SlideShare a Scribd company logo
1 of 19
Lou Milrad B.A., LL.B.
Lawyer
MilradLaw
Cloud Computing –
Moving Forward
March 26th, 2013
Burlington Convention Centre
This presentation illustrates a sampling of issues relating to
cloud service contracts while also providing discussion
insights on such issues and is intended to be merely
Illustrative, rather than conclusive, of the complexity of those
issues.
The model under discussion assumes that your Municipality
will be negotiating a cloud services contract and that the
expectation is that some sensitive and private data will be
stored on cloud-based data servers belonging to either the
cloud provider or to a business partner of that provider. In
addition, your Municipality is in the final stages of launching a
BYOD (Bring Your Own Device) policy.
 In shifting away from the traditional infrastructure approach of
separately (or in combination) purchasing hardware, software and
services to complete services solution (SaaS, IaaS, PaaS, (MaaS,
SaaS, etc.), critical need to focus on
 IT contracting strategy, and
 Associated contract terms & conditions
 Legal issues have become somewhat more complex
 Many are traditional (e.g. IT outsourcing and similar managed
services arrangements), but many are new and unique to or
exacerbated by migration to the cloud.
 Typically governed by total $$$ to be spent coupled
with supplier target market and industry standard
practices.
 Try to avoid web-based terms and conditions
approach – exception may only be in “free” services
 However, “free” might change to “paid for” services
model if volume or usage thresholds are exceed
 Cautions -
 Automatic term renewals
 Incorporation of web-terms into negotiated
contracts
Clou
 Web-based vs. negotiated terms
 Governing Law
 Data Availability and Term and Renewals
 Additionally referenced terms & unilateral amendments, Statements of Work (SOW’s), & Service level agreements (SLA’s)
 Intellectual property rights (IPR)
 Confidential information (Confidentiality) and Trade Secrets
 Privacy
 Force majeure
 Geographic Location of Data Servers
 Third party access
 Indemnification & insurance suspension & Termination
 Suppliers’ compliance requirements
 Grounds for Contract Termination
 Liability of Damages due to a Service Interruption
 Having an Exit Strategy
 Grounds for Contract Termination
 Data retention upon contract termination
Boilerplate examples for discussion
 Contract Structure
 Governing Law
 Term and Renewals
 Data Availability and Ownership
 Intellectual Property Rights (IPR)
 Confidential Information
 Privacy
 Force Majeure
AND
 Data Availability and Ownership
Terms and Conditions
Full of legalese
Once signed, becomes the governing terms and
conditions
Amending Agreement to change terms
Schedules
Specifications
Pricing and Payment, etc.
Statements of Work (SOW’s)
Service Level Agreements (SLA’s)
 What law governs performance under the contract terms?
 Complex legal regulatory environment surrounding cloud computing
that both customers and providers need to consider.
 e.g. Privacy statutes
 Provision is typically found in the Boilerplate section of the contract (i.e.
- towards the end of the T’s & C’s)
 Typically, vendor’s form contract
• Good place to start and build on
 will specify that it is governed by the law of the vendor’s home
province/state, and
 grant the courts of that province/state exclusive jurisdiction over
any disputes arising out of the contract
 3 Key aspects – Applicable law & jurisdiction/location
 Contract interpretation
 Location for Hearing(s)/Trial(s)
 Resolution through mediation & arbitration
 Options
 Mutual agreement on these items
 Leave unresolved and open for later argument and resolution
(if needed)
 Vendor form contracts typically
 Renew automatically for additional terms unless proper prior
notice
 Not really major concern in the context of “free” services, but
could be problematic under a ”pay for services” automatic
renewal contract where the customer has not tracked the
advance notice of “intention to not to renew” date… and it
slips by
 Auto renewal avoids the need to renegotiate the
contract, but…
 Consideration for negotiating “termination for convenience”
provisions
 Avoid additionally referenced terms & unilateral amendments -
 Provide the vendor with the unilateral right, to make
modifications to its services – a negotiated
compromise might be something like:
 “Vendor may make commercially reasonable
modifications to the Service, provided that they do
not materially diminish the nature, scope, or quality
of the Service.
 Prerequisite for consideration:
 Understanding of the system architecture
 e.g. - How and in what format it keeps your data
 Tools that are available to you to access your data
 Covering off on e-discovery needs that may arise
 Remain mindful of compliance with enterprise-wide policies (existing &
under consideration/development) - AUP, MDM, BYOD, etc.
 Additional Requirements
 Redundancy and backup
 Disaster recovery
 No vendor lock-in
 Exit strategies as required
 Protection of all designated confidential information and other intellectual property
rights
 Confirmation that the vendor does not acquire and may not claim any security
interest in your data.
 Where does Open Data fit in?
 IP categories include
 Copyrights, Trademarks, Trade secrets (Confidential Information) Data
 IP Assets & Treatment under
 Canadian laws
 Laws of other countries
 Infringement – what remedies?
 Third party access – is vendor intending to grant some privileged third parties access to
your Municipality's stored data
 Who is that to be
 What is approval and authorization procedure?
 Is there to be a confidential disclosure agreement and what form is it to take?
 Protecting “personal information” and IPR
 Defining Characteristics of Confidential Information: Typically includes intangible assets (and
associated materials) such as trade secrets, designs, processes, programs, procedures, third party
Information, developments, disclosed under terms of a software license or services agreement
 Examples might include, nonpublic and financial contract terms with other suppliers, and
categories set out under MFIPPA
 Negotiated cloud contracts will typically define, spell out, the restrictions, and remedies for
unauthorized disclosure or other violation – Web-based, less likely to address question although
it may be included under Intellectual Property Rights language
 Breach of Confidentiality: Legal obligation of employees to respect the organization’s intangible
assets, business and trade secrets etc. and maintain their confidentiality both during and after term of
employment
 Confidentiality & Non-Disclosure Agreements (NDA’s) might precede contract negotiation, and in
any event, negotiate contracts will contain associated obligations and restrictions regarding
confidentiality
 Key consideration: Notwithstanding vendors adherence to best practices, what happens if the data
center gets hacked? Is there a remedy, and if so, what is it to be?
 Canada has two federal privacy laws
 the Privacy Act and the Personal Information Protection and Electronic Documents Act. …
 Every province and territory has privacy legislation governing the collection, use and disclosure of
personal information held by government agencies – Office of The Privacy Commissioner of Canada
 Ontario’s
 MFIPPA Municipal Freedom of Information and Protection of Privacy Act, &
 PHIPA - the Personal Health Information Protection Act
 Onus on Municipalities and their suppliers to protect “personal information” from disclosure
 Challenge to be considered - the trusteeship by the Municipality of personal information coupled with
possible access, handling and disclosure of personal information of others stored on external cloud
servers.
 BYOD and Cloud access - Makings of a perfect storm with the convergence on one device of both
personal and corporate data and providing access to cloud based data and databases – therefore, a
critical need to have an enforceable BYOD policy in place.
Others
Our systems are vulnerable to damage or interruption
from earthquakes, terrorist attacks, floods, fires, power
loss, telecommunications failures, computer viruses,
computer denial of service attacks, or other attempts to
harm our systems.
Thank You
Lou Milrad
IT Lawyer
Milrad Law Office
lou@milrad.ca
647.982.7890
www.milradlaw.ca
Cloud Computing Contract Issues

More Related Content

What's hot

Cloud computing contracts
Cloud computing contractsCloud computing contracts
Cloud computing contractsMeera Kaul
 
Common Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsCommon Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsMatheson Law Firm
 
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)AltheimPrivacy
 
Cybersecurity and Data Privacy Update
Cybersecurity and Data Privacy UpdateCybersecurity and Data Privacy Update
Cybersecurity and Data Privacy UpdateWilmerHale
 
Cloud Computing: Legal Issues and Safety Risks by Brian Miller Solicitor
Cloud Computing:  Legal Issues and Safety Risks by Brian Miller SolicitorCloud Computing:  Legal Issues and Safety Risks by Brian Miller Solicitor
Cloud Computing: Legal Issues and Safety Risks by Brian Miller SolicitorBrian Miller, Solicitor
 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa complianceTrustArc
 
Sookman law society_6_min_business_law
Sookman law society_6_min_business_lawSookman law society_6_min_business_law
Sookman law society_6_min_business_lawbsookman
 
Understanding Binding Corporate Rules
Understanding Binding Corporate RulesUnderstanding Binding Corporate Rules
Understanding Binding Corporate RulesJan Dhont
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceTinuiti
 
Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0David Spinks
 
Cloud Computing: legal issues
Cloud Computing: legal issuesCloud Computing: legal issues
Cloud Computing: legal issuesISPABelgium
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesTech Trust
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsUlf Mattsson
 
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec
 
GDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projectsGDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projectsLorenzo Mannella
 
Legal ethics & cloud computing
Legal ethics & cloud computingLegal ethics & cloud computing
Legal ethics & cloud computingPatrick Fowler
 

What's hot (20)

GDPR - 5 Months On!
GDPR - 5 Months On!GDPR - 5 Months On!
GDPR - 5 Months On!
 
Cloud computing contracts
Cloud computing contractsCloud computing contracts
Cloud computing contracts
 
Common Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A DealsCommon Data Protection Issues in Managing M&A Deals
Common Data Protection Issues in Managing M&A Deals
 
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)
Security and Privacy in Deals (altheim & mahajan)(6-3 -2015)
 
Cybersecurity and Data Privacy Update
Cybersecurity and Data Privacy UpdateCybersecurity and Data Privacy Update
Cybersecurity and Data Privacy Update
 
Cloud Computing: Legal Issues and Safety Risks by Brian Miller Solicitor
Cloud Computing:  Legal Issues and Safety Risks by Brian Miller SolicitorCloud Computing:  Legal Issues and Safety Risks by Brian Miller Solicitor
Cloud Computing: Legal Issues and Safety Risks by Brian Miller Solicitor
 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance
 
Sookman law society_6_min_business_law
Sookman law society_6_min_business_lawSookman law society_6_min_business_law
Sookman law society_6_min_business_law
 
Understanding Binding Corporate Rules
Understanding Binding Corporate RulesUnderstanding Binding Corporate Rules
Understanding Binding Corporate Rules
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to Compliance
 
Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0Legal And Regulatory Issues Cloud Computing...V2.0
Legal And Regulatory Issues Cloud Computing...V2.0
 
Cloud Computing: legal issues
Cloud Computing: legal issuesCloud Computing: legal issues
Cloud Computing: legal issues
 
NetSquared London - GDPR for charities
NetSquared London - GDPR for charitiesNetSquared London - GDPR for charities
NetSquared London - GDPR for charities
 
New opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulationsNew opportunities and business risks with evolving privacy regulations
New opportunities and business risks with evolving privacy regulations
 
Binding corporate rules
Binding corporate rulesBinding corporate rules
Binding corporate rules
 
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
 
CHAPTER 10A The Imposition of Sales Tax on Computer Software
CHAPTER 10A The Imposition of Sales Tax on Computer SoftwareCHAPTER 10A The Imposition of Sales Tax on Computer Software
CHAPTER 10A The Imposition of Sales Tax on Computer Software
 
GDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projectsGDPR and personal data protection in EU research projects
GDPR and personal data protection in EU research projects
 
Engagement and Consumer Law
Engagement and Consumer LawEngagement and Consumer Law
Engagement and Consumer Law
 
Legal ethics & cloud computing
Legal ethics & cloud computingLegal ethics & cloud computing
Legal ethics & cloud computing
 

Viewers also liked

Cloud Computing presentation by Lisa Abe at the Canadian IT Lawyers Associat...
Cloud Computing  presentation by Lisa Abe at the Canadian IT Lawyers Associat...Cloud Computing  presentation by Lisa Abe at the Canadian IT Lawyers Associat...
Cloud Computing presentation by Lisa Abe at the Canadian IT Lawyers Associat...lisaabe
 
Intellectual property
Intellectual property Intellectual property
Intellectual property Accuprosys
 
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30This account is closed
 
Cloud Computing Legal Risks And Best Practices
Cloud Computing Legal Risks And Best PracticesCloud Computing Legal Risks And Best Practices
Cloud Computing Legal Risks And Best Practiceslisaabe
 
Overcoming the Challenges of Integration: The Legal Issues
Overcoming the Challenges of Integration: The Legal IssuesOvercoming the Challenges of Integration: The Legal Issues
Overcoming the Challenges of Integration: The Legal Issueslisaabe
 
Cloud computing & service level agreements
Cloud computing & service level agreementsCloud computing & service level agreements
Cloud computing & service level agreementsCade Zvavanjanja
 

Viewers also liked (6)

Cloud Computing presentation by Lisa Abe at the Canadian IT Lawyers Associat...
Cloud Computing  presentation by Lisa Abe at the Canadian IT Lawyers Associat...Cloud Computing  presentation by Lisa Abe at the Canadian IT Lawyers Associat...
Cloud Computing presentation by Lisa Abe at the Canadian IT Lawyers Associat...
 
Intellectual property
Intellectual property Intellectual property
Intellectual property
 
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
The Cloud Computing Contract Playbook - Contracting for Cloud Services, Sept. 30
 
Cloud Computing Legal Risks And Best Practices
Cloud Computing Legal Risks And Best PracticesCloud Computing Legal Risks And Best Practices
Cloud Computing Legal Risks And Best Practices
 
Overcoming the Challenges of Integration: The Legal Issues
Overcoming the Challenges of Integration: The Legal IssuesOvercoming the Challenges of Integration: The Legal Issues
Overcoming the Challenges of Integration: The Legal Issues
 
Cloud computing & service level agreements
Cloud computing & service level agreementsCloud computing & service level agreements
Cloud computing & service level agreements
 

Similar to Cloud Computing Contract Issues

C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110guestd7fc9c
 
Legal issues in cloud computing
Legal issues in cloud computingLegal issues in cloud computing
Legal issues in cloud computingmovinghats
 
Procurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesProcurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesPeister
 
Cloud Computing & IT in the Boardroom
Cloud Computing & IT in the BoardroomCloud Computing & IT in the Boardroom
Cloud Computing & IT in the BoardroomBrendon Noney
 
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')DLA Piper Nederland N.V.
 
The ugly, the bad and the good of cloud computing
The ugly, the bad and the good of cloud computingThe ugly, the bad and the good of cloud computing
The ugly, the bad and the good of cloud computingDan Michaluk
 
Cloud computing and Law-India legal summit
Cloud computing and Law-India legal summitCloud computing and Law-India legal summit
Cloud computing and Law-India legal summitAdv Prashant Mali
 
Cloud computing and law-India legal summit 2011
Cloud computing and law-India legal summit 2011Cloud computing and law-India legal summit 2011
Cloud computing and law-India legal summit 2011Adv Prashant Mali
 
TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...
TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...
TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...Jan Lindberg
 
Cloud Security And Cyber Security Legal And Regulatory Hp Version V 2.1
Cloud Security And Cyber Security Legal And Regulatory  Hp Version V 2.1Cloud Security And Cyber Security Legal And Regulatory  Hp Version V 2.1
Cloud Security And Cyber Security Legal And Regulatory Hp Version V 2.1David Spinks
 
Cloud Services As An Enabler: The Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: The Strategic, Legal & Pragmatic ApproachCloud Services As An Enabler: The Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: The Strategic, Legal & Pragmatic ApproachSLA-Ready Network
 
Cloud Services As An Enabler
Cloud Services As An EnablerCloud Services As An Enabler
Cloud Services As An EnablerSLA-Ready Network
 
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009 Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009 EuroCloud
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015Jan Dhont
 
Securing data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law FirmsSecuring data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law FirmsCloudMask inc.
 
Cloud Information Accountability Frameworks for Data Sharing in Cloud
Cloud Information Accountability Frameworks for Data Sharing in CloudCloud Information Accountability Frameworks for Data Sharing in Cloud
Cloud Information Accountability Frameworks for Data Sharing in CloudIOSR Journals
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationIBM Security
 
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...Tom Kulik
 
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...Oliver Barreto Rodríguez
 

Similar to Cloud Computing Contract Issues (20)

C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
 
Legal issues in cloud computing
Legal issues in cloud computingLegal issues in cloud computing
Legal issues in cloud computing
 
Procurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesProcurement Of Software And Information Technology Services
Procurement Of Software And Information Technology Services
 
Cloud Computing & IT in the Boardroom
Cloud Computing & IT in the BoardroomCloud Computing & IT in the Boardroom
Cloud Computing & IT in the Boardroom
 
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
Cloud computing: 'everything you always wanted to know (but were aftaid to ask')
 
The ugly, the bad and the good of cloud computing
The ugly, the bad and the good of cloud computingThe ugly, the bad and the good of cloud computing
The ugly, the bad and the good of cloud computing
 
Cloud computing and Law-India legal summit
Cloud computing and Law-India legal summitCloud computing and Law-India legal summit
Cloud computing and Law-India legal summit
 
Cloud computing and law-India legal summit 2011
Cloud computing and law-India legal summit 2011Cloud computing and law-India legal summit 2011
Cloud computing and law-India legal summit 2011
 
TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...
TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...
TRUST. IP and Technology Update - IT Audit Toolkit for CIOs and General Couns...
 
Cloud Security And Cyber Security Legal And Regulatory Hp Version V 2.1
Cloud Security And Cyber Security Legal And Regulatory  Hp Version V 2.1Cloud Security And Cyber Security Legal And Regulatory  Hp Version V 2.1
Cloud Security And Cyber Security Legal And Regulatory Hp Version V 2.1
 
Cloud Services As An Enabler: The Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: The Strategic, Legal & Pragmatic ApproachCloud Services As An Enabler: The Strategic, Legal & Pragmatic Approach
Cloud Services As An Enabler: The Strategic, Legal & Pragmatic Approach
 
Cloud Services As An Enabler
Cloud Services As An EnablerCloud Services As An Enabler
Cloud Services As An Enabler
 
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009 Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
Carla Pinheiro Presentation / CloudViews.Org - Cloud Computing Conference 2009
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
 
Securing data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law FirmsSecuring data in the cloud: A challenge for UK Law Firms
Securing data in the cloud: A challenge for UK Law Firms
 
Law 302
Law 302Law 302
Law 302
 
Cloud Information Accountability Frameworks for Data Sharing in Cloud
Cloud Information Accountability Frameworks for Data Sharing in CloudCloud Information Accountability Frameworks for Data Sharing in Cloud
Cloud Information Accountability Frameworks for Data Sharing in Cloud
 
How IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity LegislationHow IBM Supports Clients around GDPR and Cybersecurity Legislation
How IBM Supports Clients around GDPR and Cybersecurity Legislation
 
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
Partly Sunny With a Chance of Rain: Forecasting the Legal Issues in Cloud Com...
 
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
 

More from Lou Milrad

Lou's cips tips
Lou's cips tipsLou's cips tips
Lou's cips tipsLou Milrad
 
Harnessing Open Data as a Tool for Municipal Investment Attraction
Harnessing Open Data as a Tool for Municipal Investment  AttractionHarnessing Open Data as a Tool for Municipal Investment  Attraction
Harnessing Open Data as a Tool for Municipal Investment AttractionLou Milrad
 
Open Data - Legal Framework & Municipal Economic Development Opportunities
Open Data - Legal Framework & Municipal Economic Development OpportunitiesOpen Data - Legal Framework & Municipal Economic Development Opportunities
Open Data - Legal Framework & Municipal Economic Development OpportunitiesLou Milrad
 
Milrad open data presentation nov. 2014
Milrad open data presentation nov. 2014Milrad open data presentation nov. 2014
Milrad open data presentation nov. 2014Lou Milrad
 
The CIO and professionalism A legal perspective on the value of IT industry a...
The CIO and professionalism A legal perspective on the value of IT industry a...The CIO and professionalism A legal perspective on the value of IT industry a...
The CIO and professionalism A legal perspective on the value of IT industry a...Lou Milrad
 
10 Legal Challenges in Creating a BYOD Policy - Lou Milrad
10 Legal Challenges in Creating a BYOD Policy - Lou Milrad10 Legal Challenges in Creating a BYOD Policy - Lou Milrad
10 Legal Challenges in Creating a BYOD Policy - Lou MilradLou Milrad
 
Professionalism, Ethics, IT & the Law - CIPS Ontario
Professionalism, Ethics, IT & the Law - CIPS OntarioProfessionalism, Ethics, IT & the Law - CIPS Ontario
Professionalism, Ethics, IT & the Law - CIPS OntarioLou Milrad
 
Public-Private Partnerships - Business & Legal Issues
Public-Private Partnerships - Business & Legal IssuesPublic-Private Partnerships - Business & Legal Issues
Public-Private Partnerships - Business & Legal IssuesLou Milrad
 
Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...
Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...
Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...Lou Milrad
 
Ownership rights in map products - an Intellectual Property perspective.
Ownership rights in map products - an Intellectual Property perspective.Ownership rights in map products - an Intellectual Property perspective.
Ownership rights in map products - an Intellectual Property perspective.Lou Milrad
 

More from Lou Milrad (10)

Lou's cips tips
Lou's cips tipsLou's cips tips
Lou's cips tips
 
Harnessing Open Data as a Tool for Municipal Investment Attraction
Harnessing Open Data as a Tool for Municipal Investment  AttractionHarnessing Open Data as a Tool for Municipal Investment  Attraction
Harnessing Open Data as a Tool for Municipal Investment Attraction
 
Open Data - Legal Framework & Municipal Economic Development Opportunities
Open Data - Legal Framework & Municipal Economic Development OpportunitiesOpen Data - Legal Framework & Municipal Economic Development Opportunities
Open Data - Legal Framework & Municipal Economic Development Opportunities
 
Milrad open data presentation nov. 2014
Milrad open data presentation nov. 2014Milrad open data presentation nov. 2014
Milrad open data presentation nov. 2014
 
The CIO and professionalism A legal perspective on the value of IT industry a...
The CIO and professionalism A legal perspective on the value of IT industry a...The CIO and professionalism A legal perspective on the value of IT industry a...
The CIO and professionalism A legal perspective on the value of IT industry a...
 
10 Legal Challenges in Creating a BYOD Policy - Lou Milrad
10 Legal Challenges in Creating a BYOD Policy - Lou Milrad10 Legal Challenges in Creating a BYOD Policy - Lou Milrad
10 Legal Challenges in Creating a BYOD Policy - Lou Milrad
 
Professionalism, Ethics, IT & the Law - CIPS Ontario
Professionalism, Ethics, IT & the Law - CIPS OntarioProfessionalism, Ethics, IT & the Law - CIPS Ontario
Professionalism, Ethics, IT & the Law - CIPS Ontario
 
Public-Private Partnerships - Business & Legal Issues
Public-Private Partnerships - Business & Legal IssuesPublic-Private Partnerships - Business & Legal Issues
Public-Private Partnerships - Business & Legal Issues
 
Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...
Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...
Open Data Solutions - Managing the Risk & Economic Development - 2012 AMCTO O...
 
Ownership rights in map products - an Intellectual Property perspective.
Ownership rights in map products - an Intellectual Property perspective.Ownership rights in map products - an Intellectual Property perspective.
Ownership rights in map products - an Intellectual Property perspective.
 

Recently uploaded

DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 

Recently uploaded (20)

DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 

Cloud Computing Contract Issues

  • 1. Lou Milrad B.A., LL.B. Lawyer MilradLaw Cloud Computing – Moving Forward March 26th, 2013 Burlington Convention Centre
  • 2. This presentation illustrates a sampling of issues relating to cloud service contracts while also providing discussion insights on such issues and is intended to be merely Illustrative, rather than conclusive, of the complexity of those issues. The model under discussion assumes that your Municipality will be negotiating a cloud services contract and that the expectation is that some sensitive and private data will be stored on cloud-based data servers belonging to either the cloud provider or to a business partner of that provider. In addition, your Municipality is in the final stages of launching a BYOD (Bring Your Own Device) policy.
  • 3.  In shifting away from the traditional infrastructure approach of separately (or in combination) purchasing hardware, software and services to complete services solution (SaaS, IaaS, PaaS, (MaaS, SaaS, etc.), critical need to focus on  IT contracting strategy, and  Associated contract terms & conditions  Legal issues have become somewhat more complex  Many are traditional (e.g. IT outsourcing and similar managed services arrangements), but many are new and unique to or exacerbated by migration to the cloud.
  • 4.  Typically governed by total $$$ to be spent coupled with supplier target market and industry standard practices.  Try to avoid web-based terms and conditions approach – exception may only be in “free” services  However, “free” might change to “paid for” services model if volume or usage thresholds are exceed  Cautions -  Automatic term renewals  Incorporation of web-terms into negotiated contracts
  • 5. Clou  Web-based vs. negotiated terms  Governing Law  Data Availability and Term and Renewals  Additionally referenced terms & unilateral amendments, Statements of Work (SOW’s), & Service level agreements (SLA’s)  Intellectual property rights (IPR)  Confidential information (Confidentiality) and Trade Secrets  Privacy  Force majeure  Geographic Location of Data Servers  Third party access  Indemnification & insurance suspension & Termination  Suppliers’ compliance requirements  Grounds for Contract Termination  Liability of Damages due to a Service Interruption  Having an Exit Strategy  Grounds for Contract Termination  Data retention upon contract termination
  • 6. Boilerplate examples for discussion  Contract Structure  Governing Law  Term and Renewals  Data Availability and Ownership  Intellectual Property Rights (IPR)  Confidential Information  Privacy  Force Majeure AND  Data Availability and Ownership
  • 7. Terms and Conditions Full of legalese Once signed, becomes the governing terms and conditions Amending Agreement to change terms Schedules Specifications Pricing and Payment, etc. Statements of Work (SOW’s) Service Level Agreements (SLA’s)
  • 8.  What law governs performance under the contract terms?  Complex legal regulatory environment surrounding cloud computing that both customers and providers need to consider.  e.g. Privacy statutes  Provision is typically found in the Boilerplate section of the contract (i.e. - towards the end of the T’s & C’s)  Typically, vendor’s form contract • Good place to start and build on  will specify that it is governed by the law of the vendor’s home province/state, and  grant the courts of that province/state exclusive jurisdiction over any disputes arising out of the contract
  • 9.  3 Key aspects – Applicable law & jurisdiction/location  Contract interpretation  Location for Hearing(s)/Trial(s)  Resolution through mediation & arbitration  Options  Mutual agreement on these items  Leave unresolved and open for later argument and resolution (if needed)
  • 10.  Vendor form contracts typically  Renew automatically for additional terms unless proper prior notice  Not really major concern in the context of “free” services, but could be problematic under a ”pay for services” automatic renewal contract where the customer has not tracked the advance notice of “intention to not to renew” date… and it slips by  Auto renewal avoids the need to renegotiate the contract, but…  Consideration for negotiating “termination for convenience” provisions  Avoid additionally referenced terms & unilateral amendments -
  • 11.  Provide the vendor with the unilateral right, to make modifications to its services – a negotiated compromise might be something like:  “Vendor may make commercially reasonable modifications to the Service, provided that they do not materially diminish the nature, scope, or quality of the Service.
  • 12.  Prerequisite for consideration:  Understanding of the system architecture  e.g. - How and in what format it keeps your data  Tools that are available to you to access your data  Covering off on e-discovery needs that may arise  Remain mindful of compliance with enterprise-wide policies (existing & under consideration/development) - AUP, MDM, BYOD, etc.
  • 13.  Additional Requirements  Redundancy and backup  Disaster recovery  No vendor lock-in  Exit strategies as required  Protection of all designated confidential information and other intellectual property rights  Confirmation that the vendor does not acquire and may not claim any security interest in your data.  Where does Open Data fit in?
  • 14.  IP categories include  Copyrights, Trademarks, Trade secrets (Confidential Information) Data  IP Assets & Treatment under  Canadian laws  Laws of other countries  Infringement – what remedies?  Third party access – is vendor intending to grant some privileged third parties access to your Municipality's stored data  Who is that to be  What is approval and authorization procedure?  Is there to be a confidential disclosure agreement and what form is it to take?  Protecting “personal information” and IPR
  • 15.  Defining Characteristics of Confidential Information: Typically includes intangible assets (and associated materials) such as trade secrets, designs, processes, programs, procedures, third party Information, developments, disclosed under terms of a software license or services agreement  Examples might include, nonpublic and financial contract terms with other suppliers, and categories set out under MFIPPA  Negotiated cloud contracts will typically define, spell out, the restrictions, and remedies for unauthorized disclosure or other violation – Web-based, less likely to address question although it may be included under Intellectual Property Rights language  Breach of Confidentiality: Legal obligation of employees to respect the organization’s intangible assets, business and trade secrets etc. and maintain their confidentiality both during and after term of employment  Confidentiality & Non-Disclosure Agreements (NDA’s) might precede contract negotiation, and in any event, negotiate contracts will contain associated obligations and restrictions regarding confidentiality  Key consideration: Notwithstanding vendors adherence to best practices, what happens if the data center gets hacked? Is there a remedy, and if so, what is it to be?
  • 16.  Canada has two federal privacy laws  the Privacy Act and the Personal Information Protection and Electronic Documents Act. …  Every province and territory has privacy legislation governing the collection, use and disclosure of personal information held by government agencies – Office of The Privacy Commissioner of Canada  Ontario’s  MFIPPA Municipal Freedom of Information and Protection of Privacy Act, &  PHIPA - the Personal Health Information Protection Act  Onus on Municipalities and their suppliers to protect “personal information” from disclosure  Challenge to be considered - the trusteeship by the Municipality of personal information coupled with possible access, handling and disclosure of personal information of others stored on external cloud servers.  BYOD and Cloud access - Makings of a perfect storm with the convergence on one device of both personal and corporate data and providing access to cloud based data and databases – therefore, a critical need to have an enforceable BYOD policy in place.
  • 17. Others Our systems are vulnerable to damage or interruption from earthquakes, terrorist attacks, floods, fires, power loss, telecommunications failures, computer viruses, computer denial of service attacks, or other attempts to harm our systems.
  • 18. Thank You Lou Milrad IT Lawyer Milrad Law Office lou@milrad.ca 647.982.7890 www.milradlaw.ca