German DPAs Issue Resolution and Guidance Paper on Cloud Computing and Compliance with Data Protection Law
Time 3 Minute Read

On September 29, 2011, the German federal and state data protection authorities (“DPAs”) issued a resolution on cloud computing and compliance with data protection law. The publication was released in conjunction with the DPAs’ 82nd annual conference.

In the resolution, the DPAs ask that cloud service providers ensure their services comply with data protection law, and cloud service customers are urged to use cloud services only if they are in a position to fulfill their obligations as data controllers and have verified that the appropriate data protection and information security requirements are in place. The DPAs state that, in addition to ensuring the confidentiality, integrity and availability of data, data controllers must take into account the difficult-to-implement requirements concerning control, transparency and influence over data processing. According to the DPAs, deploying cloud computing solutions should not relieve data controllers, particularly management, of their responsibilities with respect to their data processing operations.

The DPAs’ minimum requirements outlined in the resolution include the following:

  • Open, transparent and detailed information about the cloud service provider’s technical, organizational and legal framework requirements regarding the services they offer, including information regarding data security concepts, so that cloud service customers can evaluate whether or not they should use cloud computing services, and also have sufficient information to choose between various cloud service providers
  • Transparent, detailed and unambiguous contractual provisions regarding the processing of data in the cloud, in particular regarding the location of data processing and notification about possible changes to the locations where cloud data may be processed
  • Implementation of the agreed upon data security and data protection measures by both cloud service providers and cloud service customers
  • Current and meaningful information (for instance certificates issued by recognized, independent auditors) about the information security, portability and interoperability infrastructure to be used in the performance of the contract

In addition, the DPA working groups for technology and media have released a guidance paper on cloud computing that provides more detail on data protection compliance. The 26-page guidance paper was developed by six state DPAs and covers the following topics:

  • Definitions for types of clouds and cloud services such as IaaS, PaaS and SaaS
  • Data controller responsibilities
  • Control of the cloud service providers
  • Rights of data subjects
  • Requirements for international data transfers within and outside Europe, including statements on the use of EU standard contractual clauses and Safe Harbor
  • Technical and organizational aspects
  • Objectives and risks, including general and cloud-specific risk related to certain types of cloud services

You May Also Be Interested In

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 3 Minute Read

Indiana’s comprehensive consumer privacy law, the Indiana Consumer Data Protection Act, is set to take effect on January 1, 2026. In advance of the law’s effective date, the Indiana Attorney General’s Office has published a Consumer Bill of Rights that provides guidance to both consumers and businesses.

Time 2 Minute Read

On November 17, 2025, the Council of the European Union adopted new rules designed to strengthen cooperation among national data protection authorities, enhancing the enforcement of the EU General Data Protection Regulation.

Time 1 Minute Read

On October 14, 2025, the European Data Protection Board announced that its fifth coordinated enforcement action will focus on compliance with the transparency and information requirements under the GDPR.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page