BSA: Australia cloud-friendly, EU privacy risks losing it

Software lobby kicks off fight against EU data protection

Software industry lobbyist the Business Software Alliance (BSA) has ranked Australia second out of 24 nations for their suitability to cloud computing, and warns that Europe’s high-ranking is under threat due to its controversial proposed data protection overhaul.

The wide-ranging document (PDF) released Wednesday covers cloud computing in the context of laws relating to security, cybercrime, intellectual property and cross-jurisdictional harmonisation efforts, ranking each nation according to its suitability for data handlers.

With a collective score of 79.2 Australia ranked second in the world behind Japan, based on the nation’s data privacy laws, approach to cybercrime, security, intellectual property as well as ICT investments such as the National Broadband Network.

Australia was ahead of Germany, the US, France, Italy, the UK, Korea, Spain, Singapore, Poland, Canada and 12 other mostly developing nations that make up 80 per cent of the worldwide ICT market.

Australia’s data privacy profile helped give it a high score in that field, since data controllers do not need register while organisations are free from registration requirements when conducting cross-border transfers. Australia also lacked a data breach notification law.

Established cybercrime laws and tough penalties on intellectual property infringement also made Australia cloud friendly, according to the BSA which also lobbies against software piracy, pointing out, for example, that there is a “basis for ISPs to be held liable for content that infringes copyright”.

EU data protection under fire

Broadly, developed nations had more cloud-friendly environments thanks to well established data, security and privacy laws, but the BSA warned that the European Union’s proposal to update its Data Protection Directive “threaten to undermine the economic advances that a truly global cloud can provide.”

“These findings may not be surprising. But the study warns that many high-ranking countries are beginning to wall themselves in with technology preferences and market-distorting regulations,” wrote the BSA’s president Robert Hollyman.

“Lawmakers in some EU countries, for example, are doing things to keep non-European firms waiting at the border while favouring local cloud providers. This does not bode well, because it effectively chops the global cloud into little pieces.”

That proposal, which could see 24 hour breach reporting and massive fines, triggered fierce lobbying from all sides, EU Commissioner Viviane Reding said after she announced the proposal.

The BSA’s voice adds to a varied line up of opponents that include Microsoft and Britain’s data protection authority, the Information Commissioner’s Office, which both agree that the proposal is too prescriptive.

Google’s Global Privacy Counsel Peter Fleischer meanwhile has on his personal blog argued that the proposed “right to be forgotten” clause would force Google to become the world’s biggest censor.

Follow @CSO_Australia and sign up to the CSO Australia newsletter.

Tags: Australia, cloud, data protection, eu, Business Software Alliance (BSA)

Comments

1

Allen

Tue 28/02/2012 - 17:45

The more friendly atmosphere in cloud computing will lead to a great flaw in cloud security

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CSO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
CSO Corporate Partners
  • FirEye
  • Clear Swift
  • Trend Micro
  • Sophos
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Trend Micro Mobile Security

Comprehensive enterprise protection for mobile devices

Security Awareness Tip
Clearswift tips: Guidelines for introducing and policing an effective IT Policy

1. Make it clear that the policy is not about playing ‘Big Brother’ but to ensure the security of employees, company information and data and to safeguard the company’s reputation.
2. Invest time to get buy-in from managers and their teams.
3. Convey the message of flexibility – with regard to social media, it is not about blocking staff usage but working in everyone’s interests to ensure that threats are contained.
4. Introduce a regular company-wide training programme that everyone attends at regular intervals throughout the year, not merely as part of an induction programme.
5. Within the training programme make sure that there are specific examples to demonstrate each rule or regulation, and that there is a clear explanation of the dangers of casual or careless talk on social networking sites. Again use examples, employees need to understand the consequences of raising a throwaway comment that has negative connotations for the business, as much as they need to be aware of dangers of making a more direct but ill-considered attack on a competitor, regulator or even a fellow colleague. They need to be clearly advised on any impact on the company and/or legal action or inquires that may be raised as a result.
6. Alert employees to any changes in policy through regular clear communication.
7. Reinforce the operational policy guidelines regularly, cover everything from blogging to Facebook, LinkedIn and Twitter.
8. Ensure that the rules are fair and that they apply throughout the business.
9. Enforce the rules – if there is a deliberate or malicious contravening, disciplinary action needs to be taken. A policy isn’t worth having if it is seen to be lax and unenforced.
10. Review the policy regularly to ensure you keep up to date with new systems and technology.

Phil Vasic is Regional Director, APAC, at Clearswift, the software security company www.clearswift.com
Security ABC Guides

7 Ways to Protect Your Business Printers

Can a hacker burn down your business by remotely setting one of your printers on fire? Researchers at Columbia University have recently proposed such a scenario, although HP quickly denied that it's possible. However, even if your printers can't be used as remote firestarters, there are many risks involved in networking a printer.