The EU Data Protection Code of Conduct for Cloud Service Providers

21 settembre 2021

The EDPB adopted Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe.

The main objective of the EU Cloud Code is to concretize the legal requirements of Art. 28 GDPR and the relevant related articles of the GDPR. The EU Cloud Code is intended to address all service types of the cloud market (e.g. IaaS, PaaS, SaaS) and creates a “baseline for implementation of GDPR” for these services. Its purpose is to provide practical guidance and define specific requirements for the cloud service providers (“CSPs”). 

As known, Cloud computing consists of a set of technologies and service models that focus on the Internet-based use and delivery of IT applications, processing capability, storage, and memory space. 

The term "cloud computing" covers a variety of very distinct service provision models such as Cloud Infrastructure as a Service Cloud (“IaaS”), Cloud Software as a Service (“SaaS”), and Cloud Platform as a Service (“PaaS”). The term “IaaS” describes a situation in which a provider leases a technological infrastructure, i.e. virtual remote servers the end-user can rely upon in accordance with mechanisms and arrangements such as to make it simple, effective as well as beneficial to replace the corporate IT systems at the company’s premises and/or use the leased infrastructure alongside the corporate systems. When providing “SaaS”, a provider delivers, via the web, various application services and makes them available to end-users. These services are often meant to replace conventional applications to be installed by users on their local systems; accordingly, users are ultimately meant to outsource their data to the individual provider. When providing “PaaS”, a provider offers solutions for the advanced development and hosting of applications. These services are usually addressed to market players that use them to develop and host proprietary application-based solutions to meet in-house requirements and/or to provide services to third parties. 

The EU Cloud Code only applies to cloud services where the CSP is acting as a processor. It, therefore, does not apply to “business to consumer” (B2C) services or for any processing activities for which the CSP may act as a data controller. However, the Code is also relevant for consumers who will get additional guarantees of compliance when entrusting with their personal data a company that uses a processor which adheres to the Code .

Archivio news

 

News dello studio

lug20

20/07/2026

Sentenza della Corte nella causa C-421/24 | AGCOM (Gioco d’azzardo online)

er la Corte di Giustizia dell'Ue, la  Piattaforme multimediali Google può essere ritenuta responsabile per i video YouTube di un creatore di contenuti vincolato da una partnership

lug20

20/07/2026

Sintesi della consultazione pubblica indetta con la delibera n. 59/26/CONS concernente l’impiego di frequenze nella banda 40,5-43,5 GHz per sistemi terrestri in grado di fornire servizi di comunicazione elettronica a banda larga wireless ai sensi della de

Il documento riporta una sintesi delle posizioni espresse e delle informazioni fornite dai rispondenti alla consultazione pubblica di cui alla delibera n. 59/26/CONS concernente l’impiego

lug20

20/07/2026

NIS2: Organi di amministrazione e direttivi

L'Agenzia per la Cybersicurezza Nazionale ha aggiornato le FAQ relative agli obblighi degli organi di amministrazione e direttivi dei soggetti NIS, integrando le FAQ ODA.8 e ODA.9 e introducendo

News Giuridiche

lug20

20/07/2026

L’avvocato non è mai in pausa: la toga senza scrivania

Per l'iscrizione e la permanenza nell’albo

lug20

20/07/2026

Esame avvocato e pratica forense: le nuove disposizioni

<p>Con il <a href="https://onelegale.wolterskluwer.it/document/10LX0001006304SOMM"

lug20

20/07/2026

Nel CCNL Studi professionali la formazione diventa welfare

<p><span>Il CCNL con il supporto