The European Union (EU) has proposed new draft rules that would require non-European Union cloud service providers, such as Amazon, Google, and Microsoft, to secure an EU cybersecurity label before handling sensitive data. According to a draft document seen by Reuters, the joint venture with an EU-based company would be the only way for non-EU cloud service providers to obtain the cybersecurity label.
The document adds that US tech giants and others involved in the joint venture can only have a minority stake, and employees that have access to EU data would have to undergo specific screening and have to be located in the 27-country bloc. Furthermore, the cloud service must operate and maintain from the EU, and all cloud service customer data stored and processed in the EU. The new draft proposal concerns an EU certification scheme (EUCS) that would vouch for the cybersecurity of cloud services and determine how governments and companies in the bloc select a vendor for their business.
The latest provisions underscore EU concerns about interference from non-EU states, as EU laws take precedence over non-EU laws regarding the cloud service provider. While the new rules could potentially spark criticism from US tech giants concerned about shut out from the European market. The EU maintains that certified cloud services should only operate by companies based in the EU, with no entity from outside the EU having effective control over the cloud service provider.
The document states that “undertakings whose registered head office or headquarters are not established in a Member State of the EU shall not, directly or indirectly, solely or jointly, hold positive or negative effective control of the CSP applying for the certification of a cloud service”.
The tougher rules will apply to personal and non-personal data of particular sensitivity where a breach may have a negative impact on public order, public safety, human life or health, or the protection of intellectual property. The draft could fragment the EU single market as each country has full discretion to impose the requirements whenever it sees fit, according to an industry source.
The US Chamber of Commerce has previously said that the plan puts US companies on an unequal footing. However, the EU believes that the new rules are necessary to protect the bloc’s data rights and privacy. EU countries will review the draft later this month, after which the European Commission will adopt a final scheme.
Moreover, Visit CxO Global FORUM or CxO News Live for all the latest updates.



