Cloud computing

Data protection glossary · 1 minute read

Cloud computing is the provision of IT resources such as storage, computing power or software over the internet by an external provider.

Data protection classification

Where a cloud provider processes personal data on behalf of a customer, this is generally processing on behalf of a controller. A data processing agreement is then required, and the customer must check whether the provider offers sufficient guarantees of data security.

Responsibility for the lawfulness of the processing remains with the customer. The provider's certifications and audit reports make it easier to provide evidence.

Third-country aspects

If the provider or a sub-processor is based outside the EU or the EEA, or if access from there is possible, the rules on third-country transfers also apply. For US providers, it is particularly important whether they are certified under the EU-U.S. Data Privacy Framework or whether standard contractual clauses are used.

Art. 28 GDPR
Processing on behalf of a controller and contractual obligations.
Art. 32 GDPR
Security of processing.
Arts. 44 to 46 GDPR
Conditions for transfers to third countries.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.