munotes®

Cloud Computing and the Internet of Things

Chapter One Hundred Three

Syllabus topic 4.2, "Emerging New Legal Issues."

Pages 651 to 656 of 948

In one line

Cloud computing puts a person's data on somebody else's machine in an unknown country, the internet of things puts a computer in objects nobody thinks of as computers, and Indian law addresses the first through the service level agreement and the second hardly at all.

Cloud computing: the three models

By service.

Infrastructure as a service: the provider supplies raw compute, storage and networking, and the customer runs everything above it. The customer configures the security, and most breaches are the customer's fault.

Platform as a service: the provider supplies a runtime and the customer supplies the application.

Software as a service: the provider supplies the application and the customer supplies only its data. The customer controls nothing technical, and the contract is the only lever it has.

By deployment: public, private, community and hybrid. The legal difference is who else is on the same hardware and where it sits.

And the axis that matters legally is control, which runs opposite to convenience. The more the provider supplies, the less the customer can do about security, location, retention or exit, and the more the contract has to do.

Who is who under Indian law

Under the Information Technology Act.

The provider is an intermediary under section 2(1)(w), because it receives, stores or transmits electronic records on behalf of another. Chapter 1360. So it has the section 79 exemption and the due diligence obligations, and it is not the originator under section 2(1)(za). Chapter 940.

The customer is a body corporate for section 43A, if it possesses, deals with or handles sensitive personal data in a computer resource it owns, controls or operates. The SPDI Rules 2011 make the customer responsible for reasonable security practices, and outsourcing the machine does not outsource the duty. Chapter 230.

Under the DPDP Act, 2023, when it commences on 13 May 2027, the customer is the Data Fiduciary and the provider is a Data Processor, defined in section 2(k) as a person who processes personal data on behalf of a Data Fiduciary. Section 8(2) is the provision to remember: a Data Fiduciary may engage a Data Processor only under a valid contract, and under section 8(1) the Fiduciary is responsible for compliance whether or not the Data Principal has agreed and notwithstanding any agreement to the contrary. Chapter 1050.

Read section 8 twice. Liability cannot be contracted away to the provider. The customer answers to the individual and to the Board, and its recourse against the provider is a matter of contract alone.

Under the CERT-In directions of 28 April 2022. A cloud service provider is expressly named in direction (v), and must keep five years of validated subscriber records. Direction (iv) requires 180 days of logs within Indian jurisdiction, which for a cloud customer means insisting on Indian log retention in the contract. Chapter 770.

munotes.in651

The rest of this chapter

Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.

You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.

Notes + Solved papers: ₹798 Already bought it? Sign in

Or notes only: ₹499
Or solved papers only: ₹499

Free either way: question papers, the syllabus, and module one of every subject.

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!