10 Tips for effective cloud service agreements.

PositionCLOUD

Legal experts in a LegalTech News article recommend 10 best practices for those who negotiate and write cloud service agreements:

  1. Require service providers to comply with all applicable privacy and data security laws, regulations, and industry standards.

  2. Identify a minimum standard of care for privacy and data security to meet the organization's particular needs, and require service providers to meet it.

  3. Allow cloud providers to access the organization's IT systems and use its data only as required to perform the agreed-on services or as authorized for other purposes.

  4. Restrict cloud providers from disclosing the organization's data to third parties except as specifically authorized. Address how the provider will handle any data requests from government authorities.

  5. Require cloud providers to impose the same privacy and data security mandates on their subcontractors and to monitor them to ensure compliance.

  6. Include privacy and data security performance expectations and measures in service level agreements, including timeframes for addressing risks and reporting security incidents.

  7. Require cloud providers to return or destroy, at the organization's request, all copies of the organization's data when the service agreement ends.

  8. Define specific security incident reporting and response...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT