{"id":36453,"date":"2022-02-28T13:23:25","date_gmt":"2022-02-28T13:23:25","guid":{"rendered":"https:\/\/www.vmengine.net\/2022\/02\/28\/data-protection-europe-approves-code-of-conduct-on-cloud-services\/"},"modified":"2025-05-23T17:32:58","modified_gmt":"2025-05-23T17:32:58","slug":"data-protection-europe-approves-code-of-conduct-on-cloud-services","status":"publish","type":"post","link":"http:\/\/temp_new.vmenginelab.com\/en\/2022\/02\/28\/data-protection-europe-approves-code-of-conduct-on-cloud-services\/","title":{"rendered":"Data Protection, Europe approves Code of Conduct on Cloud Services"},"content":{"rendered":"<div class=\"et_pb_section et_pb_section_393 et_section_regular\" >\n<div class=\"et_pb_row et_pb_row_491\">\n<div class=\"et_pb_column et_pb_column_4_4 et_pb_column_497  et_pb_css_mix_blend_mode_passthrough et-last-child\">\n<div class=\"et_pb_module et_pb_text et_pb_text_1772  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>The CISPE Code of Conduct is the first industry-specific European code for cloud infrastructure service providers (under Article 40 of the European Union&#8217;s GDPR) that receives the green light from <strong><a href=\"https:\/\/edpb.europa.eu\/edpb_it\">the European Data Protection Board (EDPB).<\/a><\/p>\n<p><\/strong><\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1773  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>On 3 February 2022, <strong>CISPE,<\/strong> the voice of <strong>Cloud Infrastructure Service Providers<\/strong> in Europe, announced that companies such as <a href=\"https:\/\/www.aruba.it\/home.aspx\"><br \/>\n  <strong>Aruba<\/strong><br \/>\n<\/a>, <a href=\"https:\/\/aws.amazon.com\/it\/?nc2=h_lg\"><br \/>\n  <strong>Amazon Web Services<\/strong><br \/>\n<\/a>, <strong><br \/>\n  <a href=\"https:\/\/www.elogic.it\/it-it\/homepage\">Elogic<\/a><br \/>\n<\/strong>,<strong> <a href=\"https:\/\/www.leaseweb.com\/\">Leaseweb<\/a><\/strong>, <strong><a href=\"https:\/\/en.outscale.com\/\">Outscale<\/a> <\/strong>and<a href=\"https:\/\/www.ovhcloud.com\/it\/\"><strong> OVHCloud<\/strong> <\/a>are the first members to declare that their services comply with their <strong>Data Protection Code of Conduct<\/strong> . The CISPE Code of Conduct is the <strong>first General Data Protection Regulation<\/strong> (GDPR) code of conduct specifically designed for<strong> Cloud Infrastructure Service<\/strong> Providers.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_cta_407 et_pb_promo  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_promo_description et_multi_view_hidden\"><\/div>\n<div class=\"et_pb_button_wrapper\"><a class=\"et_pb_button et_pb_promo_button\" href=\"https:\/\/temp_new.vmenginelab.com\/2021\/09\/21\/protezione-e-controllo-dei-dati-limpegno-di-aws-verso-i-clienti-europei\/\" target=\"_blank\">Data Protection and Control, AWS&amp;apos; Commitment to European Customers<\/a><\/div>\n<\/p><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1774  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<h2><\/h2>\n<p>Automated Compliance &amp; Partnership with GAIA-X<\/p>\n<h2><\/h2>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_image et_pb_image_468 et_animated et-waypoint\">\n<p>\t\t\t\t<span class=\"et_pb_image_wrap \"><img decoding=\"async\" src=\"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/security-data-2.jpg\" alt=\"\" title=\"Data Security system Shield Protection Verification\"  sizes=\"(max-width: 740px) 100vw, 740px\" class=\"wp-image-34674\" \/><\/span>\n\t\t\t<\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1775  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>All declared services must be verified by one of the three independent monitoring bodies accredited by <a href=\"https:\/\/www.cnil.fr\/\"><br \/>\n  <strong>the CNIL:<\/strong><br \/>\n<\/a> <a href=\"https:\/\/www.bureauveritas.it\/\"><br \/>\n  <strong>Bureau Veritas<\/strong><br \/>\n<\/a>, <a href=\"https:\/\/www.lne.fr\/fr\"><br \/>\n  <strong>LNE<\/strong><br \/>\n<\/a> and <strong><br \/>\n  <a href=\"https:\/\/www.ey.com\/en_gl\/consulting\/certify-point\">EY CertifyPoint<\/a><br \/>\n<\/strong>. Controlled adherence by independent monitoring bodies provides cloud infrastructure customers with an additional layer of assurance when developing GDPR-compliant services in the cloud.<br \/>As a compliance tool validated by data protection authorities, the CISPE Code will be able to provide an additional guarantee of the compliance of Cloud services with European legislation.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1776  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>The CISPE Code is the first tool approved by the EDPB to go beyond the requirements of the GDPR by certifying services to <strong>ensure the non-reuse of customer data<\/strong> and to provide customers with the choice to use the services to store and process customer data exclusively in the <a href=\"https:\/\/www.europarl.europa.eu\/factsheets\/it\/sheet\/169\/lo-spazio-economico-europeo-see-la-svizzera-e-il-nord#:~:text=Lo%20Spazio%20economico%20europeo%20(SEE)%20%C3%A8%20stato%20istituito%20nel%201994,di%20libero%20scambio%20(EFTA).\"><strong>European Economic Area (EEA).<\/strong><\/p>\n<p><\/a><\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1777  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>A key goal of the GAIA-X project is to provide automated <strong>compliance<\/strong> to digitally create transparency and trust. Together with GAIA-X, CISPE has used its Data Protection Code of Conduct to issue <strong>verifiable credentials<\/strong> according to the W3C standard.<br \/>These allow GAIA-X to automatically verify claims of compliance with <strong>data protection and data localization<\/strong> provisions.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_cta_408 et_pb_promo  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_promo_description et_multi_view_hidden\"><\/div>\n<div class=\"et_pb_button_wrapper\"><a class=\"et_pb_button et_pb_promo_button\" href=\"https:\/\/temp_new.vmenginelab.com\/2021\/05\/27\/conformita-aws-il-futuro-delle-regolamentazioni\/\" target=\"_blank\">Find out more about the GAIA-X project<\/a><\/div>\n<\/p><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1778  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<h2>  The benefits of the Code of Conduct  <\/p>\n<h2><\/h2>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_image et_pb_image_469 et_animated et-waypoint\">\n<p>\t\t\t\t<span class=\"et_pb_image_wrap \"><img decoding=\"async\" src=\"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/cybersecuroty-2.jpg\" alt=\"\" title=\"Firewall popup for security cybercrime protection\"  sizes=\"(max-width: 740px) 100vw, 740px\" class=\"wp-image-34680\" \/><\/span>\n\t\t\t<\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1779  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p><strong>SECURITY.<\/strong> Many European businesses want to maintain better control over their data by ensuring that it stays within the <strong>European Union<\/strong>. The CISPE Code of Conduct provides IaaS customers with explicit options to select services that allow data processing entirely within the European Economic Area. As such, it also promotes data protection best practices that support the <strong>EU&#8217;s GAIA-X<\/strong> initiative for the development of <strong>European federated cloud<\/strong> data services.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1780  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p><strong>COMPLIANCE.<\/strong> Compliance with the CISPE Code of Conduct is verified by independent external auditors accredited as &#8220;Supervisory Bodies&#8221; by <strong><br \/>\n  <a href=\"https:\/\/edpb.europa.eu\/about-edpb\/about-edpb\/who-we-are_it#:~:text=L'EDPB%20%C3%A8%20un%20organismo,tra%20le%20autorit%C3%A0%20di%20controllo.\">the competent European Data Protection Authority<\/a><br \/>\n<\/strong>. The independent &#8220;Supervisory Bodies&#8221; strengthen the level of guarantee provided by the services declared under the Code.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1781  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p><strong>FOCUS.<\/strong> It is the first and only code to focus exclusively on the <strong>Infrastructure-as-a-Service<\/strong> (<strong>IaaS<\/strong>) industry and address roles and responsibilities specific to IaaS providers, which cannot be represented in general, multi-purpose code. The CISPE Code of Conduct creates trust for end users that a declared IaaS service is GDPR compliant. The stated service providers will only access or use customer data to maintain or provide the service and will not use customer data for marketing or advertising purposes.<\/p>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>About three years after the GDPR came into force, the European Data Protection Board (EDPB) formalizes the first code of conduct on Cloud services.<\/p>\n","protected":false},"author":3,"featured_media":34673,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[97,3574,2297],"tags":[132,100,4285,4836,1270],"class_list":["post-36453","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","category-in-evidence","category-news-en","tag-amazon-web-services-en","tag-aws-cloud-security-en","tag-cybersecurity-en","tag-data-protection-en","tag-security-en"],"aioseo_notices":[],"jetpack_featured_media_url":"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/data-protection-1.jpg","amp_enabled":true,"_links":{"self":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/comments?post=36453"}],"version-history":[{"count":1,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36453\/revisions"}],"predecessor-version":[{"id":41697,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36453\/revisions\/41697"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/media\/34673"}],"wp:attachment":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/media?parent=36453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/categories?post=36453"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/tags?post=36453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}