Cloud and data sovereignty caught in a paradox | Computer Weekly

General News

Summary

The piece investigates how US-based hyperscaler cloud providers may be incompatible with data sovereignty because US legal instruments (Cloud Act, FISA) can compel access to overseas data and technical assistance. It finds vendor responses avoided core technical issues and highlights risks such as court-ordered compiled updates, data-in-use vulnerabilities, and routine cross-border data transit in standard terms. The article warns customers must opt out of standard cloud terms, use air-gapped services, or accept residual risk, noting no approach is 100% proof against intrusion. It emphasizes the urgency for the UK public sector, which heavily relies on US hyperscalers, and notes gaps such as DSIT lacking a clear definition of data sovereignty.

Classifications

industries
Entertainment
applications
Accounting and Taxes

AskAI Classifications

Labels
Enterprise Software SaaS Data Streaming Platforms

Linked Companies

IBM
$1B+
Oracle
$1B+
Amazon
$1B+
Google LLC
$100M to $250M
Microsoft
$1B+