EU Proposes Strict Cybersecurity label Requirements for Amazon, Google, Microsoft
European Union presented draft rules that have tougher cybersecurity requirements for tech companies like Amazon, Google, and Microsoft. These companies can achieve the label only via a joint venture with an EU-based firm, as per the written rules in the EU draft document.
Highlights
- Companies based in the EU are operating certified cloud service
- Outside entities rather than the EU won’t have effective control over the CSP
- Still, the EU countries have their reconsideration over the draft later this month
Cybersecurity issue is still placed one of the biggest issues in the tech world and companies other than the EU like Amazon, Google, and Microsoft, and some other companies based on cloud service providers see to secure an EU cybersecurity label to handle sensitive data can only do via a joint venture with the companies based on EU. Revealed as per the draft document seen by the news agency.
Several tech giants of the US and others are involved in the joint venture and they can only have a minority stake, also the employees who have access to the data of the EU will have to pass specific screening and have to provide their location in the 27-country bloc, as said in the document.
This document also includes the rules as all the cloud-related services and works will only be operated and maintained from the EU including all the data and all cloud-related service customer data stored and processed in the EU, and the laws made by the EU should have the precedence over non-EU laws related to the cloud service provider.
The document has stated “Certified cloud services are operated only by companies based in the EU, with no entity from outside the EU having effective control over the CSP (cloud service provider), to mitigate the risk of non-EU interfering powers undermining EU regulations, norms and values,” can be read in the document.
“Undertakings whose registered head office or headquarters are not established in a member state of the EU shall not, indirectly, solely or jointly, hold positive or negative effective control of the CSP applying for the certification of a cloud service,” Document include.