• Latest
  • Trending
Data protection when using cloud services: what startups need to know

Data protection when using cloud services

10. October 2024
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Data protection when using cloud services

10. October 2024
in Data protection Law
Reading Time: 4 mins read
0 0
A A
0
Data protection when using cloud services: what startups need to know

Cloud services offer start-ups numerous advantages such as flexibility, scalability and cost efficiency. However, the use of cloud services also entails considerable data protection challenges. This article highlights the most important aspects of data protection law that startups need to consider when using cloud services.

Content Hide
1. Legal framework
2. Responsibilities when using the cloud
3. Data processing agreement (DPA)
4. Technical and organizational measures
5. International data transfers
6. Special challenges for start-ups
7. Practical tips for start-ups
7.1. Author: Marian Härtel
Key Facts
  • Cloud services offer flexibility, scalability and cost efficiency, but also pose data protection challenges.
  • The legal framework for cloud use is defined by the GDPR, in particular by Art. 6, 28, 32, 44 et seq.
  • Startups are generally responsible for complying with data protection regulations and must conclude a DPA.
  • The DPA regulates key points such as processing, data protection obligations and confidentiality.
  • International data transfers require special attention in order to guarantee protection standards.
  • Startups should carry out due diligence and document data protection compliance measures.
  • A proactive data protection culture strengthens the trust of customers and partners and minimizes legal risks.

Legal framework

Data protection when using cloud services is primarily regulated by the General Data Protection Regulation (GDPR). Central aspects are:

  1. Lawfulness of the data processing (Art. 6 GDPR)
  2. Order processing (Art. 28 GDPR)
  3. Technical and organizational measures (Art. 32 GDPR)
  4. International data transfers (Art. 44 et seq. GDPR)

Responsibilities when using the cloud

When using cloud services, the startup is usually the controller within the meaning of the GDPR, while the cloud provider acts as a processor. This has important consequences:

  1. The startup remains responsible for compliance with data protection regulations.
  2. A data processing agreement (DPA) must be concluded with the cloud provider.
  3. The startup must monitor the cloud provider’s compliance with data protection regulations.

Data processing agreement (DPA)

The DPA is a central element in the data protection-compliant use of cloud services. It must regulate the following points in accordance with Art. 28 para. 3 GDPR:

  1. Object and duration of processing
  2. Nature and purpose of processing
  3. Type of personal data and categories of data subjects
  4. Obligations and rights of the controller
  5. The processor is bound by instructions
  6. Obligation of confidentiality
  7. Technical and organizational measures
  8. Regulations to support the person responsible
  9. Dealing with sub-processors
  10. Deletion or return of data after the end of processing

Many cloud providers make standardized AVVs available. These should be checked carefully and adapted if necessary.

Technical and organizational measures

Startups must ensure that the cloud provider has implemented appropriate technical and organizational measures (TOMs) to ensure a level of protection appropriate to the risk. Important aspects are:

  1. Encryption: both during transmission and when storing the data
  2. Access control: Strict regulations and procedures for accessing data
  3. Availability control: Measures to ensure the availability of data
  4. Separation control: Separate processing of data from different clients
  5. Pseudonymization: Where possible, data should be pseudonymized

Startups should carefully check and document the cloud provider’s TOMs.

International data transfers

Many cloud providers store or process data outside the EU. This is particularly relevant under data protection law:

  1. Adequacy decision: If the EU Commission has issued an adequacy decision for the destination country (e.g. for the United Kingdom), the data transfer is generally permitted.
  2. Standard contractual clauses: In many cases, the standard contractual clauses provided by the EU Commission are used to enable legally compliant data transfer.
  3. Binding Corporate Rules: Approved binding internal data protection regulations can be a solution for intra-group transfers.
  4. Additional measures: Following the ECJ’s Schrems II ruling, additional measures often need to be taken to ensure an adequate level of protection.

Startups should be particularly careful when using cloud services that transfer data to countries without an adequate level of data protection.

Special challenges for start-ups

  1. Resource constraints: Many startups do not have dedicated data protection experts. However, it is important to provide sufficient resources for data protection.
  2. Rapid growth: Data protection measures must be scaled accordingly when a company grows rapidly.
  3. Flexibility vs. compliance: The need to act quickly and flexibly must not come at the expense of data protection compliance.
  4. International expansion: When expanding into new markets, local data protection regulations must be taken into account.

Practical tips for start-ups

  1. Due diligence: Conduct a thorough review of potential cloud providers, particularly with regard to their data protection practices and certifications.
  2. Data protection impact assessment: For high-risk processing operations, carry out a data protection impact assessment in accordance with Art. 35 GDPR.
  3. Documentation: Carefully document all decisions and measures in connection with the use of cloud services.
  4. Encryption: Where possible, use end-to-end encryption to provide additional data protection.
  5. Data economy: Think critically about which data actually needs to be outsourced to the cloud.
  6. Contingency plan: Develop a plan in the event of a data protection incident or insolvency of the cloud provider.
  7. Regular review: Regularly check compliance with data protection regulations and that your measures are up to date.
  8. Training courses: Train your employees regularly in data protection issues, especially in dealing with cloud services.

The use of cloud services offers start-ups enormous opportunities, but also requires careful consideration of data protection aspects. A proactive approach to data protection can not only minimize legal risks, but also strengthen the trust of customers and partners. By implementing robust data protection practices, startups can reap the benefits of cloud services without neglecting compliance.

Given the complexity of the issue and the potentially serious consequences of non-compliance, it is advisable for start-ups to seek expert legal support when implementing cloud solutions. A specialist data protection lawyer can help develop tailor-made solutions that meet both business requirements and legal requirements.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: ComplianceEmployeesEntscheidungenEuGDPRGeneral Data Protection RegulationGrowthInsolvencyJudgmentPrivacyRiskStandard contractual clausesStartups

Weitere spannende Blogposts

Data protection authority may ban operation of Facebook page

Facebook pages, data protection and August 1, 2019
12. September 2019

The Federal Administrative Court has ruled that the operator of a company page on Facebook may be obliged to shut...

Read moreDetails

Legal structure of API usage agreements

Legal drafting of API usage agreements: Key issues for tech companies
16. October 2024

APIs (Application Programming Interfaces) are the backbone of the modern digital economy. They enable the seamless integration of services and...

Read moreDetails

Planned legal changes in 2023 in the area of digitization

Planned legal changes in 2023 in the area of digitization
5. January 2023

In its coalition agreement, the German government has firmly committed itself to fundamental strengthening in the area of digitization. Almost...

Read moreDetails

Supreme Federal Courts on Mastodon

Supreme Federal Courts on Mastodon
2. March 2023

Since yesterday, the offerings of the Federal Court of Justice, the Federal Administrative Court, the Federal Fiscal Court, the Federal...

Read moreDetails

10 aspects computer game developers should look for in a publishing contract

judge plays videogames in his spare time
27. July 2023

A publishing contract can be the turning point in any game developer's career, contributing to the growth and success of...

Read moreDetails

Excessive and unjustified warning does not lead to liability of the warning party

Adblock II decision: Reason is there
7. November 2022

The BGH has made an interesting judgment, which I would like to leave simply once in the with the guiding...

Read moreDetails

OLG Hamm and e-mail

OLG Hamm and e-mail
27. June 2024

OLG Hamm: Proof of e-mail access remains a challenge In a recent ruling (case no. 26 W 13/23 dated 10.08.2023),...

Read moreDetails

AI & Copyright: An Analysis

AI & Copyright: An Analysis
10. December 2022

AI & copyright is a new and important topic that worries many people. It is important to understand this issue...

Read moreDetails

Why work with a lawyer as a streamer?

youtube 3503481 960 720
30. January 2020

From last year's experience, I would like to accumulate in this article ten tips that YouTubers and streamers on the...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

75df8eaa33cd7d3975a96b022c65c6e4

Life as an IT lawyer, work-life balance, family and my career

26. September 2024

In this captivating episode of my IT Medialaw podcast, I, Marian Härtel, share my personal journey as a passionate IT...

Read moreDetails
43a60cb39d7ea477ac8f3845c1b7739c

Legal advice for start-ups – investments that pay off

8. December 2024
AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024
fcb134a2b3cfec5d256cf9742ecef1cd

The unconventional lawyer: a nerd in the service of the law

26. September 2024
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung