Document Type
Article
Abstract
With cloud services emerging as the latest computing technological advancement, privacy looms as a critical component to the successful adoption of this technology. Through a comprehensive analysis of the looming dangers of privacy and security in clouds, this Article attempts to promote core principles and strategic business directions with the goal of fostering a consensus in legislative, regulatory, and international Internet policy. Influenced by the Federal Trade Commission’s Privacy Initiative, this Article advocates for the implementation of core privacy principles into cloud computing services. These core principles include facilitating transparency, empowering individuals to make informed and intelligent choices, strengthening multi-stakeholder governance models, promoting cooperation, and building trust in online environments.
Part I of this Article provides an overview of the historical and technical perspectives of cloud computing, and discusses its benefits. Part II addresses the inherent risks of cloud computing and demonstrates how the stage is set for the perfect storm to erupt if regulatory action does not take place. Part III introduces Carnegie Mellon’s Software Engineering Institutes’ Capability Maturity Model® Integration (CMMISM)3 as a way to project the development of privacy contracting principles within the cloud. This part also introduces five major business sectors to provide specific and distinguishable expectations for each business to evaluate its level of maturity. Finally, this part introduces the Federal Trade Commission (FTC) core privacy principles as a guidepost for future regulatory action across all business industries.
Lastly, Part IV offers “shelter from the storm” by providing potential adopters of cloud services with suggestions to ensure that adequate protective controls are included as a part of their Service Level Agreement (SLA) negotiated with the provider. This Article concludes by making a call to implement the core FTC privacy principles into all “cloud” SLAs. Most of the private cloud sector’s voluntary compliance with privacy regulation has been unsuccessful. Nonetheless, the cloud sector and interested investors should leverage these initial efforts to engage privacy regulation at the beginning of the maturity technological development stages to embrace core privacy principles across the industry and to optimize individual business prosperity.
Recommended Citation
John Soma, Maury Nichols, Melodi Mosley Gates, and Ana Gutiérrez,
Chasing the Clouds Without Getting Drenched: A Call for Fair Practices in Cloud Computing Services,
16 J. Tech. L. & Pol'y
(2011).
Available at: https://scholarship.law.ufl.edu/jtlp/vol16/iss2/1