Google echoes Amazon's assurance on EU data protection compliance

Microsoft, Amazon Web Services and now Google have promised customers they will be ready for the European Union's new data protection regime when it enters force next year



Google has joined Amazon Web Services in promising customers of its cloud services that it will be compliant with new European Union data protection rules due to take effect next year.

Neither company is fully compliant yet, but both have now made public commitments to meet the requirements of the EU General Data Protection Regulation (GDPR) by May 25, 2018, echoing a promise Microsoft made back in February.

The GDPR replaces the 1995 Data Protection Directive. Among its biggest changes are requirements that companies:
- erase personal data on request unless there is a legitimate reason to retain it;
- inform those affected by data breaches, and
- design data protection into their products and services from the earliest stage of development.

It's not all extra work for businesses: There are some exemptions for small and medium-size businesses (SMEs), and the GDPR's move to a single set of rules for all of the EU's 28 (for now) member states puts an end to jurisdiction shopping -- litigating privacy cases in the most favorable territory -- and makes compliance simpler for companies working across borders.

But some businesses will become liable in ways that they weren't before: The GDPR applies not just to data controllers -- typically those by or for whom the data was collected -- but also to data processors, the service providers or middlemen that hold the data or perform the calculations on it. Their customers will want the rights and responsibilities of each party set out clearly before the new rules take effect.

AWS Chief Information Security Officer Stephen Schmidt outlined the company's progress towards GDPR compliance in a blog post on April 25. "I am happy to announce today that all AWS services will comply with the GDPR when it becomes enforceable," he wrote.

That surely prompted Wednesday's blog post from Google Cloud's director for security, trust and privacy, Suzanne Frey, and its director of data protection and compliance, Marc Crandall. "Google is committed to GDPR compliance across G Suite and Google Cloud Platform (GCP) services when the GDPR takes effect," they wrote.

But both companies were beaten to the punch by Microsoft Chief Privacy Officer Brendon Lynch. "Microsoft is committing to be GDPR compliant across our cloud services when enforcement begins," he wrote on Feb. 15 in a blog post about the readiness of services such as Azure, Dynamics 365 and Office 365 for the the new rules.

AWS is a little further ahead than Google, at least when it comes to the paperwork. The company has already revised its Data Processing Agreement to meet the requirements of the GDPR, and is making it available to customers on request, Schmidt said.

Frey and Crandall could only say that Google Cloud has evolved its data processing terms over the years, and that they "will be updated for the GDPR as well."

Once again, Microsoft has trumped them: Lynch pointed readers to the GDPR pages of the company's Trust Center, which now indicate that Microsoft made available contractual guarantees on data processing back in March.

It's a fairly safe bet that the big cloud service providers will ensure their compliance with the new regulation: Their business, at least in Europe, depends on it.

But their customers operating in Europe still have work to do before the deadline. They'll need to figure out (if they haven't already) what personal information they hold about European citizens, update internal governance and procedures to determine who can access the data and how it will be protected, and prepare the documents needed to prove compliance with the new rules come May 25, 2018.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Peter Sayer

IDG News Service
Show Comments


James Cook University - Master of Data Science Online Course

Learn more >


Victorinox Werks Professional Executive 17 Laptop Case

Learn more >



Back To Business Guide

Click for more ›

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?