current issue

Prawo Nowych Technologii

no. 3/2025

Secure processing of personal data within a cloud storage - key aspects based on ISO 27017 and ISO 27018 standards and selected GDPR provisions

Kamila Król
Autorka jest aplikantem radcowskim II roku przy Okręgowej Izbie Radców Prawnych w Łodzi
Abstract

The security of personal data processed within a cloud storage requires a comprehensive approach, encompassing an analysis of data processing purposes, the data minimalization principle and the appropriate selection of tools and data protection principled under the GDPR. Proper structuring of agreements with cloud storage providers as well as ISO 27017 and ISO 27018 standards, which establish standards for data management and privacy protection, have vital importance in data processing.
The Data Protection Impact Assessment (DPIA), the application of the principles of legality, fairness, transparency, purpose limitation and data adequacy, as well as the implementation of backup mechanisms and company’s personnel training, constitute the lynchpin of ensuring data security. The consideration and proper application of regulations by law enable the mitigation of risk of data breaches and contribute to enhancing users’ trust in cloud services.

Keywords
personal data security, cloud-based data processing, GDPR, ISO 27017 standard, ISO 27018 standard, privacy protection, Data Protection Impact Assessment (DPIA), data minimization, cloud services provider contract