Hong Kong privacy regulator recognises ISO/IEC 27018

This guest post is written by @matthew1hunter and @aisling1odwyer.

Regular readers of this blog will know we have been tracking the impact of ISO/IEC 27018:2014 –Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors (ISO/IEC 27018). We see this as the go-to standard for customers of public cloud computing services.  In a significant move, the Hong Kong Privacy Commissioner for Personal Data (Privacy Commissioner) has recently recognised the value of ISO/IEC 27018 in its revised Cloud Computing Information Leaflet (Information Leaflet).

The Information Leaflet is a helpful piece of guidance which sets out the practical steps cloud customers should take to ensure they comply with the Hong Kong privacy laws when using cloud computing services.  In the leaflet the Privacy Commissioner recognises ISO/IEC 27018 as “a comprehensive reference that has met the need to assist the selection of cloud providers by data users”.

Recap on ISO/IEC 27018

We previously covered the publication ISO/IEC 27018, and also discussed how ISO/IEC 27018 would be a useful tool for customers looking to ensure compliance with privacy laws in Singapore and other countries.

We predicted regulators would begin to recognise and refer to ISO/IEC 27018 in setting privacy standards for customers of cloud computing services. Hong Kong provides the most recent example of this.  We also predicted the adoption of ISO/IEC 27018 by market-leading cloud service providers (CSPs).

Why Hong Kong and its Privacy Commissioner matter

Hong Kong was one of the early adopters of privacy laws in Asia, and has an established and well-respected privacy regime. Its Personal Data (Privacy) Ordinance (PDPO) has been in force since December 1996 and the independent Privacy Commissioner has played an active role in promoting and maintaining high privacy standards since then.

It is very significant that that Privacy Commissioner in Hong Kong has recognised the benefits of ISO/IEC 27018 in its Information Leaflet.  This endorsement sets the stage for wider recognition of ISO/IEC 27018 as the go-to international standard for protecting personal information in the cloud.

When regulators accept ISO/IEC 27018 as the global gold standard for CSPs, this makes the lives of customers, CSPs and regulators easier.  It is easier for customers and CSPs to ensure compliance with one international standard that facilitates compliance with most national-level privacy laws, rather than starting with the each of the national-level privacy laws.

Does ISO/IEC 27018 help customers in Hong Kong?

Hong Kong’s privacy laws, set out in the PDPO, place obligations on organisations in relation to the collection, processing, use and deletion of data. Organisations that wish to use cloud computing services need to assess how they can implement such services and continue to comply with the PDPO, and in particular, its six data protection principles.

The revised Information Leaflet alerts customers to their obligations under the PDPO and highlights three overarching points cloud customers should have in mind when choosing a CSP. These points are:

  1. Rapid transborder data flow: CSPs may have data centres in multiple jurisdictions and customers need to know their data will have the same level of protection wherever it is stored.
  2. Loose outsourcing arrangements: Customers need to know that any CSP sub-contractors are subject to the same standards as their CSP, and that there are legally enforceable contracts in place between the CSP and its sub-contractors.
  3. Standard services and contracts: Customers need to carefully evaluate whether their specific security and personal data privacy protection needs are met by any standard contract offered.

It is helpful then to note that the controls introduced by ISO/IEC 27018 help customers to address these points.  Taking each in turn:

  1.  CSPs are required to disclose and document where personal data will be processed and the controls in ISO/IEC 27018 are applicable no matter where the personal data is located;
  2. ISO/IEC 27018 requires CSPs to be transparent about their use of sub-contractors and enter into written agreements with any sub-contractors, preventing weak, informal outsourcing arrangements; and
  3. ISO/IEC 27018 imposes strict security standards that CSPs must adhere to, which are applicable even where the CSP and the customer are contracting on standard terms.

In summary: Hong Kong’s privacy laws impose a range of obligations on customers, some of which apply to the customer’s use of cloud computing services.  ISO/IEC 27018 is a helpful tool for customers to rely on to meet those obligations.  If a customer’s CSP commits to comply with ISO/IEC 27018, this should reassure the customer that the CPS’s solution will help the customer to comply with the relevant obligations under Hong Kong’s privacy laws.

Conclusion

The recognition of ISO/IEC 27018 by the Hong Kong regulator shows that the standard is a robust tool, capable of addressing important questions customers will have to consider when choosing a CSP.

Hong Kong now joins privacy regulators in Australia, Belgium, Canada, Germany and Slovenia (among others) who have all recognised the benefit ISO/IEC 27018 offers as a global standard for CSPs.  We anticipate that more CSPs will commit to ISO/IEC 27018 and also that more customers will look for CSPs that commit to the standard (e.g. by adding a requirement in their RFPs for CSPs to be compliant with ISO/IEC 27018).

Good news from Korea for FSI cloud customers and CSPs

A guest post by @matthew1hunter and @danieljung88

This week the Korean financial services regulator announced regulatory changes that will make it easier for financial services institutions (FSIs) in Korea to use cloud computing services.  First, FSIs will now be allowed to engage cloud service providers (CSPs) whose data hosting infrastructure is located overseas.  Second, FSIs will no longer need approval from the regulator to use cloud computing services.  Third, FSIs will no longer need to sign the regulator’s standard form contract with CSPs, so the parties can agree their own contract. 

In this post, we look at what has changed, how do the changes compare with regulations in other countries and why these changes are good news.  You should also note that this is the second of two recent steps forward for cloud computing in Korea; in April this year we posted a report on Korea’s new (and the world’s first) cloud-specific law.

What has changed?

The Financial Services Commission (FSC) and the Financial Services Supervisor (FSS) announced in a joint press release (on the 9 June 2015) revisions to the Regulation on Financial Institutions’ Outsourcing of Data Processing Business & IT Facilities (dated June 2013) (the Regulation).  The FSC stated that with these changes it “intends to reduce financial institutions’ burden relating with outsourcing of data processing”.

There are four changes:

  1. FSIs will be allowed to offshore data processing to a professional IT company whose infrastructure is located outside of Korea.
  1. FSIs will no longer be required to obtain the approval from the FSC in order to outsource IT facilities.
  1. FSIs will be allowed to outsource their data processing without notifying all the information to the FSS prior to outsourcing data processing.  Instead they can report the outsourcing after the event to the FSS.  FSIs will only be required to notify an outsourcing in advance to the FSS if customers’ financial transaction information will be outsourced.
  1. FSIs will no longer be required to sign the standard form contract when contracting with CSPs, as long as the contract includes the regulatory requirements (e.g. obligations to permit the regulator to supervise and inspect the CSP).

How do the Korean regulations compare now to those in other countries?

These changes bring the Korean regime more into line with the regimes in many other countries in the Asia-Pacific region, including Singapore, New Zealand, Australia, Hong Kong and Japan.

For more information on the regulations that impact the use of cloud computing by FSIs in the Asia-Pacific region, see our report, published with the Asia Cloud Computing Association (the ACCA Report).

These changes also bring the Korean regime into line with the recommendations made in the ACCA Report.  The report sets out recommendations to regulators.  The aim of the recommendations is to make it easier for FSIs to use cloud computing services.  The ACCA Report states that regulators should: allow the use by FSIs of offshore CSPs; not require FSIs to obtain approval for the use of cloud computing services; and not be prescriptive about the content of contracts between FSIs and CSPs.  Korea now scores well against these recommendations and the report will be updated in the next version.

Why are these changes good news for FSIs and CSPs?

  • These changes will make it easier for FSIs in Korea to use cloud computing services.  FSIs around the world are benefiting from cloud computing services.  The services offer many benefits to FSIs, including security, agility, reliability, scalability and (not to forget) potential cost savings. Korean FSIs should and now will be able to benefit in the same way as FSIs in other countries.
  • These changes will help domestic FSIs in Korea to compete more evenly with international FSIs. Before now, international FSIs could transfer data to their other locations around the world for processing.  Domestic FSIs were unable to enjoy the benefits of offshore service providers.  Now all FSIs can transfer data offshore, to other branches (for international FSIs) and to IT service providers, including CSPs.
  • These changes should make it easier in the future for other cloud customers in Korea (not just FSIs) to use cloud computing services. The FSI sector is generally recognized as a heavy user of IT services and this activity is heavily regulated.  Potential cloud customers in other sectors may look towards the FSI sector for a lead.  The more the FSI sector opens up to the use of cloud, the more other sectors are likely to follow.
  • These changes may influence other regulators in the region to take similar approaches. Regulators talk, and they watch one another.  There has been plenty of discussion about increased rules on data sovereignty.   In these discussions it is helpful to be able to point to regulators, like the FSC in Korea, that allow international transfers of data.  The focus should not be on the location of the data, but always on whether or not the data is adequately protected.  The more markets that follow this lead, the better.
  • The changes will increase and improve competition in the Korean CSP market.  International CSPs will be able to compete to provide services to FSI cloud customers in Korea, where they were previously unable to.  CSPs who were reluctant to enter into the Korean market, may now be persuaded to do so.  We believe that increased competition is healthy for customers and between competitors.

We believe this is a good step forward for the cloud computing market in Korea.  We hope that more regulators will follow suit.  We will keep you posted on further developments.

Korea leads the world with cloud law encouraging cloud use

On 3rd March 2015, Korea passed the world’s first cloud-specific law, with the stated aim of driving the adoption of cloud computing in Korea. But what are the practical implications for cloud customers and cloud services providers in Korea?

Data centre (wikicommons)

 

This guest post is written by Daniel Jung and @matthew1hunter.

When does the Korean Cloud Act come into force?

On 3 March 2015, the Korean National Assembly passed the Act on the Development of Cloud Computing and Protection of Users (Korean Cloud Act).  The bill has been under consideration since October 2013.  The final version of the Korean Cloud Act is available here (currently only available in Korean).

The Korean Cloud Act comes into force on 28th September 2015.  Before the Korean Cloud Act comes into force, the Ministry of Science, ICT and Future Planning (Ministry) will establish additional rules for cloud services (as explained below).

What will the Korean Cloud Act do?

The good news for cloud customers and cloud services providers alike is that the Cloud Act aims to promote the cloud market in Korea.

The Korean government sees cloud computing market as a vital industry for future IT development and intends to build a solid foundation to raise Korea’s global competitiveness in the industry.

The Korean Cloud Act aims to do this by:

  1. boosting investment and support in the cloud market, in particular by the government;
  2. permitting (and encouraging) the use of cloud services (including public cloud services) by public institutions; and
  3. placing appropriate safeguards on cloud services providers (CSPs).

Taking these three points in turn:

1. Korea is going to invest time and effort in enhancing the cloud market.

The Korean government is keen to boost its investment in the cloud market.  In this respect, under the Korean Cloud Act, the Ministry is to establish plans (and update them every three years) to enhance the cloud market.  This will include: setting out plans for the development of the cloud computing market; cloud computing related research and expert training; financial and other support for local SMEs providing cloud services and ancillary services, establishing pilot projects, tax incentives and collaboration with other countries.

2. Public institutions in Korea can and should use cloud services.

The Korean Cloud Act encourages public institutions to implement cloud services as a priority, in order to benefit from cost efficiency, improving productivity and industrial competitiveness.  In order to assist with this encouragement, the Korean Cloud Act permits the use of cloud services by public institutions.

 3. The bar for protecting customers’ information has been raised – and cloud customers should expect their CSPs to comply.

Security and privacy issues have always been perceived as being the main roadblocks to the use of cloud services.  To address this the Korean Cloud Act imposes certain obligations on CSPs to try to remove the roadblocks and drive the use of cloud services in a way that addresses security and privacy concerns. In practical terms, CSPs have some new obligations to comply with, and cloud customers will want to look for CSPs who can meet these requirements. In particular, CSPs should note the following important points (and consider their compliance levels):

  •  CSPs must report information leakage to their customers and the Minister.  An investigation may then follow.
  • CSPs must not provide their customers’ information to a third party or use it for purposes other than the designated purpose without the consent.
  • CSPs must return or delete the relevant customer’s information upon termination of the relevant cloud contract.
  • If a CSP hosts a customer’s information outside of Korea, the customer may request the CSP to disclose the location.
  • If a customer incurs losses due to the deliberate or negligent acts of a CSP which violate the Cloud Act, the customer may bring a claim for compensation against the CSP.  The onus will be on the CSP to prove that the CSP’s act was not deliberate or negligent.
  • The Minister will establish additional obligations that cover the quality/capability of cloud services, appropriate service levels and standards for information protection.  It is anticipated that a cloud services certification system will be implemented.
  • A standardised contract for use when providing cloud services is also anticipated.

The Korean Cloud Act has teeth

Any person who uses or discloses a customer’s information to a third party without consent shall be punished by imprisonment for not more than 5 years or with a fine not exceeding KRW 50 million (about USD 46,500).  Slightly reduced levels of fines will apply to breaches of the other obligations listed above.

Areas not currently addressed by the Korean Cloud Act

The Korean Cloud Act doesn’t deal with data classification.  One of the perceived hurdles, in particular for public institutions, to using cloud services, is the ability to determine what categories of data can be hosted by CSPs.  There are different ways of categorizing data and clear guidelines on the subject help to overcome this hurdle.  This is an area that may be considered in the future. Nonetheless, the clear endorsement of cloud services in the Korean Cloud Act will likely be sufficient evidence for most that the Ministry considers that cloud is appropriate for the vast majority of data held by public institutions.

The Korean Cloud Act doesn’t address the limits imposed by other (quite strict) regulations in Korea.  For example, the financial services sector is subject to strict regulations that are potentially delaying the adoption of cloud services in the sector. CSPs and cloud customers alike will be hoping that this clear endorsement of cloud will drive regulatory change in other sectors.

The Korean Cloud Act states that the Personal Information Protection Act (PIPA) will continue to apply in regard to personal data.  However, as the Ministry develops further plans and regulations, the obligations in the Cloud Act will sit alongside those in the PIPA and will likely add a layer of additional requirements (although the focus of these additional obligations will be CSPs).

The Korean Cloud Act doesn’t, as yet, point to any particular international standards.  In other countries, authorities point to international standards (e.g. ISO/IEC 27001 and ISO/IEC 27018) as appropriate measures to assess CSPs i.e. does the CSP comply with these standards.  It’s interesting to note that the controls in the new international standard for public cloud services, ISO/IEC 27018, appears to meet many of the new requirements included in the Cloud Act (and goes further than many of them), so CSPs who comply with ISO/IEC 27018 will not have any trouble complying with the new Cloud Act requirements.

What next?  

CSPs should consider their levels of compliance and cloud customers in Korea should, as a matter of good practice whenever they procure or use cloud services, ask their CSP how their solution complies with the Korean Cloud Act. Reputable CSPs should have no problems providing a satisfactory response to customer questions about the Korean Cloud Act.

In addition, CSPs and customers alike should wait for further updates from the Ministry on the plans to support the cloud market and the plans for further obligations/requirements in relation to cloud services.

Financial technology, cloud, mobile data and social networking will drive deals and valuation multiples in technology sector

As a new blogger, site statistics are a source of endless fascination.  They are however useful – my post on TMT valuation multiples seems to have been wildly popular, so I thought it worthwhile to trawl through some other reports to see what commentators were predicting.

PwC‘s technology insight presentation caught my eye.  It is a perceptive commentary on M&A trends in the technology sector, not only identifying hot areas, but also the drivers behind those hot-spots.

The first area identified is financial technology, with ongoing regulatory scrutiny and change within the banking vertical driving demand for integrated software and outsourced platforms. They highlight the Misys acquisition of Sophis as an example of this type of deal.

The second area is cloud services and the various activities within that space such as hosting, virtualisation and security. Reinforcing the theme of my last post, PwC sees relatively high valuation multiples for deals in this segment.

The third area is mobile data, which again is something of a recurring theme for this blog. The sub-segments highlighted include applications, gaming and advertising – all of which I agree with based on the recent deals we have seen.

I am less convinced with their last identified area – that of the public sector. As a result of the cuts in the UK, overall revenues are likely to fall so I would see deal activity being primarily defensive and with somewhat depressed valuations as compared to other segments.

Finishing with a personal view on another hot-spots for the year,  one segment that I think will be very hot is social media, with both IPOs for the large players possible, and also mid-market deal activity as the larger players acquire smaller players for capabilities to integrate into their platforms.