Statement of Guidance
Cloud Computing
Status not confirmedView on ODPA's website Source document
Summary
This is general guidance from the Office of the Data Protection Authority (Guernsey) explaining what cloud-based services are and what practical steps individuals and organisations should consider when storing or sharing personal data in the cloud. It is part of a wider suite of guidance on engaging processors and does not itself impose new legal duties beyond existing data protection law.
- Access controls: Think carefully about whether files are set to private, public or shared, and who can view them.
- Passwords and authentication: Use unique, strong passwords for each service and enable two factor authentication where offered.
- Provider terms and privacy notices: Check the cloud provider's terms and conditions and privacy notice for clarity on how personal information is secured and used.
- Encryption in transit and at rest: Understand what encryption the provider offers, including whether data is encrypted in transit (e.g. via HTTPS) and how encryption keys are managed.
- Encrypting before upload: Consider encrypting files before uploading them to the cloud for greater control, while noting this can complicate sharing and key management.
The guidance is aimed at anyone using cloud storage or computing services for activities involving personal data, including individuals and organisations acting as data controllers who engage third-party cloud providers as processors.
Applies to
organisations and individuals using cloud-based services to process personal data, data controllers engaging cloud service providers as processors