective is to assemble a reserve pool of legal and technical experts. The legal expertise sought covers a wide range of areas, including data protection, policy monitoring, technology, cybersecurity, competition law, healthcare, online intermediary services, and content moderation. Regarding technical expertise, relevant areas include IT.

## Literature

### Challenges of Cloud Data Privacy in Surveillance: Legal, Technical, and Ethical Implications

*Source: IJARCCE, 2026-07-07 — https://overview.legal/posts/83508 — original: https://doi.org/10.17148/ijarcce.2026.15701*

The migration of surveillance systems to cloud infrastructure has improved scalability and analytics capabilities but introduces distinct privacy challenges: jurisdictional conflicts between GDPR and the CLOUD Act, expanded attack surfaces from third-party integrations, mandatory retention that conflicts with data minimization, and function creep enabled by centralized data lakes.Using case law from Schrems II, breach reports from ENISA, and technical evaluations of federated learning and differ

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia

*Source: As-Syar i Jurnal Bimbingan & Konseling Keluarga, 2026-07-04 — https://overview.legal/posts/83517 — original: https://doi.org/10.47467/as.v8i3.12817*

Personal data protection has become an increasingly important legal issue due to the rapid development of digital technology and the growing volume of personal data processing activities. Indonesia has enacted Law Number 27 of 2022 concerning Personal Data Protection (PDP Law) as the primary legal framework for personal data protection. However, several limitations remain within its substantive and institutional aspects, requiring further improvement. This study aims to analyze the substantive a

### General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens?

*Source: Comparative Law Review, 2018-02-09 — https://overview.legal/posts/132416 — original: https://doi.org/10.12775/clr.2017.005*

Comparative Law Review 22 2016 Nicolaus Copernicus University http://dx.doi.org/10.12775/CLR.2016.006 Katarzyna Krupa- Lipińska  THE PROBLEM OF THE INDETERMINATE DEFENDANT IN TORT LAW IN EUROPE Abstract The article discusses the problem of the indeterminate defendant in European tort law systems and in the projects aiming to unify tort law in Europe, such as Draft Common Frame of Reference and Principles of European Tort Law. The given issue relates to a situation where there is a damage caused by one factor, yet upon available evidence one may indicate a few potential factors which might have led to the damage, but it cannot be ascertained which factor was the actual cause of it. The problem is addressed with reference to two scenarios. First, when there is a limited and known number of persons acting tortiously, each of whom potentially might have led to the damage, but only one of them had actually caused it. Second, when it is certain that one tortfeasor from the undetermined group of tortfeasors caused damage to some of the injured persons from the group of the injured persons, but it cannot be established precisely which tortfeasor caused damage to precisely which injured pe

### Dalla guida assistita alle driverless cars: rischio tecnologico e responsabilità civile

*Source: European Journal of Privacy Law & Technologies, 2026-01-01 — https://overview.legal/posts/53847 — original: https://doi.org/10.57230/ejplt261eam*

Lo sviluppo di tecnologie che consentono l’implementazione della guida assistita e automatizzata – foriere di un significativo aumento della sicurezza e della conseguente riduzione degli incidenti – comporta la necessità di testare le nuove tecnologie non solo in ambienti protetti e controllati, ma anche in condizioni reali. Il contributo, analizzando le norme che disciplinano la responsabilità civile anche alla luce dell’AI Act, ricostruisce i possibili scenari che si concretizzeranno nella lun

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers

---
Generated by overview.legal · https://overview.legal/topics/cloud-computing · 2026-08-22
