Privacy Assessments
Cloud service providers can now show their compliance with the GDPR, in the role as a processor, and help controllers identify those compliant cloud service providers.
The General Data Protection Regulation (GDPR), which became effective in 2018, requires adoption of technical and organizational measures for controllers and processors of personal data to demonstrate compliance with the GDPR. The GDPR outlines Codes of Conduct in Article 40 as a way for organizations to demonstrate compliance against an approved and recognized set of best practices.
On May 19th, 2021, the European Data Protection Board (EDPB) adopted the EU Cloud Code of Conduct, which was then adopted by the Belgian Data Protection Authority on May 20th. This is significant as this Code was designed specifically for cloud service providers. Adherence to the Code is voluntary; however, compliance will help controllers to identify processors that adhere to the GDPR.
The EU Cloud Code of Conduct (Code) applies to cloud service providers (CSP) (e.g., IaaS, PaaS, or SaaS) acting in the role as a processor to certify the in-scope cloud services as compliant with the EU recognized Code of Conduct. The cloud services that are included in the scope can include all cloud service offerings or a portion of the services. Selection of the cloud services to include in the scope is up to the CSP.
The applicable GDPR requirements are included in Chapter 5 and 6 of the Code. Chapter 5 includes requirements specific to privacy, or data protection requirements applicable to processors, while Chapter 6 includes security requirements. The Code is administered by Scope Europe, also referred to as the monitoring body.
There are three levels of compliance that the CSP can choose:
Level 1 is a self-assessment by the CSP confirming that the requirements within the Code have been met. The monitoring body will verify that the CSP complies with the Code.
Level 2 provides compliance to the Code utilizing existing third party assessments, audits or certifications that cover some of the Code’s requirements. The monitoring body will verify that the third party reports partially satisfy the code. When the reports do not support compliance with all of the Code requirements, the monitoring body verifies that the CSP complies with those requirements of the Code not covered by the third party reports.
Level 3 demonstrates compliance with every requirement outlined within the Code from third party assessments, audits or certifications. The audit reports must be internationally recognized standards and should provide sufficient information for the monitoring body to determine that the Code requirements were met.
The planning phase occurs at least two months in advance of fieldwork in accordance with the timing outlined in the job arrangement letter (JAL) or statement of work (SOW) executed with the client. Planning includes the completion of an intake questionnaire, confirming timing of interviews with key points of contact, and deployment of and evidence gathering for the information request list provided via AuditSource 2.0. Schellman will be available to the client to answer any questions associated with the assessment to ensure both parties are aligned on scope and expectations.
Schellman will hold a kickoff meeting to start fieldwork. Fieldwork consists of various testing procedures to evidence the requirements are met. The testing procedures may include one of the following:
Inquiry of relevant personnel with the requisite knowledge and experience regarding the performance and application of the related requirement
Observation of the relevant processes or procedures that includes, but is not limited to, witnessing the performance of controls or evidence of control performance with relevant personnel
Inspection of the relevant audit records that include, but is not limited to, policies, documented procedures, system configurations, or the existence of sampling attributes such as logged events or acknowledgements
Schellman has a no surprises policy and regular contact with the client during fieldwork, allowing clients to be apprised at all times of conformance status.
Schellman's assessment is focused on creating a deliverable that is clear, concise, and accurate. The draft report is provided within 2-3 weeks of the last day of fieldwork. The final deliverable is available within 5 business days of the client approving the draft version.
Chris is a Director and Privacy Technical Lead at Schellman based out of Atlanta, GA. With more than five years of experience in information assurance, Chris has a concentration in privacy-related engagements.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: