• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Data protection when using cloud services

10. October 2024
in Data protection Law
Reading Time: 4 mins read
0 0
A A
0
Data protection when using cloud services: what startups need to know
Key Facts
  • Cloud services offer flexibility, scalability and cost efficiency, but also pose data protection challenges.
  • The legal framework for cloud use is defined by the GDPR, in particular by Art. 6, 28, 32, 44 et seq.
  • Startups are generally responsible for complying with data protection regulations and must conclude a DPA.
  • The DPA regulates key points such as processing, data protection obligations and confidentiality.
  • International data transfers require special attention in order to guarantee protection standards.
  • Startups should carry out due diligence and document data protection compliance measures.
  • A proactive data protection culture strengthens the trust of customers and partners and minimizes legal risks.

Cloud services offer start-ups numerous advantages such as flexibility, scalability and cost efficiency. However, the use of cloud services also entails considerable data protection challenges. This article highlights the most important aspects of data protection law that startups need to consider when using cloud services.

Content Hide
1. Legal framework
2. Responsibilities when using the cloud
3. Data processing agreement (DPA)
4. Technical and organizational measures
5. International data transfers
6. Special challenges for start-ups
7. Practical tips for start-ups
7.1. Author: Marian Härtel

Legal framework

Data protection when using cloud services is primarily regulated by the General Data Protection Regulation (GDPR). Central aspects are:

  1. Lawfulness of the data processing (Art. 6 GDPR)
  2. Order processing (Art. 28 GDPR)
  3. Technical and organizational measures (Art. 32 GDPR)
  4. International data transfers (Art. 44 et seq. GDPR)

Responsibilities when using the cloud

When using cloud services, the startup is usually the controller within the meaning of the GDPR, while the cloud provider acts as a processor. This has important consequences:

  1. The startup remains responsible for compliance with data protection regulations.
  2. A data processing agreement (DPA) must be concluded with the cloud provider.
  3. The startup must monitor the cloud provider’s compliance with data protection regulations.

Data processing agreement (DPA)

The DPA is a central element in the data protection-compliant use of cloud services. It must regulate the following points in accordance with Art. 28 para. 3 GDPR:

  1. Object and duration of processing
  2. Nature and purpose of processing
  3. Type of personal data and categories of data subjects
  4. Obligations and rights of the controller
  5. The processor is bound by instructions
  6. Obligation of confidentiality
  7. Technical and organizational measures
  8. Regulations to support the person responsible
  9. Dealing with sub-processors
  10. Deletion or return of data after the end of processing

Many cloud providers make standardized AVVs available. These should be checked carefully and adapted if necessary.

Technical and organizational measures

Startups must ensure that the cloud provider has implemented appropriate technical and organizational measures (TOMs) to ensure a level of protection appropriate to the risk. Important aspects are:

  1. Encryption: both during transmission and when storing the data
  2. Access control: Strict regulations and procedures for accessing data
  3. Availability control: Measures to ensure the availability of data
  4. Separation control: Separate processing of data from different clients
  5. Pseudonymization: Where possible, data should be pseudonymized

Startups should carefully check and document the cloud provider’s TOMs.

International data transfers

Many cloud providers store or process data outside the EU. This is particularly relevant under data protection law:

  1. Adequacy decision: If the EU Commission has issued an adequacy decision for the destination country (e.g. for the United Kingdom), the data transfer is generally permitted.
  2. Standard contractual clauses: In many cases, the standard contractual clauses provided by the EU Commission are used to enable legally compliant data transfer.
  3. Binding Corporate Rules: Approved binding internal data protection regulations can be a solution for intra-group transfers.
  4. Additional measures: Following the ECJ’s Schrems II ruling, additional measures often need to be taken to ensure an adequate level of protection.

Startups should be particularly careful when using cloud services that transfer data to countries without an adequate level of data protection.

Special challenges for start-ups

  1. Resource constraints: Many startups do not have dedicated data protection experts. However, it is important to provide sufficient resources for data protection.
  2. Rapid growth: Data protection measures must be scaled accordingly when a company grows rapidly.
  3. Flexibility vs. compliance: The need to act quickly and flexibly must not come at the expense of data protection compliance.
  4. International expansion: When expanding into new markets, local data protection regulations must be taken into account.

Practical tips for start-ups

  1. Due diligence: Conduct a thorough review of potential cloud providers, particularly with regard to their data protection practices and certifications.
  2. Data protection impact assessment: For high-risk processing operations, carry out a data protection impact assessment in accordance with Art. 35 GDPR.
  3. Documentation: Carefully document all decisions and measures in connection with the use of cloud services.
  4. Encryption: Where possible, use end-to-end encryption to provide additional data protection.
  5. Data economy: Think critically about which data actually needs to be outsourced to the cloud.
  6. Contingency plan: Develop a plan in the event of a data protection incident or insolvency of the cloud provider.
  7. Regular review: Regularly check compliance with data protection regulations and that your measures are up to date.
  8. Training courses: Train your employees regularly in data protection issues, especially in dealing with cloud services.

The use of cloud services offers start-ups enormous opportunities, but also requires careful consideration of data protection aspects. A proactive approach to data protection can not only minimize legal risks, but also strengthen the trust of customers and partners. By implementing robust data protection practices, startups can reap the benefits of cloud services without neglecting compliance.

Given the complexity of the issue and the potentially serious consequences of non-compliance, it is advisable for start-ups to seek expert legal support when implementing cloud solutions. A specialist data protection lawyer can help develop tailor-made solutions that meet both business requirements and legal requirements.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: ComplianceEmployeesEntscheidungenEuGDPRGeneral Data Protection RegulationGrowthInsolvencyJudgmentPrivacyRiskStandard contractual clausesStartups

Weitere spannende Blogposts

Publishing contracts and recycling of code

copyright
17. October 2019

Creating and correcting publishing contracts for computer games is just as much my day-to-day business as contracts for freelancers and...

Read moreDetails

Stralsund Regional Court: EUR 4,000 in monetary compensation for sending sexting and dickpix messages

Stralsund Regional Court: EUR 4,000 in monetary compensation for sending sexting and dickpix messages
10. June 2024

On June 6, 2024, the 4th Chamber of the Stralsund Regional Court issued a ruling on the civil law consequences...

Read moreDetails

AI-generated content: Who owns the rights?

a7476826606eddf6e6711ec857b02593
18. June 2024

Copyright for AI content: Current legal situation and open questions The nuuse of artificialartificial intelligence (AI) for thecreation of textstexts,...

Read moreDetails

LSG Celle: Artists’ social security contributions may not be levied on the basis of an undifferentiated estimate

LSG Celle: Artists’ social security contributions may not be levied on the basis of an undifferentiated estimate
8. March 2023

In an exciting decision on the so-called Künstlersozialabgabe (artists' social security contribution), the Landessozialgericht Celle (Regional Social Court of Celle)...

Read moreDetails

OLG Frankfurt am Main vs. OLG Celle – FernUSG in B2B Contracts

OLG Frankfurt am Main vs. OLG Celle – FernUSG in B2B Contracts
30. October 2023

There has been noticeable uncertainty in the coaching industry to date, particularly with regard to the applicability of the Distance...

Read moreDetails

16 years of innovation and passion in IT law: a personal review

16 jahre innovation und leidenschaft im it recht ein persoenlicher rueckblick
10. January 2024

Sometimes it takes a little reminder to make us realize the importance of a long journey. Yesterday, LinkedIn reminded me...

Read moreDetails

Blockchain technology and start-ups – a look into the future

Howey test
13. March 2024

Two days ago, I had the opportunity to attend the presentation of the W3Now study in Berlin. This event was...

Read moreDetails

Soon no Twitch, Steam, Discord, Twitter for under 16s?

Soon no Twitch, Steam, Discord, Twitter for under 16s?
7. November 2022

Will young people under 16 in Germany soon no longer be able to use Twitch, YouTube, Discord, Steam, Twitter and...

Read moreDetails

Contracts in IT law – everything always in writing

Contracts in IT law – everything always in writing
7. November 2022

I feel that 10% of my work as a lawyer consists of people or companies in IT law trusting each...

Read moreDetails
Contractual regulations for no-code/low-code software development
Other

Contractual regulations for no-code/low-code software development

21. May 2025

No-code and low-code platforms enable rapid software development without extensive manual programming. Applications are increasingly being developed on the basis...

Read moreDetails
Erotic content on OnlyFans: Copyright and personality rights protection for creators

Erotic content on OnlyFans: Copyright and personality rights protection for creators

20. May 2025
Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

19. May 2025
Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

18. May 2025
From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

17. May 2025

Podcastfolge

c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024

This insightful podcast episode takes an in-depth look at the startup and innovation landscape in Germany and Europe. The discussion...

Read moreDetails
238a909c26a0302cbd4792cbd18e4922

Global challenges for start-ups – A legal guide

10. October 2024
8ffe8f2a4228de20d20238899b3d922e

Web3, blockchain and law – a critical review

26. September 2024
247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024
Looking to the future: How technology is changing the law

Looking to the future: How technology is changing the law

18. February 2025

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung