Our Office

Calle 10 A # 34 11 Hotel Diez Categoría, office 4014

WhatsApp

+57 318 5324130

Three requirements when using Cloud Computing services

Cloud Computing

Today, companies are increasingly opting for technological solutions that offer greater efficiency and effectiveness than traditional methods. A clear example is cloud computing services, or Cloud Computing.

Through these services, a company can share hardware, software, licenses, platforms, and storage capacity with other users to obtain online data processing. This allows for greater accessibility—since it can be accessed from anywhere—and significant optimization of business processes.

However, when the information provided to the cloud computing service provider contains personal data, the contractual relationship must comply with the rules established by Colombian Habeas Data legislation.

To better understand the conditions of this relationship and the safeguards that must be provided for the information, it is important to know the parties involved:

  • The Data Controller: a natural or legal person who decides on the databases provided to the supplier.
  • The Data Processor: the cloud service provider, who receives the databases for storage, consultation, and processing.

By making this transfer, the arrangement of entrusting personal information is established, which makes the provider the Data Processor.

Therefore, to comply with Colombian regulations on personal data protection, the following requirements must be taken into account:

1. Obtain the personal data subject’s authorization

In most organizations, personal information is collected. Therefore, it is essential to follow Law 1581 of 2012 and its implementing decrees, which establish that all personal data must be processed in accordance with the company’s personal data processing policies.

The data subject must be aware of these policies, as well as the purpose for which their data will be used and the possibility that it may be provided to third parties for processing.

Having clear policies also implies complying with additional obligations, such as:

  • Registering the databases with the Superintendence of Industry and Commerce (SIC).
  • Providing privacy notices and authorizations.
  • Implementing physical, logical, and administrative security controls.

Given the complexity of the matter, it is recommended to have the support of a lawyer specialized in data protection.

2. Verify the Data Processor’s security levels

The data subject authorizes the use of their data trusting that it will be properly safeguarded. Therefore, when hiring a Cloud Computing provider, the Data Controller must ensure that the security levels offered by the provider meet the standards it applies within its own organization.

This verification is essential to ensure the confidentiality, integrity, and availability of personal information.

3. Enter into a personal information processing agreement

Once the security standards have been verified, a processing agreement for the handling of personal data must be formalized. This document must establish:

  • The procedures that will be carried out with the data.
  • The type of information to be entrusted.
  • The databases subject to processing.
  • The term of the engagement.
  • The processor’s commitments regarding the information received.

Likewise, the Data Controller must report the processing arrangement to the SIC.

When the cloud service provider is located abroad, an International Personal Data Transmission Agreement must be executed, under which the processor undertakes to:

  • Safeguarding the security of the database.
  • Comply with the principles of personal data processing.
  • Maintain confidentiality regarding the data to which it has access.

If the provider does not meet these conditions, it will be necessary to request from the Superintendence of Industry and Commerce a Declaration of Conformity authorizing the commercial relationship.

Source: Superintendence of Industry and Commerce

Scroll to Top