Achieving Regulatory Compliance for Data Protection in the Cloud

Abstract

The advent of cloud computing has enabled organizations to take advantage of cost-effective, scalable and reliable computing platforms. However, entrusting data hosting to third parties has inherent risks. Where the data in question can be used to identify living individuals in the UK, the Data Protection Act 1998 (DPA) must be adhered to. In this case, adequate security controls must be in place to ensure privacy of the data. Transgressions may be met with severe penalties. This paper outlines the data controller’s obligations under the DPA and, with respect to cloud computing, presents solutions for possible encryption schemes. Using traditional encryption can lead to key management challenges and limit the type of processing which the cloud service can fulfill. Improving on this, the evolving area of homomorphic encryption is presented which promises to enable useful processing of data whilst it is encrypted. Current approaches in this field have limited scope and an impractical processing overhead. We conclude that organizations must thoroughly evaluate and manage the risks associated with processing personal data in the cloud.

Authors and Affiliations

Mark Rivis, Shao Zhu

Keywords

Related Articles

Dynamic Allocation of Abundant Data Along Update Sub-Cycles To Support Update Transactions In Wireless Broadcasting

Supporting transactions processing over wireless broadcasting environment has attracted a considerable amount of research in a mobile computing system. To allow more than one conflicting transactions to be committed with...

An efficient user scheduling scheme for downlink Multiuser MIMO-OFDM systems with Block Diagonalization

The combination of multiuser multiple-input multiple-output (MU-MIMO) technology with orthogonal frequency division multiplexing (OFDM) is an attractive solution for next generation of wireless local area networks (WLANs...

Churn Prediction in Telecommunication Using Data Mining Technology

Since its inception, the field of Data Mining and Knowledge Discovery from Databases has been driven by the need to solve practical problems. In this paper an attempt is made to build a decision support system using data...

Novel Carrier based PWM Techniques Reduce Common Mode Voltage for Six Phase Induction Motor Drives

This paper proposes a novel pulse width modulation (CBPWM) technique for reducing the common mode voltage for a six-phase induction motor (SPIM) drive. This proposed CBPWM technique relies on setting up offset functions...

Social Success Factors Affecting Implementation of Agile Software Development Methodologies in Software Industry of Pakistan: An Empirical Study

During the past few years it has been observed that the implementation of Agile software development methodologies have become a part and parcel in software development projects not only in large and developed organizati...

Download PDF file
  • EP ID EP99426
  • DOI 10.14569/IJACSA.2013.041224
  • Views 122
  • Downloads 0

How To Cite

Mark Rivis, Shao Zhu (2013). Achieving Regulatory Compliance for Data Protection in the Cloud. International Journal of Advanced Computer Science & Applications, 4(12), 162-167. https://europub.co.uk/articles/-A-99426