• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
SAVED POSTS
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Data protection when using cloud services: what startups need to know

10. October 2024
in Data protection Law
Reading Time: 4 mins read
0 0
A A
0
Key Facts
  • Startups must ensure compliance with GDPR by defining clear responsibilities and securing a Data Processing Agreement with the cloud provider.
  • Implementing appropriate technical and organizational measures is crucial for data protection during cloud service usage, especially in international contexts.

Cloud services offer start-ups numerous advantages such as flexibility, scalability and cost efficiency. However, the use of cloud services also entails considerable data protection challenges. This article highlights the most important aspects of data protection law that startups need to consider when using cloud services.

Content Hide
1. Legal framework
2. Responsibilities when using the cloud
3. Data processing agreement (DPA)
4. Technical and organizational measures
5. International data transfers
6. Special challenges for start-ups
7. Practical tips for start-ups
7.1. Author: Marian Härtel

Legal framework

Data protection when using cloud services is primarily regulated by the General Data Protection Regulation (GDPR). Central aspects are:

  1. Lawfulness of the data processing (Art. 6 GDPR)
  2. Order processing (Art. 28 GDPR)
  3. Technical and organizational measures (Art. 32 GDPR)
  4. International data transfers (Art. 44 et seq. GDPR)

Responsibilities when using the cloud

When using cloud services, the startup is usually the controller within the meaning of the GDPR, while the cloud provider acts as a processor. This has important consequences:

  1. The startup remains responsible for compliance with data protection regulations.
  2. A data processing agreement (DPA) must be concluded with the cloud provider.
  3. The startup must monitor the cloud provider’s compliance with data protection regulations.

Data processing agreement (DPA)

The DPA is a central element in the data protection-compliant use of cloud services. It must regulate the following points in accordance with Art. 28 para. 3 GDPR:

  1. Object and duration of processing
  2. Nature and purpose of processing
  3. Type of personal data and categories of data subjects
  4. Obligations and rights of the controller
  5. The processor is bound by instructions
  6. Obligation of confidentiality
  7. Technical and organizational measures
  8. Regulations to support the person responsible
  9. Dealing with sub-processors
  10. Deletion or return of data after the end of processing

Many cloud providers make standardized AVVs available. These should be checked carefully and adapted if necessary.

Technical and organizational measures

Startups must ensure that the cloud provider has implemented appropriate technical and organizational measures (TOMs) to ensure a level of protection appropriate to the risk. Important aspects are:

  1. Encryption: both during transmission and when storing the data
  2. Access control: Strict regulations and procedures for accessing data
  3. Availability control: Measures to ensure the availability of data
  4. Separation control: Separate processing of data from different clients
  5. Pseudonymization: Where possible, data should be pseudonymized

Startups should carefully check and document the cloud provider’s TOMs.

International data transfers

Many cloud providers store or process data outside the EU. This is particularly relevant under data protection law:

  1. Adequacy decision: If the EU Commission has issued an adequacy decision for the destination country (e.g. for the United Kingdom), the data transfer is generally permitted.
  2. Standard contractual clauses: In many cases, the standard contractual clauses provided by the EU Commission are used to enable legally compliant data transfer.
  3. Binding Corporate Rules: Approved binding internal data protection regulations can be a solution for intra-group transfers.
  4. Additional measures: Following the ECJ’s Schrems II ruling, additional measures often need to be taken to ensure an adequate level of protection.

Startups should be particularly careful when using cloud services that transfer data to countries without an adequate level of data protection.

Special challenges for start-ups

  1. Resource constraints: Many startups do not have dedicated data protection experts. However, it is important to provide sufficient resources for data protection.
  2. Rapid growth: Data protection measures must be scaled accordingly when a company grows rapidly.
  3. Flexibility vs. compliance: The need to act quickly and flexibly must not come at the expense of data protection compliance.
  4. International expansion: When expanding into new markets, local data protection regulations must be taken into account.

Practical tips for start-ups

  1. Due diligence: Conduct a thorough review of potential cloud providers, particularly with regard to their data protection practices and certifications.
  2. Data protection impact assessment: For high-risk processing operations, carry out a data protection impact assessment in accordance with Art. 35 GDPR.
  3. Documentation: Carefully document all decisions and measures in connection with the use of cloud services.
  4. Encryption: Where possible, use end-to-end encryption to provide additional data protection.
  5. Data economy: Think critically about which data actually needs to be outsourced to the cloud.
  6. Contingency plan: Develop a plan in the event of a data protection incident or insolvency of the cloud provider.
  7. Regular review: Regularly check compliance with data protection regulations and that your measures are up to date.
  8. Training courses: Train your employees regularly in data protection issues, especially in dealing with cloud services.

The use of cloud services offers start-ups enormous opportunities, but also requires careful consideration of data protection aspects. A proactive approach to data protection can not only minimize legal risks, but also strengthen the trust of customers and partners. By implementing robust data protection practices, startups can reap the benefits of cloud services without neglecting compliance. Given the complexity of the issue and the potentially serious consequences of non-compliance, it is advisable for startups to seek expert legal support when implementing cloud solutions. A specialist data protection lawyer can help develop tailor-made solutions that meet both business requirements and legal requirements.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: ComplianceConfidentialityEmployeesEntscheidungenEuGDPRGeneral Data Protection RegulationGrowthInsolvencyJudgmentPrivacyRiskStandard contractual clausesStartups

Weitere spannende Blogposts

Amazon sellers and duplicate product pages

Attention: Vouchers to existing customers can be advertising!
12. December 2018

The issue and case law are from last year, but there still seem to be sellers at Amazon who don't...

Read moreDetails

Employment law for startups

Employment law for start-ups: Important regulations when building a team
10. October 2024

Building a competent and motivated team is crucial to the success of a start-up. However, founders must observe a variety...

Read moreDetails

Data protection conference allows “pure subscription” model on websites

Data protection conference allows “pure subscription” model on websites
4. April 2023

The Conference of Independent Federal and State Data Protection Authorities (DSK) recently issued a decision regarding so-called pure subscription models...

Read moreDetails

Fraud through Apple Pay: A recent ruling by the Regional Court of Cologne and its implications

Fraud through Apple Pay: A recent ruling by the Regional Court of Cologne and its implications
17. May 2024

Introduction In everyday practice, there are always clients who have fallen victim to fraud through Apple Pay. These cases require...

Read moreDetails

Why I love innovative business models as a lawyer

Why I love innovative business models as a lawyer
29. March 2023

As a lawyer, I have done a lot of contracting and consulting on traditional business models. But it is particularly...

Read moreDetails

ECJ confirms classification of TikTok as a “gatekeeper”

Lego brick still protected as a design patent
13. August 2024

The Chinese Bytedance Group, which operates the video portal TikTok, has failed with a lawsuit against its classification as a...

Read moreDetails

Smart contract implementation in traditional contracts

Smart contract implementation in traditional contracts
10. October 2024

The integration of smart contracts into traditional contract structures opens up fascinating opportunities for blockchain start-ups, but also poses complex...

Read moreDetails

LG Frankfurt a.M.: Other termination options permitted in addition to the termination button on the website

LG Frankfurt a.M.: Other termination options permitted in addition to the termination button on the website
17. May 2024

Background of the judgment In a ruling dated August 30, 2023 (case no. 2-06 O 411/22), the Regional Court of...

Read moreDetails

What are Security Tokens and what are Utility Tokens?

What are Security Tokens and what are Utility Tokens?
21. December 2022

Introduction: what are tokens and what are they used for? Tokens are a digital type of currency used to conduct...

Read moreDetails
Q&A: Legal issues for game developers
Law and computer games

5-day guide: Founding a game development studio

5. August 2025

As a support for young studios, this series summarizes the essential steps for founding a game development company. The guide...

Read moreDetails
EU Inc: Why Europe needs a unified startup society now

EU Inc: Why Europe needs a unified startup society now

22. July 2025
BGH considers Uber Black to be anti-competitive

BGH shakes up the coaching industry – What applies now?

21. July 2025
Growth hacking and viral marketing – legal requirements

Games funding 2025 – back at last!

20. July 2025
Ownership of software – Who actually owns the code?

Ownership of software – Who actually owns the code?

14. July 2025

Podcastfolge

4f3597d5481e0f38e37bf80eaad208c7

The IT Media Law Podcast. Episode No. 1: What is this actually about?

26. August 2024

Yeah, the first real episode with myself! In this podcast, we dive into the exciting world of IT law and...

Read moreDetails
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024
8ffe8f2a4228de20d20238899b3d922e

Web3, blockchain and law – a critical review

26. September 2024
7c0b449a651fe0b81e5eec2e23515012 2

Copyright in the digital age

15. January 2025
75df8eaa33cd7d3975a96b022c65c6e4

Life as an IT lawyer, work-life balance, family and my career

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung