European recommendations following Schrems II Privacy Shield ruling cast doubt on cloud encryption practices
(2020/11/23)
- Reference: 1606123806
- News link: https://www.theregister.co.uk/2020/11/23/european_recommendations_on_schrems_ii/
- Source link:
The European Data Protection Board (EDPB) has issued guidance that calls into question recommendations to cloud services providers in responding to the Schrems II ruling, which struck down the Privacy Shield arrangement for moving data from the EU to the US.
The EDPB, which is responsible for European data protection law, [1]said [PDF] encryption could safeguard against contravening the ruling, but only when keys remain within the EU or trusted third countries.
In July, [2]the EU Court of Justice ruled that the now-dead Privacy Shield arrangement – itself a replacement of Safe Harbor – does not allow EU citizens to challenge a breach of the arrangement by a company in the US handling EU personal data.
The Schrems II ruling resulted from a case brought by privacy activist Max Schrems, complaining that Ireland's data protection agency did not prevent Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from sending his data to the US.
The ruling triggered a fresh wave of legal confusion over the transfer of EU subjects' data to countries outside its jurisdiction – particularly the US. Trusted third countries with "adequate" data protection rules allowing the transfer of data include Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, and Uruguay. Whether the UK will be on the list will be [3]determined by ongoing Brexit negotiations .
Following the Schrems II ruling, [4]AWS issued guidance saying its "customers and partners can continue to use AWS to transfer their content from Europe to the US and other countries, in compliance with EU data protection laws" as it was covered by standard contractual clauses (SCCs).
The SSCs might need to include [5]“supplementary measures” where laws in a third country create risks to data protection . These supplementary measures can be contractual, technical or organisational or a combination of the three.
Among measures to mitigate risk, AWS pointed to "a number of advanced encryption and key management services that customers and partners can use to protect their content".
Key management services include " [6]bring-your-own-key " encryption, which allows organisations to manage their own encryption key services for data in the AWS cloud.
However, in its recommendations the EDPB said that encryption would only be an adequate measure if "the keys are retained solely under the control of the data exporter, or other entities entrusted with this task which reside in the European Economic Areas" or a third country with an adequate level of protection.
Speaking on a UKCloud webinar this week, Owen Sayers, enterprise architect and data protection, privacy and security specialist, said encrypting the data and storing it as a blob in a country outside the EU and trusted jurisdictions, retaining the keys, then bringing the data back down and decrypting was "perfectly OK" so long as there was sufficient encryption.
The problem with BYOK encryption arises if the data exporter uses a cloud provider in a third country where it can be obliged by the authorities to hand over data. If the exporter uses that cloud service and puts the encryption keys into the cloud, or makes them available to the cloud provider to decrypt data and process data inside the cloud then that data could be intercepted, copied, or manipulated. That’s insufficient to meet the needs of the EDPB recommendations.
"When it comes to accessing data from a third country or doing anything with the live data in a clear text format, they're very clear that encryption has very little benefit. An awful lot of solutions that the industry has put forwards [involving] bring-your-own-key encryption... the reality is that has never really been a good thing to do, and the EDPB are now saying that they don't believe that that would be adequate," Sayers.
As such, it would not make a requirement for a supplementary measure in SCCs to help comply with the Schrems II ruling.
The issue may not be unique to AWS. [7]GCP and [8]Microsoft Azure have both issued guidance saying their services are safe to use in accordance with the ruling due to overlapping SCCs, although neither mentioned encryption as a supplementary measure. Both do offer forms of BYOK encryptions.
An AWS spokesperson told The Reg : "Because the Court of Justice of the European Union (CJEU) has validated the use of Standard Contractual Clauses (SCCs) as a mechanism for transferring data outside the European Union, our customers can continue to rely on the SCCs included in the AWS Data Processing Addendum for any data transfer outside of the European Union.
"To address the European Data Protection Board's recent recommendation regarding the CJEU ruling, in addition to the supplemental measures we implement, customers can choose to encrypt their data, at rest or in motion, using AWS tools or a number of supported 3rd party security solutions, while maintaining full control of the encryption keys." ®
Get our [9]Tech Resources
[1] https://edpb.europa.eu/sites/edpb/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_en.pdf
[2] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[3] https://www.theregister.com/2020/09/29/uk_data_adequacy_brexit/
[4] https://aws.amazon.com/blogs/security/customer-update-aws-and-the-eu-us-privacy-shield/
[5] https://www.twobirds.com/en/news/articles/2020/global/edpb-publishes-draft-recommendations-on-data-transfer-post-schrems-ii
[6] https://aws.amazon.com/blogs/security/how-to-byok-bring-your-own-key-to-aws-kms-for-less-than-15-00-a-year-using-aws-cloudhsm/
[7] https://cloud.google.com/blog/products/identity-security/google-clouds-commitment-to-eu-international-data-transfers-and-the-cjeu-ruling
[8] https://blogs.microsoft.com/eupolicy/2020/07/16/assuring-customers-about-cross-border-data-flows/
[9] https://whitepapers.theregister.com/
The EDPB, which is responsible for European data protection law, [1]said [PDF] encryption could safeguard against contravening the ruling, but only when keys remain within the EU or trusted third countries.
In July, [2]the EU Court of Justice ruled that the now-dead Privacy Shield arrangement – itself a replacement of Safe Harbor – does not allow EU citizens to challenge a breach of the arrangement by a company in the US handling EU personal data.
The Schrems II ruling resulted from a case brought by privacy activist Max Schrems, complaining that Ireland's data protection agency did not prevent Facebook Ireland Ltd (as EU representative of the Zuckerberg empire) from sending his data to the US.
The ruling triggered a fresh wave of legal confusion over the transfer of EU subjects' data to countries outside its jurisdiction – particularly the US. Trusted third countries with "adequate" data protection rules allowing the transfer of data include Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, and Uruguay. Whether the UK will be on the list will be [3]determined by ongoing Brexit negotiations .
Following the Schrems II ruling, [4]AWS issued guidance saying its "customers and partners can continue to use AWS to transfer their content from Europe to the US and other countries, in compliance with EU data protection laws" as it was covered by standard contractual clauses (SCCs).
The SSCs might need to include [5]“supplementary measures” where laws in a third country create risks to data protection . These supplementary measures can be contractual, technical or organisational or a combination of the three.
Among measures to mitigate risk, AWS pointed to "a number of advanced encryption and key management services that customers and partners can use to protect their content".
Key management services include " [6]bring-your-own-key " encryption, which allows organisations to manage their own encryption key services for data in the AWS cloud.
However, in its recommendations the EDPB said that encryption would only be an adequate measure if "the keys are retained solely under the control of the data exporter, or other entities entrusted with this task which reside in the European Economic Areas" or a third country with an adequate level of protection.
Speaking on a UKCloud webinar this week, Owen Sayers, enterprise architect and data protection, privacy and security specialist, said encrypting the data and storing it as a blob in a country outside the EU and trusted jurisdictions, retaining the keys, then bringing the data back down and decrypting was "perfectly OK" so long as there was sufficient encryption.
The problem with BYOK encryption arises if the data exporter uses a cloud provider in a third country where it can be obliged by the authorities to hand over data. If the exporter uses that cloud service and puts the encryption keys into the cloud, or makes them available to the cloud provider to decrypt data and process data inside the cloud then that data could be intercepted, copied, or manipulated. That’s insufficient to meet the needs of the EDPB recommendations.
"When it comes to accessing data from a third country or doing anything with the live data in a clear text format, they're very clear that encryption has very little benefit. An awful lot of solutions that the industry has put forwards [involving] bring-your-own-key encryption... the reality is that has never really been a good thing to do, and the EDPB are now saying that they don't believe that that would be adequate," Sayers.
As such, it would not make a requirement for a supplementary measure in SCCs to help comply with the Schrems II ruling.
The issue may not be unique to AWS. [7]GCP and [8]Microsoft Azure have both issued guidance saying their services are safe to use in accordance with the ruling due to overlapping SCCs, although neither mentioned encryption as a supplementary measure. Both do offer forms of BYOK encryptions.
An AWS spokesperson told The Reg : "Because the Court of Justice of the European Union (CJEU) has validated the use of Standard Contractual Clauses (SCCs) as a mechanism for transferring data outside the European Union, our customers can continue to rely on the SCCs included in the AWS Data Processing Addendum for any data transfer outside of the European Union.
"To address the European Data Protection Board's recent recommendation regarding the CJEU ruling, in addition to the supplemental measures we implement, customers can choose to encrypt their data, at rest or in motion, using AWS tools or a number of supported 3rd party security solutions, while maintaining full control of the encryption keys." ®
Get our [9]Tech Resources
[1] https://edpb.europa.eu/sites/edpb/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_en.pdf
[2] https://www.theregister.com/2020/07/16/privacy_shield_struck_down/
[3] https://www.theregister.com/2020/09/29/uk_data_adequacy_brexit/
[4] https://aws.amazon.com/blogs/security/customer-update-aws-and-the-eu-us-privacy-shield/
[5] https://www.twobirds.com/en/news/articles/2020/global/edpb-publishes-draft-recommendations-on-data-transfer-post-schrems-ii
[6] https://aws.amazon.com/blogs/security/how-to-byok-bring-your-own-key-to-aws-kms-for-less-than-15-00-a-year-using-aws-cloudhsm/
[7] https://cloud.google.com/blog/products/identity-security/google-clouds-commitment-to-eu-international-data-transfers-and-the-cjeu-ruling
[8] https://blogs.microsoft.com/eupolicy/2020/07/16/assuring-customers-about-cross-border-data-flows/
[9] https://whitepapers.theregister.com/
Re: What about Office Suites?
Zippy´s Sausage Factory
I can see a lot of consultants are going to be getting very rich selling a lot of snake oil solutions to this problem n the very near future...
What about Office Suites?
I guess most still wonder if they can/should use Office365, G Suite and similar to process EU citizens personal data.
The short answer is: No, you are violating data subjects fundamental right to Privacy (art. 7 and 8) as stated by the EUCJ.
You could do it if you obtain informed consent from the users, as their personal data will be often shared in Azure AD, and the people you are writing about/contacting by email/adding to your CRM/etc...(data subjects) stating clearly that their personal data will be transferred to a data importer (Microsoft/Google/etc) which, regardless if the contract is signed with a EU subsidiary and stored in EU, cannot ensure an adequate and equivalent level of protection and by doing so it will violate their right to privacy (and contribute to support the expansion of surveillance capitalism business models but that's another issue).
Some more info: https://joinup.ec.europa.eu/collection/joinup/news/privacy-shield-invalidation
These transfers fall under the Use Case 6 of the EDPB recommendations as the text you are writing in Word or the emails you are sending out are all processed in clear so at present you are not able to use those tools without violating people's privacy and naturally that will make your organisation also non GDPR/DPA compliant.
EDPB's recommendations can be found here: https://edpb.europa.eu/sites/edpb/files/consultation/edpb_recommendations_202001_supplementarymeasurestransferstools_en.pdf