UK ICO Publishes Cloud Computing Guidance
Time 4 Minute Read

On September 27, 2012, the UK Information Commissioner’s Office (“ICO”) published guidance on complying with the requirements of the UK Data Protection Act 1998 (“DPA”) in the context of cloud computing services (the “Guidance”). In its Guidance, the ICO reminds data controllers that transferring personal data to the cloud does not absolve them of their compliance obligations under the DPA.

The Guidance provides specific examples that illustrate which party in a cloud computing services scenario will operate as the data controller. In layered service models, where multiple providers offer different services, there may be multiple data controllers. However, as a general rule, it is the cloud customer who determines the purposes for and the manner in which personal data are processed. The cloud customer is therefore deemed to be the data controller, with the overall responsibility for complying with the DPA. In its Guidance, the ICO recognizes that, although customers of large cloud providers may be required to accept the provider’s standard contractual terms and may have little leverage to negotiate those terms, the customer is responsible nonetheless as controller for complying with the DPA. A cloud provider generally will operate as a data processor, but if the cloud provider uses the personal data for its own purposes, it also will be required to comply with the provisions of the DPA.

The Guidance prompts data controllers intending to use cloud services to consider whether such use could result in the processing of additional data, e.g., usage statistics and transaction history metadata, which also may constitute personal data.

The Guidance specifically advises data controllers intending to use cloud services to:

  • create a clear record of the categories of data to be moved to the cloud;
  • select the appropriate cloud provider, particularly a provider that guarantees confidentiality and integrity of the data; and
  • be wary of cloud providers offering “take it or leave it” terms without the possibility of negotiation.

With respect to assessing a potential provider’s security safeguards, the Guidance notes that the most effective method of assessment is conducting an onsite inspection, but recognizes that this may not be practicable.

The Guidance also states that the customer and provider should have in place a clear policy specifying the circumstances in which the provider may access the personal data it processes. In addition, the cloud provider should be contractually restricted from processing personal data for its own purposes.

According to the Guidance, cloud providers should:

  • keep cloud customers informed of changes in the chain of sub-processors;
  • provide assurance that data in transit are appropriately secured;
  • have the ability to delete all copies of personal data (including from underlying storage media) within the timeframe specified in the customer’s deletion schedule;
  • provide a list of countries where data are likely to be processed and a description of the security safeguards in place in those jurisdictions; and
  • provide the location of each sub-processor and the details of the security safeguards in place.

Of longstanding concern to data controllers using service providers located in foreign jurisdictions is the tension between EU data protection rules on the one hand, and foreign law civil disclosure rules and access requests by foreign law enforcement agencies on the other. The Guidance states that generally, neither the cloud customer nor cloud provider would be subject to regulatory enforcement for disclosures to foreign law enforcement agencies, because it would not be appropriate to punish a customer whose provider was legally required to make the disclosure. Although UK organizations may take comfort in the fact that the Guidance indicates that regulatory action would be unlikely in these situations, cloud providers will have a difficult time pointing to an actual legal basis under UK law for making such a disclosure. Further, such disclosures may constitute a breach of contract.

The Guidance supplements the ICO’s more general Guide to Data Protection and its Personal information Online Code of Practice.

You May Also Be Interested In

Time 2 Minute Read

On March 25, 2026, the UK Information Commissioner’s Office and the UK Office of Communications released a joint statement addressing the intersection of online safety and data protection in relation to age assurance.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 3 Minute Read

On February 27, 2026, the UK ICO announced a public consultation on proposed updates to its guidance concerning research, archiving and statistics to reflect the changes introduced by the Data (Use and Access) Act 2025.

Time 2 Minute Read

On February 24, 2026, the UK ICO announced that it had fined Reddit, Inc. £14.47 million following an investigation into the company’s handling of children’s personal information.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page