SlideShare uma empresa Scribd logo
1 de 15
Chicago . Frankfurt . London . Los Angeles . New York . Palo Alto . Shanghai . Washington DC . West Palm Beach




Data Security and Privacy Risks in
Cloud Computing
       William A. Tanenbaum
           Chair, Technology, Intellectual Property & Outsourcing Group, and
           Chair, GreenTech and Sustainability Group
           Kaye Scholer LLP
           New York and Palo Alto Offices
Audience Poll

• Do you have company trade secrets in
  the Cloud?
• Do you have contractual consent to use
  U.S. health and financial personal data?
• Do you have customer data from Europe
  in the Cloud?
• Has a court ordered you to preserve
  litigation documents?
• Will your Cloud provider pay for costs of
  database breaches?


        60350343.PPTX
Data Security vs. Privacy

• To identify and protect against
  your risks, you need to
  distinguish between company
  data and personally identifiable
  information (“PII”)
• Unauthorized access vs.
  impermissible use




60414334.PPTX
Risk No. 1: Regulatory Requirements

• Data security requirements
  imposed by US regulations
   – HIPPA, HITECH, GLB, SOX,
     FTC Act § 5, FERPA,
     Massachusetts, other states
• Raises audit issues
• Also export control
  regulations




60350343.PPTX
Risk No. 2: Practical Data Hazards

• Weak technical access
  protection
• Provider’s employees
• Provider’s subcontractors
• Lack of transparency
• Lack of customer control




60350343.PPTX
Risk No. 3: Litigation Holds
• Can you meet litigation
  document hold requirements
  if your data is in the Cloud?
• Is metadata a legal and
  practical solution?
• Who pays tagging costs?




 60350343.PPTX
Risk No. 4: Can You Use Available Legal
Options Under EEA Law?



• Safe Harbor
• Approved Clauses
• Binding Corporate




       60350343.PPTX
Risk No. 5: Low Price Comes at a Cost
• Generally, Utility Cloud
  providers:
 – Rely on third party platforms
   and software
 – Use one-sided contracts
 – No ability to negotiate stronger
   protections
 – No service levels
 – Disclaim liability
• Conclusion: may not meet
  customer’s legal
  obligations
         60350343.PPTX
Risk No. 6. Do Tier 1 Providers Go Far
Enough?
• Offer Private Clouds, but
  they may still fall short of
  legal obligations
• Offer more location
  specificity, but still may fall
  short
• Pay extra for data security
• At some point, tips into
  custom data center and
  hosting services, and
  becomes more ITO than
  Cloud
60350343.PPTX
Risk No. 7: Is There Sufficient Software
Change Control?
• If Provider changes software or
  version, will your software still
  work?
• Can compromise on advance
  notice?
• Caution: what do online terms
  and conditions allow?




60350343.PPTX
Risk No. 8: Database Breaches

• Who bears cost of:
 – Determining liability and exposure
   under state law?
 – Providing statutory notices?
 – Providing identity protection
   services?
 – Providing call centers and other
   customer-facing remediation?
 – Government investigations?
 – Infrastructure upgrades?



         60350343.PPTX
Questions and Answers


    William A. Tanenbaum
        Chair, Technology, Intellectual
        Property & Outsourcing Group
        Chair, GreenTech and
        Sustainability Group
        Kaye Scholer LLP,
        New York and Palo Alto
        wtanenbaum@kayescholer.com
        212-836-7661




60350343.PPTX
William A. Tanenbaum
 wtanenbaum@kayescholer.com
• William A. Tanenbaum is the international chair of both Kaye Scholer’s Technology, Intellectual
  Property & Outsourcing Group and its GreenTech and Sustainability Group, and works in the
  firm’s New York and Palo Alto offices. Legal Researcher Chambers found that Bill:
• “built one of New York City‟s most outstanding transactional IT practices,”
• is an “internationally recognized intellectual property, technology and outsourcing lawyer,”
• is a “well-respected attorney, with a well-informed approach [who] provides litigation,
  transaction work and strategic counseling on a range of technology and outsourcing-related
  issues,”
• is “efficient, solution-driven and makes excellent judgment calls,”
• is “a leading light” in outsourcing with “household names” in his client roster,
• is “an acknowledged expert on the convergence of mainstream business with cleantech,” and
  that
• “clients highlight his IP experience but „commend his command of the whole deal.‟”
• The Legal 500 publication found that Bill is “an outstanding attorney with a deep knowledge
  and understanding of technology and outsourcing and a deeply principled and trustworthy
  colleague.”

     60350343.PPTX
William A. Tanenbaum (cont’d)
• Bill’s Information Technology Law practice has been recognized for over ten years by Best
  Lawyers and was ranked in the First Tier in New York in the 2010 Best Law Firms Survey
  by U.S. News and World Report. Because of the strength of his Group’s practice, Kaye
  Scholer was named as the “Internet & E-Commerce Law Firm of the Year” by The Lawyers
  World Law Awards 2011. He is a past President of the ITech Law Association and a graduate
  of Brown University (Phi Beta Kappa), Cornell Law School, and the Bob Bondurant School of
  High Performance Driving. Chambers recognized him as a “Leading Individual” and awarded
  him “Recommended” ratings in both “Technology and IT Outsourcing” and “Business Process
  Outsourcing,” and named him as a “Notable Practitioner” at the national level in Outsourcing.
  He was voted one of the World‟s Top 250 IP strategists (IAM client survey) and he was
  selected as one of the country‟s top 25 pre-eminent IT practitioners in the Best of the Best
  USA. He regularly advises clients on strategic intellectual property concerns, privacy, data
  security, data transfer, information life cycle management and competitive intelligence matters,
  in both transactional and litigation contexts. His the founder and co-chair of PLI’s annual legal
  Outsourcing Conference and the founder and chair of PLI’s annual GreenTech Law and
  Business Conference. He is listed in Who‟s Who in America, the International Who‟s Who of
  Business Lawyers, the Guide to the World‟s Leading Litigation Experts and the Guide to the
  World‟s Leading Patent Law Experts. He was the privacy and data protection columnist for the
  New York Law Journal, co-author of a book on privacy law and has been quoted in The
  Economist magazine as an expert on IP law. His articles have been used at Harvard and
  other law schools.

             60350343.PPTX
Chicago . Frankfurt . London . Los Angeles . New York . Palo Alto . Shanghai . Washington DC . West Palm Beach




           Copyright ©2011 by Kaye Scholer LLP. All Rights Reserved. This publication is intended as a general guide only. It does not
           contain a general legal analysis or constitute an opinion of Kaye Scholer LLP or any member of the firm on legal issues described.
           It is recommended that readers not rely on this general guide in structuring individual transactions but that professional advice be
           sought in connection with individual transactions. References herein to “Kaye Scholer LLP & Affiliates,” “Kaye Scholer,” “Kaye
           Scholer LLP,” “the firm” and terms of similar import refer to Kaye Scholer LLP and its affiliates operating in various jurisdictions.

Mais conteúdo relacionado

Mais procurados

Technology, Data and Computation Session @ The World Bank - Law, Justice, and...
Technology, Data and Computation Session @ The World Bank - Law, Justice, and...Technology, Data and Computation Session @ The World Bank - Law, Justice, and...
Technology, Data and Computation Session @ The World Bank - Law, Justice, and...Daniel Katz
 
Legal Tech Ethics
Legal Tech EthicsLegal Tech Ethics
Legal Tech EthicsAaron Vick
 
Overcoming In-house Politics to Implement eDiscovery
Overcoming In-house Politics to Implement eDiscoveryOvercoming In-house Politics to Implement eDiscovery
Overcoming In-house Politics to Implement eDiscoveryJ. David Morris
 
The Sedona Canada Panel on Privacy and E-Discovery
The Sedona Canada Panel on Privacy and E-DiscoveryThe Sedona Canada Panel on Privacy and E-Discovery
The Sedona Canada Panel on Privacy and E-DiscoveryDan Michaluk
 
The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...
The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...
The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...Daniel Katz
 
Managing the Legal Concerns of Cloud Computing
Managing the Legal Concerns of Cloud ComputingManaging the Legal Concerns of Cloud Computing
Managing the Legal Concerns of Cloud ComputingAmy Larrimore
 
Innovation and Emerging Technology
Innovation and Emerging TechnologyInnovation and Emerging Technology
Innovation and Emerging TechnologyRon Dolin
 
Ethics In DW & DM
Ethics In DW & DMEthics In DW & DM
Ethics In DW & DMabethan
 
International/Cross Border Legal Malpractice
International/Cross Border Legal MalpracticeInternational/Cross Border Legal Malpractice
International/Cross Border Legal MalpracticeEthan Burger
 
Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...
Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...
Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...Jason Haislmaier
 
gibbs.timothy.k.06232016.resume
gibbs.timothy.k.06232016.resumegibbs.timothy.k.06232016.resume
gibbs.timothy.k.06232016.resumeTim Gibbs
 
IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...
IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...
IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...J. David Morris
 
HvA Legaltech Lab Opening
HvA Legaltech Lab OpeningHvA Legaltech Lab Opening
HvA Legaltech Lab Openingjcscholtes
 
ACEDS-Driven March 2015 BYOD Webcast
ACEDS-Driven March 2015 BYOD WebcastACEDS-Driven March 2015 BYOD Webcast
ACEDS-Driven March 2015 BYOD WebcastLogikcull.com
 
Understanding Legal Technology Competence with Bob Ambrogi and Joshua Lenon
Understanding Legal Technology Competence with Bob Ambrogi and Joshua LenonUnderstanding Legal Technology Competence with Bob Ambrogi and Joshua Lenon
Understanding Legal Technology Competence with Bob Ambrogi and Joshua LenonClio - Cloud-Based Legal Technology
 
E discovery production and non-party privacy v2
E discovery production and non-party privacy v2E discovery production and non-party privacy v2
E discovery production and non-party privacy v2Dan Michaluk
 
Startup Legal & IP (July2013 Founder Institute)
Startup Legal & IP (July2013 Founder Institute)Startup Legal & IP (July2013 Founder Institute)
Startup Legal & IP (July2013 Founder Institute)Touraj Parang
 
Best Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information SecurityBest Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information Securitysatyakam_biswas
 
Law Scribe Corporate Profile Cs
Law Scribe Corporate Profile CsLaw Scribe Corporate Profile Cs
Law Scribe Corporate Profile Csguestc030a75
 

Mais procurados (20)

Technology, Data and Computation Session @ The World Bank - Law, Justice, and...
Technology, Data and Computation Session @ The World Bank - Law, Justice, and...Technology, Data and Computation Session @ The World Bank - Law, Justice, and...
Technology, Data and Computation Session @ The World Bank - Law, Justice, and...
 
Legal Tech Ethics
Legal Tech EthicsLegal Tech Ethics
Legal Tech Ethics
 
Overcoming In-house Politics to Implement eDiscovery
Overcoming In-house Politics to Implement eDiscoveryOvercoming In-house Politics to Implement eDiscovery
Overcoming In-house Politics to Implement eDiscovery
 
The Sedona Canada Panel on Privacy and E-Discovery
The Sedona Canada Panel on Privacy and E-DiscoveryThe Sedona Canada Panel on Privacy and E-Discovery
The Sedona Canada Panel on Privacy and E-Discovery
 
The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...
The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...
The "MIT School of Law" - Keynote Presentation @Stanford CodeX FutureLaw Conf...
 
Managing the Legal Concerns of Cloud Computing
Managing the Legal Concerns of Cloud ComputingManaging the Legal Concerns of Cloud Computing
Managing the Legal Concerns of Cloud Computing
 
Innovation and Emerging Technology
Innovation and Emerging TechnologyInnovation and Emerging Technology
Innovation and Emerging Technology
 
Ethics In DW & DM
Ethics In DW & DMEthics In DW & DM
Ethics In DW & DM
 
International/Cross Border Legal Malpractice
International/Cross Border Legal MalpracticeInternational/Cross Border Legal Malpractice
International/Cross Border Legal Malpractice
 
Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...
Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...
Data Property Rights (Rocky Mountain IP and Technology Institute 2013) (May 2...
 
gibbs.timothy.k.06232016.resume
gibbs.timothy.k.06232016.resumegibbs.timothy.k.06232016.resume
gibbs.timothy.k.06232016.resume
 
IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...
IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...
IQPC NY Financial Conference on eDiscovery: Legal Speaks Greek and IT Speaks ...
 
HvA Legaltech Lab Opening
HvA Legaltech Lab OpeningHvA Legaltech Lab Opening
HvA Legaltech Lab Opening
 
ACEDS-Driven March 2015 BYOD Webcast
ACEDS-Driven March 2015 BYOD WebcastACEDS-Driven March 2015 BYOD Webcast
ACEDS-Driven March 2015 BYOD Webcast
 
Understanding Legal Technology Competence with Bob Ambrogi and Joshua Lenon
Understanding Legal Technology Competence with Bob Ambrogi and Joshua LenonUnderstanding Legal Technology Competence with Bob Ambrogi and Joshua Lenon
Understanding Legal Technology Competence with Bob Ambrogi and Joshua Lenon
 
E discovery production and non-party privacy v2
E discovery production and non-party privacy v2E discovery production and non-party privacy v2
E discovery production and non-party privacy v2
 
Startup Legal & IP (July2013 Founder Institute)
Startup Legal & IP (July2013 Founder Institute)Startup Legal & IP (July2013 Founder Institute)
Startup Legal & IP (July2013 Founder Institute)
 
Best Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information SecurityBest Practices In Corporate Privacy & Information Security
Best Practices In Corporate Privacy & Information Security
 
#7 Insurance
#7 Insurance#7 Insurance
#7 Insurance
 
Law Scribe Corporate Profile Cs
Law Scribe Corporate Profile CsLaw Scribe Corporate Profile Cs
Law Scribe Corporate Profile Cs
 

Semelhante a Data Security Risks in Cloud Computing

Chief Data Officer Agenda Webinar: How CDOs Should Work with Lawyers
Chief Data Officer Agenda Webinar: How CDOs Should Work with LawyersChief Data Officer Agenda Webinar: How CDOs Should Work with Lawyers
Chief Data Officer Agenda Webinar: How CDOs Should Work with LawyersDATAVERSITY
 
William A. Tanenbaum Association of Benefit Administrators April 2015
William A. Tanenbaum  Association of Benefit Administrators April 2015William A. Tanenbaum  Association of Benefit Administrators April 2015
William A. Tanenbaum Association of Benefit Administrators April 2015William Tanenbaum
 
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the RiskPrivacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the Riskduffeeandeitzen
 
LAC15032_WBINQ_Legal_Tech_Toronto
LAC15032_WBINQ_Legal_Tech_TorontoLAC15032_WBINQ_Legal_Tech_Toronto
LAC15032_WBINQ_Legal_Tech_TorontoPatrick Crummey
 
Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008
Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008
Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008Mark Ross
 
Learning to Thrive as a Tech-Savvy Lawyer by Nehal Madhani
Learning to Thrive as a Tech-Savvy Lawyer by Nehal MadhaniLearning to Thrive as a Tech-Savvy Lawyer by Nehal Madhani
Learning to Thrive as a Tech-Savvy Lawyer by Nehal MadhaniNehal Madhani
 
William A Tanenbaum David with Goliath: How Big Companies Do Business with...
William A Tanenbaum   David with Goliath:  How Big Companies Do Business with...William A Tanenbaum   David with Goliath:  How Big Companies Do Business with...
William A Tanenbaum David with Goliath: How Big Companies Do Business with...William Tanenbaum
 
Trends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the RisksTrends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the RisksNicole Garton
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Diana Maier
 
EKovacevich-IT697-Phase 5 IP
EKovacevich-IT697-Phase 5 IPEKovacevich-IT697-Phase 5 IP
EKovacevich-IT697-Phase 5 IPEDDY KOVACEVICH
 
Cybersecurity: Managing Risk Around New Data Threats
Cybersecurity: Managing Risk Around New Data ThreatsCybersecurity: Managing Risk Around New Data Threats
Cybersecurity: Managing Risk Around New Data ThreatsEthisphere
 
Deconstructing Data Breach Cost
Deconstructing Data Breach CostDeconstructing Data Breach Cost
Deconstructing Data Breach CostResilient Systems
 
David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...
David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...
David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...William Tanenbaum
 
Social Business =Cloud + Big Data + Social Media + Mobile Computing
Social Business =Cloud + Big Data + Social Media + Mobile ComputingSocial Business =Cloud + Big Data + Social Media + Mobile Computing
Social Business =Cloud + Big Data + Social Media + Mobile ComputingWilliam Tanenbaum
 
SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...
SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...
SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...SirionLabs
 
Do You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & Privacy
Do You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & PrivacyDo You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & Privacy
Do You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & PrivacyButlerRubin
 
Open Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companiesiasaglobal
 

Semelhante a Data Security Risks in Cloud Computing (20)

Chief Data Officer Agenda Webinar: How CDOs Should Work with Lawyers
Chief Data Officer Agenda Webinar: How CDOs Should Work with LawyersChief Data Officer Agenda Webinar: How CDOs Should Work with Lawyers
Chief Data Officer Agenda Webinar: How CDOs Should Work with Lawyers
 
William A. Tanenbaum Association of Benefit Administrators April 2015
William A. Tanenbaum  Association of Benefit Administrators April 2015William A. Tanenbaum  Association of Benefit Administrators April 2015
William A. Tanenbaum Association of Benefit Administrators April 2015
 
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the RiskPrivacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
 
LAC15032_WBINQ_Legal_Tech_Toronto
LAC15032_WBINQ_Legal_Tech_TorontoLAC15032_WBINQ_Legal_Tech_Toronto
LAC15032_WBINQ_Legal_Tech_Toronto
 
Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008
Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008
Offshore Legal Outsourcing The Ethical Implications Webinar Sep 9th 2008
 
Learning to Thrive as a Tech-Savvy Lawyer by Nehal Madhani
Learning to Thrive as a Tech-Savvy Lawyer by Nehal MadhaniLearning to Thrive as a Tech-Savvy Lawyer by Nehal Madhani
Learning to Thrive as a Tech-Savvy Lawyer by Nehal Madhani
 
William A Tanenbaum David with Goliath: How Big Companies Do Business with...
William A Tanenbaum   David with Goliath:  How Big Companies Do Business with...William A Tanenbaum   David with Goliath:  How Big Companies Do Business with...
William A Tanenbaum David with Goliath: How Big Companies Do Business with...
 
Trends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the RisksTrends in Law Practice Management – Calculating the Risks
Trends in Law Practice Management – Calculating the Risks
 
Licensing Resources
Licensing ResourcesLicensing Resources
Licensing Resources
 
(Webinar Slides) How to Ethically Use Technology in Your Practice
(Webinar Slides) How to Ethically Use Technology in Your Practice(Webinar Slides) How to Ethically Use Technology in Your Practice
(Webinar Slides) How to Ethically Use Technology in Your Practice
 
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
Privacy Best Practices for Lawyers: What Every Law Practice Needs to Know Abo...
 
EKovacevich-IT697-Phase 5 IP
EKovacevich-IT697-Phase 5 IPEKovacevich-IT697-Phase 5 IP
EKovacevich-IT697-Phase 5 IP
 
Cybersecurity: Managing Risk Around New Data Threats
Cybersecurity: Managing Risk Around New Data ThreatsCybersecurity: Managing Risk Around New Data Threats
Cybersecurity: Managing Risk Around New Data Threats
 
Deconstructing Data Breach Cost
Deconstructing Data Breach CostDeconstructing Data Breach Cost
Deconstructing Data Breach Cost
 
Co3 rsc r5
Co3 rsc r5Co3 rsc r5
Co3 rsc r5
 
David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...
David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...
David WITH Goliath: How Big Companies Do Deals with Small Cloud and Social Me...
 
Social Business =Cloud + Big Data + Social Media + Mobile Computing
Social Business =Cloud + Big Data + Social Media + Mobile ComputingSocial Business =Cloud + Big Data + Social Media + Mobile Computing
Social Business =Cloud + Big Data + Social Media + Mobile Computing
 
SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...
SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...
SirionLabs Webinar Featuring Forrester - Plugging Value Leakage in IT Outsour...
 
Do You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & Privacy
Do You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & PrivacyDo You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & Privacy
Do You Wannacry: Your Ethical and Legal Duties Regarding Cybersecurity & Privacy
 
Open Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated CompaniesOpen Source Governance in Highly Regulated Companies
Open Source Governance in Highly Regulated Companies
 

Mais de William Tanenbaum

Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios:  It's All Contextual Date Use Rules in Different Business Scenarios:  It's All Contextual
Date Use Rules in Different Business Scenarios: It's All Contextual William Tanenbaum
 
William Tanenbaum Data Use Rules in Different Business Scenarios: It's All C...
William Tanenbaum Data Use Rules in Different Business Scenarios:  It's All C...William Tanenbaum Data Use Rules in Different Business Scenarios:  It's All C...
William Tanenbaum Data Use Rules in Different Business Scenarios: It's All C...William Tanenbaum
 
Wm Tanenbaum Data Business Cases
Wm Tanenbaum Data Business CasesWm Tanenbaum Data Business Cases
Wm Tanenbaum Data Business CasesWilliam Tanenbaum
 
IP Licensing in Outsourcing and Tech Agreements
IP Licensing in Outsourcing and Tech AgreementsIP Licensing in Outsourcing and Tech Agreements
IP Licensing in Outsourcing and Tech AgreementsWilliam Tanenbaum
 
Date Use Rules in Different Business Scenarios:It's All Contextual
Date Use Rules in Different Business Scenarios:It's All Contextual Date Use Rules in Different Business Scenarios:It's All Contextual
Date Use Rules in Different Business Scenarios:It's All Contextual William Tanenbaum
 
Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios:  It's All Contextual Date Use Rules in Different Business Scenarios:  It's All Contextual
Date Use Rules in Different Business Scenarios: It's All Contextual William Tanenbaum
 
Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios: It's All ContextualDate Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios: It's All ContextualWilliam Tanenbaum
 
Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios:  It's All Contextual Date Use Rules in Different Business Scenarios:  It's All Contextual
Date Use Rules in Different Business Scenarios: It's All Contextual William Tanenbaum
 
Data Use Rules in Different Business Scenarios: It's All Contextual
Data Use Rules in Different Business Scenarios:  It's All Contextual Data Use Rules in Different Business Scenarios:  It's All Contextual
Data Use Rules in Different Business Scenarios: It's All Contextual William Tanenbaum
 
Date Use Rules in Different Business Scenarios: It's All Contectual it is all...
Date Use Rules in Different Business Scenarios: It's All Contectual it is all...Date Use Rules in Different Business Scenarios: It's All Contectual it is all...
Date Use Rules in Different Business Scenarios: It's All Contectual it is all...William Tanenbaum
 
Next Generation Outsourcing: Revenue vs. Cost Reduction
Next Generation Outsourcing:  Revenue vs. Cost Reduction Next Generation Outsourcing:  Revenue vs. Cost Reduction
Next Generation Outsourcing: Revenue vs. Cost Reduction William Tanenbaum
 
Next Generation Outsourcing: Revenue vs. Cost
Next Generation Outsourcing:  Revenue vs. Cost Next Generation Outsourcing:  Revenue vs. Cost
Next Generation Outsourcing: Revenue vs. Cost William Tanenbaum
 
IP Outsourcing Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...
IP Outsourcing  Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...IP Outsourcing  Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...
IP Outsourcing Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...William Tanenbaum
 
How To Avoid Procuring Ip When Doing Procurement
How To Avoid Procuring Ip When Doing ProcurementHow To Avoid Procuring Ip When Doing Procurement
How To Avoid Procuring Ip When Doing ProcurementWilliam Tanenbaum
 
Convergence Of Mainstream Business Big Data And Clean Tech William A Tanenbaum
Convergence Of Mainstream Business Big Data And Clean Tech William A TanenbaumConvergence Of Mainstream Business Big Data And Clean Tech William A Tanenbaum
Convergence Of Mainstream Business Big Data And Clean Tech William A TanenbaumWilliam Tanenbaum
 
The IT and IP Revolution Hidden In Retrofits and Green Buildings
The IT and IP Revolution Hidden In Retrofits and Green BuildingsThe IT and IP Revolution Hidden In Retrofits and Green Buildings
The IT and IP Revolution Hidden In Retrofits and Green BuildingsWilliam Tanenbaum
 
W Tanenbaum Making The Supply Chain Sustainable 0210
W Tanenbaum Making The Supply Chain Sustainable 0210W Tanenbaum Making The Supply Chain Sustainable 0210
W Tanenbaum Making The Supply Chain Sustainable 0210William Tanenbaum
 
Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...
Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...
Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...William Tanenbaum
 

Mais de William Tanenbaum (18)

Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios:  It's All Contextual Date Use Rules in Different Business Scenarios:  It's All Contextual
Date Use Rules in Different Business Scenarios: It's All Contextual
 
William Tanenbaum Data Use Rules in Different Business Scenarios: It's All C...
William Tanenbaum Data Use Rules in Different Business Scenarios:  It's All C...William Tanenbaum Data Use Rules in Different Business Scenarios:  It's All C...
William Tanenbaum Data Use Rules in Different Business Scenarios: It's All C...
 
Wm Tanenbaum Data Business Cases
Wm Tanenbaum Data Business CasesWm Tanenbaum Data Business Cases
Wm Tanenbaum Data Business Cases
 
IP Licensing in Outsourcing and Tech Agreements
IP Licensing in Outsourcing and Tech AgreementsIP Licensing in Outsourcing and Tech Agreements
IP Licensing in Outsourcing and Tech Agreements
 
Date Use Rules in Different Business Scenarios:It's All Contextual
Date Use Rules in Different Business Scenarios:It's All Contextual Date Use Rules in Different Business Scenarios:It's All Contextual
Date Use Rules in Different Business Scenarios:It's All Contextual
 
Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios:  It's All Contextual Date Use Rules in Different Business Scenarios:  It's All Contextual
Date Use Rules in Different Business Scenarios: It's All Contextual
 
Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios: It's All ContextualDate Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios: It's All Contextual
 
Date Use Rules in Different Business Scenarios: It's All Contextual
Date Use Rules in Different Business Scenarios:  It's All Contextual Date Use Rules in Different Business Scenarios:  It's All Contextual
Date Use Rules in Different Business Scenarios: It's All Contextual
 
Data Use Rules in Different Business Scenarios: It's All Contextual
Data Use Rules in Different Business Scenarios:  It's All Contextual Data Use Rules in Different Business Scenarios:  It's All Contextual
Data Use Rules in Different Business Scenarios: It's All Contextual
 
Date Use Rules in Different Business Scenarios: It's All Contectual it is all...
Date Use Rules in Different Business Scenarios: It's All Contectual it is all...Date Use Rules in Different Business Scenarios: It's All Contectual it is all...
Date Use Rules in Different Business Scenarios: It's All Contectual it is all...
 
Next Generation Outsourcing: Revenue vs. Cost Reduction
Next Generation Outsourcing:  Revenue vs. Cost Reduction Next Generation Outsourcing:  Revenue vs. Cost Reduction
Next Generation Outsourcing: Revenue vs. Cost Reduction
 
Next Generation Outsourcing: Revenue vs. Cost
Next Generation Outsourcing:  Revenue vs. Cost Next Generation Outsourcing:  Revenue vs. Cost
Next Generation Outsourcing: Revenue vs. Cost
 
IP Outsourcing Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...
IP Outsourcing  Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...IP Outsourcing  Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...
IP Outsourcing Problems... Tanenbaum, wtanenbaum@kayescholer.com Kaye Schole...
 
How To Avoid Procuring Ip When Doing Procurement
How To Avoid Procuring Ip When Doing ProcurementHow To Avoid Procuring Ip When Doing Procurement
How To Avoid Procuring Ip When Doing Procurement
 
Convergence Of Mainstream Business Big Data And Clean Tech William A Tanenbaum
Convergence Of Mainstream Business Big Data And Clean Tech William A TanenbaumConvergence Of Mainstream Business Big Data And Clean Tech William A Tanenbaum
Convergence Of Mainstream Business Big Data And Clean Tech William A Tanenbaum
 
The IT and IP Revolution Hidden In Retrofits and Green Buildings
The IT and IP Revolution Hidden In Retrofits and Green BuildingsThe IT and IP Revolution Hidden In Retrofits and Green Buildings
The IT and IP Revolution Hidden In Retrofits and Green Buildings
 
W Tanenbaum Making The Supply Chain Sustainable 0210
W Tanenbaum Making The Supply Chain Sustainable 0210W Tanenbaum Making The Supply Chain Sustainable 0210
W Tanenbaum Making The Supply Chain Sustainable 0210
 
Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...
Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...
Green Outsourcing, Energy Efficient Data Centers and Sustainable Supply Chain...
 

Data Security Risks in Cloud Computing

  • 1. Chicago . Frankfurt . London . Los Angeles . New York . Palo Alto . Shanghai . Washington DC . West Palm Beach Data Security and Privacy Risks in Cloud Computing William A. Tanenbaum Chair, Technology, Intellectual Property & Outsourcing Group, and Chair, GreenTech and Sustainability Group Kaye Scholer LLP New York and Palo Alto Offices
  • 2. Audience Poll • Do you have company trade secrets in the Cloud? • Do you have contractual consent to use U.S. health and financial personal data? • Do you have customer data from Europe in the Cloud? • Has a court ordered you to preserve litigation documents? • Will your Cloud provider pay for costs of database breaches? 60350343.PPTX
  • 3. Data Security vs. Privacy • To identify and protect against your risks, you need to distinguish between company data and personally identifiable information (“PII”) • Unauthorized access vs. impermissible use 60414334.PPTX
  • 4. Risk No. 1: Regulatory Requirements • Data security requirements imposed by US regulations – HIPPA, HITECH, GLB, SOX, FTC Act § 5, FERPA, Massachusetts, other states • Raises audit issues • Also export control regulations 60350343.PPTX
  • 5. Risk No. 2: Practical Data Hazards • Weak technical access protection • Provider’s employees • Provider’s subcontractors • Lack of transparency • Lack of customer control 60350343.PPTX
  • 6. Risk No. 3: Litigation Holds • Can you meet litigation document hold requirements if your data is in the Cloud? • Is metadata a legal and practical solution? • Who pays tagging costs? 60350343.PPTX
  • 7. Risk No. 4: Can You Use Available Legal Options Under EEA Law? • Safe Harbor • Approved Clauses • Binding Corporate 60350343.PPTX
  • 8. Risk No. 5: Low Price Comes at a Cost • Generally, Utility Cloud providers: – Rely on third party platforms and software – Use one-sided contracts – No ability to negotiate stronger protections – No service levels – Disclaim liability • Conclusion: may not meet customer’s legal obligations 60350343.PPTX
  • 9. Risk No. 6. Do Tier 1 Providers Go Far Enough? • Offer Private Clouds, but they may still fall short of legal obligations • Offer more location specificity, but still may fall short • Pay extra for data security • At some point, tips into custom data center and hosting services, and becomes more ITO than Cloud 60350343.PPTX
  • 10. Risk No. 7: Is There Sufficient Software Change Control? • If Provider changes software or version, will your software still work? • Can compromise on advance notice? • Caution: what do online terms and conditions allow? 60350343.PPTX
  • 11. Risk No. 8: Database Breaches • Who bears cost of: – Determining liability and exposure under state law? – Providing statutory notices? – Providing identity protection services? – Providing call centers and other customer-facing remediation? – Government investigations? – Infrastructure upgrades? 60350343.PPTX
  • 12. Questions and Answers William A. Tanenbaum Chair, Technology, Intellectual Property & Outsourcing Group Chair, GreenTech and Sustainability Group Kaye Scholer LLP, New York and Palo Alto wtanenbaum@kayescholer.com 212-836-7661 60350343.PPTX
  • 13. William A. Tanenbaum wtanenbaum@kayescholer.com • William A. Tanenbaum is the international chair of both Kaye Scholer’s Technology, Intellectual Property & Outsourcing Group and its GreenTech and Sustainability Group, and works in the firm’s New York and Palo Alto offices. Legal Researcher Chambers found that Bill: • “built one of New York City‟s most outstanding transactional IT practices,” • is an “internationally recognized intellectual property, technology and outsourcing lawyer,” • is a “well-respected attorney, with a well-informed approach [who] provides litigation, transaction work and strategic counseling on a range of technology and outsourcing-related issues,” • is “efficient, solution-driven and makes excellent judgment calls,” • is “a leading light” in outsourcing with “household names” in his client roster, • is “an acknowledged expert on the convergence of mainstream business with cleantech,” and that • “clients highlight his IP experience but „commend his command of the whole deal.‟” • The Legal 500 publication found that Bill is “an outstanding attorney with a deep knowledge and understanding of technology and outsourcing and a deeply principled and trustworthy colleague.” 60350343.PPTX
  • 14. William A. Tanenbaum (cont’d) • Bill’s Information Technology Law practice has been recognized for over ten years by Best Lawyers and was ranked in the First Tier in New York in the 2010 Best Law Firms Survey by U.S. News and World Report. Because of the strength of his Group’s practice, Kaye Scholer was named as the “Internet & E-Commerce Law Firm of the Year” by The Lawyers World Law Awards 2011. He is a past President of the ITech Law Association and a graduate of Brown University (Phi Beta Kappa), Cornell Law School, and the Bob Bondurant School of High Performance Driving. Chambers recognized him as a “Leading Individual” and awarded him “Recommended” ratings in both “Technology and IT Outsourcing” and “Business Process Outsourcing,” and named him as a “Notable Practitioner” at the national level in Outsourcing. He was voted one of the World‟s Top 250 IP strategists (IAM client survey) and he was selected as one of the country‟s top 25 pre-eminent IT practitioners in the Best of the Best USA. He regularly advises clients on strategic intellectual property concerns, privacy, data security, data transfer, information life cycle management and competitive intelligence matters, in both transactional and litigation contexts. His the founder and co-chair of PLI’s annual legal Outsourcing Conference and the founder and chair of PLI’s annual GreenTech Law and Business Conference. He is listed in Who‟s Who in America, the International Who‟s Who of Business Lawyers, the Guide to the World‟s Leading Litigation Experts and the Guide to the World‟s Leading Patent Law Experts. He was the privacy and data protection columnist for the New York Law Journal, co-author of a book on privacy law and has been quoted in The Economist magazine as an expert on IP law. His articles have been used at Harvard and other law schools. 60350343.PPTX
  • 15. Chicago . Frankfurt . London . Los Angeles . New York . Palo Alto . Shanghai . Washington DC . West Palm Beach Copyright ©2011 by Kaye Scholer LLP. All Rights Reserved. This publication is intended as a general guide only. It does not contain a general legal analysis or constitute an opinion of Kaye Scholer LLP or any member of the firm on legal issues described. It is recommended that readers not rely on this general guide in structuring individual transactions but that professional advice be sought in connection with individual transactions. References herein to “Kaye Scholer LLP & Affiliates,” “Kaye Scholer,” “Kaye Scholer LLP,” “the firm” and terms of similar import refer to Kaye Scholer LLP and its affiliates operating in various jurisdictions.