Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data Offcial Journal L 281 , 23/11/1995 P. 0031 - 0050
link
COM/2012/011 Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)
link
What can be protected in EU?
Fig. 7.2.2/1
(1) 'data subject'
means an identified natural person or a natural person read more who can be identified read more , directly or indirectly read more , by means reasonably likely to be used read more by the controller or by any other natural or legal person, in particular by reference to an identification number, location data, online identifier read more or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;
(2) 'personal data'
means any information relating to a data subject read more ;
majority of data falls into the category of "personal data" as "identiffcation" means (especially indirect) can be unexpectedly effective, especially in a cloud storage
(3) 'processing'
means any operation or set of operations which is performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, erasure or destruction;
Conclusions
Can you try to imagine any cloud service that is not covered by this definition of "processing"?
What to do if your cloud contains data that has been gathered but possibly not legally?
Article 5 Principles relating to personal data processing
Personal data must be:
Article 6 Lawfulness of processing
Article 7 Conditions for consent
Article 11 Transparent information and communication
Article 17 Right to be forgotten and to erasure
Article 26 Processor
Article 30 Security of processing
Article 31 Notiffication of a personal data breach to the supervisory authority
Article 39 Certiffication
Article 40 General principle for transfers
Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organization may only take place if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organization to another third country or to another international organization. read more