{"id":8314,"date":"2021-10-29T15:54:20","date_gmt":"2021-10-29T15:54:20","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3015\/"},"modified":"2026-05-11T00:19:03","modified_gmt":"2026-05-11T00:19:03","slug":"alice-in-cloud-land","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2021\/10\/29\/alice-in-cloud-land\/","title":{"rendered":"Alice in the Cloud-Land"},"content":{"rendered":"<p><strong>The cloud tempts with its simplicity, effortless implementation, and maximum scalability. Providers also tout the opportunity to reduce IT investment costs &#8211; freeing up capital to flow into core business value creation. But caution is warranted!<\/strong><\/p>\n<p>It\u2019s all too easy to violate data subjects\u2019 rights under the GDPR &#8211; and find yourself facing the Red Queen herself, literally serving you with legal process. Like Alice in Wonderland, cloud users may find personal data protection just as magical &#8211; and at times, equally obscure &#8211; as that fantastical tale.<\/p>\n<h2>The Stolen Cakes<\/h2>\n<p>For data subjects, personal data is often just as valuable as the stolen cakes are to the Red Queen. So how can such data go missing &#8211; especially when cloud providers proudly advertise exemplary compliance and strict adherence to the GDPR? The scientific service of the German Bundestag spells out this dilemma with striking clarity in its briefing paper \u201c<a href=\"https:\/\/www.bundestag.de\/resource\/blob\/852984\/692120a134f9e79999c6f4170a47859a\/WD-3-102-21-pdf-data.pdf\">GDPR and the Use of U.S. Cloud Services<\/a>\u201d<\/p>\n<div id=\"attachment_3016\" style=\"width: 260px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3016\" class=\"wp-image-3016 size-medium\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_134319674-250x167.jpg\" alt=\"\" width=\"250\" height=\"167\" srcset=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_134319674-250x167.jpg 250w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_134319674-768x513.jpg 768w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_134319674-700x467.jpg 700w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_134319674-120x80.jpg 120w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><p id=\"caption-attachment-3016\" class=\"wp-caption-text\">Don\u2019t let anyone steal your cakes &#8211; ahem, your personal data. Here\u2019s what you need to know. Source: Adobe Stock \/ Olyina<\/p><\/div>\n<p>As the title itself hints, the core risk lies in unauthorized disclosure of personal data due to access by U.S. security authorities under the <strong>CLOUD Act<\/strong> (Clarifying Lawful Overseas Use of Data Act). Crucially, corporate affiliations mean that even if a cloud provider\u2019s servers are physically located within the European Economic Area (EEA), no guarantee of access security can be assumed. Compounding the problem: in cases of GDPR violations &#8211; particularly those arising from CLOUD Act-based access &#8211; data subjects have no legal recourse available to them.<\/p>\n<p>A further complication may arise from intensified efforts to <a href=\"https:\/\/www.heise.de\/news\/Saubere-AWS-Amazon-plant-wohl-staerkere-Loeschung-nicht-regelkonformen-Contents-6180997.html\">regulate web content<\/a>. Cloud storage systems are already scanned for criminally relevant material &#8211; for example, using the fundamentally legitimate goal of protecting children. Yet even today, controllers struggle to assess precisely how far such data access extends &#8211; or how their data is processed. Further expansion of online searches conducted by private cloud providers could pose risks beyond personal data protection &#8211; especially if business-critical data is affected.<\/p>\n<h2>The Mad Hatter Invites You to Tea<\/h2>\n<p>Amidst all the requirements and promises, it\u2019s often difficult to keep track &#8211; and to judge which measures are truly needed to ensure lawful data processing. Since U.S.-based cloud providers are considered to involve a <strong>transfer of data to the United States<\/strong> (an \u201cinsecure third country\u201d), any data processing must comply with Article 44 of the GDPR. But ever since the Court of Justice of the European Union\u2019s (<strong>CJEU<\/strong>) <strong>Schrems II<\/strong> ruling &#8211; which invalidated reliance on the European Commission\u2019s adequacy decisions for data transfers &#8211; you may sometimes feel like you\u2019re once again denied the promised cup of tea.<\/p>\n<p>Legitimate legal bases under the GDPR remain contracts with companies that demonstrate GDPR-compliant processing via <a href=\"https:\/\/edpb.europa.eu\/our-work-tools\/accountability-tools\/bcr_en\"><strong>BCRs (Approved Binding Corporate Rules)<\/strong><\/a>, or the adoption of the <a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/international-dimension-data-protection\/standard-contractual-clauses-scc_en\"><strong>new SCCs (EU Standard Contractual Clauses)<\/strong><\/a>. Even then, however, additional safeguards must be implemented to protect personal data. The objective: <strong>ensuring an appropriate level of protection against access by U.S. security authorities<\/strong>.<\/p>\n<h2>Out of the Labyrinth<\/h2>\n<p>&nbsp;<\/p>\n<p>Just as the Cheshire Cat shows Alice the way, Article 32(1)(a) of the GDPR recommends <strong>pseudonymisation<\/strong> and <strong>encryption<\/strong> as suitable technical measures to meet these requirements. In its \u201c<a href=\"https:\/\/edpb.europa.eu\/system\/files\/2021-07\/eppb_guidelines_202007_controllerprocessor_final_en.pdf\">Guidelines 07\/2020 on the concepts of controller and processor in the GDPR Version 2.0<\/a>\u201d, the European Data Protection Board (EDPB) specifies that <strong>personal data must be encrypted <em>before<\/em> transmission<\/strong>, and that the encryption key must <em>not<\/em> be known to the cloud provider.<\/p>\n<p>TeleTrusT\u2019s <a href=\"https:\/\/www.teletrust.de\/publikationen\/broschueren\/cloud-security\/\"><strong>Cloud Security Guide<\/strong><\/a> offers a concise, practical overview of security measures for safe cloud application use. Under the heading \u201cIntegrated Encryption\u201d, it explains and compares common terminology.<\/p>\n<div id=\"attachment_3017\" style=\"width: 260px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3017\" class=\"wp-image-3017 size-medium\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_116573682-250x167.jpg\" alt=\"\" width=\"250\" height=\"167\" srcset=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_116573682-250x167.jpg 250w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_116573682-768x512.jpg 768w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_116573682-700x467.jpg 700w, https:\/\/www.securitytoday.de\/wp-content\/uploads\/2021\/10\/AdobeStock_116573682-120x80.jpg 120w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><p id=\"caption-attachment-3017\" class=\"wp-caption-text\">There are various approaches to data encryption &#8211; each with its own advantages and drawbacks. Source: Adobe Stock \/ Dario Lo Presti<\/p><\/div>\n<p>Many providers have implemented <strong>BYOK<\/strong> (Bring Your Own Key) solutions, where the encryption key is transferred into the cloud provider\u2019s infrastructure &#8211; making it \u201ctechnically\u201d known to them. This enables automated key management (<strong>Service-Managed Keys<\/strong>), controlled entirely by the cloud provider.<br \/>\nWhile this delivers strong cybersecurity protection, it <em>fails<\/em> to satisfy GDPR\u2019s legal requirements for data protection!<\/p>\n<p>Instead, ensure your cloud solution supports <strong>HYOK<\/strong> (Hold Your Own Key) &#8211; a model requiring <em>two<\/em> keys: one held exclusively by the customer, without which data cannot be decrypted; and a second key embedded in the cloud provider\u2019s infrastructure to enable key management <em>within<\/em> the cloud. This approach preserves essential IT security functions &#8211; like automated key rotation &#8211; that would otherwise break down (or incur significantly higher administrative overhead) under a pure HYOK setup.<\/p>\n<p>These recommended solutions apply equally to smaller-scale deployments. Even using Google Drive, OneDrive, or Dropbox <em>without<\/em> additional safeguards constitutes a GDPR compliance issue. Tools like <a href=\"https:\/\/cryptomator.org\/de\/\"><strong>Cryptomator<\/strong><\/a> enable GDPR-compliant data storage &#8211; even for private users. The principle is simple: create an encrypted folder on Dropbox using Cryptomator, then securely store files inside it. This preserves cloud applications\u2019 native sync capabilities while fully meeting data protection requirements.<\/p>\n<p>With solutions like these, you\u2019ll ensure no one steals your precious cakes &#8211; i.e., your personal data. We\u2019d be delighted to advise you on your individual cloud configuration to guarantee both flawless data protection and high IT security.<\/p>\n<h5><a href=\"https:\/\/msecure.de\/kontakt\/\">Feel free to reach out!<\/a><\/h5>\n<p><span class=\"NormalTextRun BCX4 SCXW29721201\">Many questions<\/span><span class=\"NormalTextRun BCX4 SCXW29721201\">, <\/span><span class=\"NormalTextRun BCX4 SCXW29721201\">but no answers? Our experts at <\/span><span class=\"NormalTextRun BCX4 SCXW29721201\">msecure<\/span><span class=\"NormalTextRun BCX4 SCXW29721201\"> are ready to help with all your questions about <\/span><span class=\"NormalTextRun BCX4 SCXW29721201\">data protection<\/span><span class=\"NormalTextRun BCX4 SCXW29721201\"> and <\/span><span class=\"NormalTextRun BCX4 SCXW29721201\">IT<\/span><span class=\"NormalTextRun BCX4 SCXW29721201\"> security, tailored to your specific cloud setup.<\/span><span class=\"NormalTextRun BCX4 SCXW29721201\"><a href=\"https:\/\/msecure.de\/kontakt\/\"> Learn more here<\/a>!<\/span><\/p>\n<h2>Key Facts<\/h2>\n<p><strong>GDPR implementation:<\/strong> Only 28 percent of German companies consider themselves fully GDPR-compliant.<\/p>\n<p><strong>Highest single fine:<\/strong> \u20ac1.2 billion against Meta (2023)  &#8211;  the largest GDPR penalty to date.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What penalties apply for GDPR violations?<\/h3>\n<p>Fines of up to \u20ac20 million &#8211; or 4 percent of global annual turnover &#8211; whichever is higher. In addition, affected individuals may file claims for damages.<\/p>\n<h3>What is a Data Protection Impact Assessment (DPIA)?<\/h3>\n<p>A DPIA is a systematic evaluation of the risks a data processing operation poses to the rights and freedoms of data subjects. It is mandatory whenever processing is likely to result in a high risk &#8211; for instance, in cases involving profiling, video surveillance, or processing of special categories of personal data.<\/p>\n<h3>Does the GDPR apply to small businesses?<\/h3>\n<p>Yes &#8211; the GDPR applies universally to <em>any<\/em> organisation processing personal data of EU residents, regardless of size. Small businesses benefit from limited exemptions (e.g., no obligation to maintain a record of processing activities if fewer than 250 employees and processing is low-risk), but must still uphold all core GDPR principles.<\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/26\/post_id-3531\/\">GDPR 2026: What\u2019s changing &#8211; and what companies need to watch<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/24\/post_id-3529\/\">Multi-Cloud Security 2026: The 5 biggest risks &#8211; and how to solve them<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2023\/02\/01\/post_id-2062\/\">How Machine Learning Is Transforming IT Security<\/a><\/li>\n<\/ul>\n<h3>More from the MBF Media Network<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.cloudmagazin.com\" target=\"_blank\" rel=\"noopener\">Securing Your Cloud Migration<\/a><\/li>\n<\/ul>\n<p style=\"text-align: right;\"><em>Header Image Source: Adobe Stock \/ Haibullaev<\/em><\/p>\n<p><strong>Fact:<\/strong> According to IBM, the average cost of a data breach reached $4.88 million in 2025.<\/p>\n<p><strong>Fact:<\/strong> GDPR fines can amount to up to \u20ac20 million &#8211; or 4 percent of global annual turnover.<\/p>\n<\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>In the briefing paper \u201c<a href=\"https:\/\/www.bundestag.de\/resource\/blob\/852984\/692120a134f9e79999c6f4170a47859a\/WD-3-102-21-pdf-data.pdf\">GDPR and the Use of U.S. Cloud Services<\/a>\u201d  Don\u2019t let anyone steal your cakes &#8211; ahem, your personal data \u2026<\/li>\n<li>The EDPB (European Data Protection Board) states in its \u201c<a href=\"https:\/\/edpb.europa.eu\/system\/files\/2021-07\/eppb_guidelines_202007_controllerprocessor_final_en.pdf\">Guidelines 07\/2020 on the concepts of controller and processor in the GDPR Version 2.0<\/a>\u201d that personal data must be \u2026<\/li>\n<li> There are various approaches to data encryption &#8211; each with its own advantages and drawbacks.<\/li>\n<li>Providers also promote the opportunity to reduce IT investment costs &#8211; and redirect those funds into the company\u2019s value-creation areas.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"The cloud tempts with its simplicity, effortless implementation, and maximum scalability. Providers also tout the opportunity to reduce IT investment costs &#8211; freeing up capital to flow into core business value creation. But caution is warranted! It\u2019s all too easy to violate data subjects\u2019 rights under the GDPR &#8211; and find yourself facing the Red [&hellip;]","protected":false},"author":14,"featured_media":3024,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cloud-land","_yoast_wpseo_title":"Alice in the Cloud-Land","_yoast_wpseo_metadesc":"Cloud computing boosts scalability and cuts IT costs\u2014unlock efficiency and focus on your core business. Discover how with Alice in Cloud-Land today.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3015"],"footnotes":""},"categories":[251],"tags":[],"class_list":["post-8314","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":3015,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8314"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8314\/revisions"}],"predecessor-version":[{"id":14567,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8314\/revisions\/14567"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3024"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}