DataCenterNews Asia Pacific logo
Specialist data center news for Asia Pacific
Story image

Opinion: GDPR requirements & opportunities for colocation providers

FYI, this story is more than a year old

The European General Data Protection Regulation (GDPR) law was enforced in May, but is still confusing to some colocation providers as to which requirements they must comply with and how. So, I talked to an expert on the subject and came away with a clear answer: “It depends.

GDPR is all about ensuring the privacy of consumers' personal data and giving them more control over how data is used and for how long.

It's important because it applies to any organisation of any size that stores or processes any kind of personal data on EU residents.

For all intents and purposes, that means just about any EU company to the extent each holds data on its own employees. But it also applies to companies outside the EU that hold data on EU residents – again, that's a lot of companies.

GDPR basics: Data controllers vs. data processors

Mark Bailey is a partner at the UK law firm Charles Russell Speechlys and an expert on various aspects of technology law, including data center contracts. In fact, he presented on a GDPR-related topic at the International Colocation Club event in Paris, 2016.

Bailey says the extent to which the GDPR applies to a colocation provider depends on whether the company simply houses servers for customers, or whether it provides more “hands on” services that puts it more directly in touch with customer data.

The GDPR defines two classes: data controllers and data processors.

All colocation companies are data controllers, because they provide “the purposes, conditions and means of the processing of personal data,” according to the GDPR.

But colocation companies that are controllers in relation to their own employees may nonetheless have limited responsibility under GDPR in relation to their own customer data (if you're not doing any of these things and can't do any of these things you may not be subject to the GDPR at all).

You may be considered a data processor if you can access, manipulate or disseminate customer data, or if you provide storage, encryption or analysis of data, even if it's anonymised. If you can interact with and/or remove hard drives or have access to servers such as to reboot them, you're also considered a data processor.

“Whilst not to the same extent as controllers, data processors now have far more responsibility (and liability) under GDPR,” Bailey says, “and customers are now vetting providers as to whether they're compliant.

GDPR basics: Compliance for colocation providers

“Ensuring compliance with GDPR can be monitored by a few basic measures which will help mitigate companies that are not,” Bailey says.

First is having the appropriate policies and procedures in place – and following them. That typically entails paying attention to standards and certifications, such as the ISO 27001 information security standard.

“We're seeing data center providers increasingly starting to look at certifications and use them as badges of quality,” Bailey says. “Just because you have them doesn't mean you automatically comply with GDPR. The standards need to be properly complied with, so they seamlessly operate in a chain with customer requirements.

Physical security is another key requirement. But GDPR doesn't spell out any specific technologies; rather, it talks in general terms about “adequate” technical and organisational means to protect data.

“Two things we look for in data centers are biometric access controls and CCTV (security cameras),” Bailey says.

The key is having proper policies in place around those controls, such as how long you keep access records and CCTV recordings.

“If your data center is next door to a public street with thousands of people walking by every day, you'll have a different privacy impact assessment from one in the middle of the desert.

The business opportunity GDPR brings to colocation providers

The level of security your colocation data center provides can be a differentiator that provides opportunity for customers who are concerned about GDPR.

“Operators need to be curious enough about what customers are doing, so they have the right environment in place,” says Bailey.

Industries such as healthcare and finance, for example, are likely to have more stringent requirements, as is any company that processes credit cards.

“So be aware of it, and make sure you have the right controls and the right information available to give to customers around specific controls for things like CCTV.

Be GDPR compliant, your customers are expecting you to be

Remembering that GDPR applies to any company that processes or stores data on EU citizens – even if that company is not physically located within the EU – is necessary.

“If you maintain a marketing database or have contact with European citizens, technically the law still does apply,” Bailey says.

Responsibilities may be somewhat limited, but it's best to check on what they are.

Related stories
Top stories
Story image
Network Management
Data is growing at breakneck speed, but are we optimising its value?
Data lies at the heart of digital transformation, as every digital touchpoint translates to a data point. In this digital-first world, data is being created everywhere today – at breakneck speeds.
Story image
Data Protection
Cloudflare brings Data Localisation Suite to more APAC businesses
This allows any business in these countries to service their data locally while benefiting from the speed, security, and scalability of Cloudflare’s global network.
Story image
Data Centre Cooling
The world is heating up, but data centres should keep their cool
With the world heating up, the challenge of keeping data centres cool becomes more complex, expensive and power intensive.
Story image
Artificial Intelligence
ASUS Servers announce AI developments at NVIDIA GTC
The Taiwanese multinational now offers NVIDIA-certified servers with H100 Tensor Core GPU and AI enterprise software suite.
Story image
Sustainable IT
Equinix partners NUS to use hydrogen tech in data centres
The partners will develop hydrogen fuel technologies for green data centres in tropical climates, and for use in Equinix’s global network.
Story image
IT Automation
Juniper Networks announces expansion of Apstra Software with Apstra Freeform
The newly announced Apstra Freeform technology will give customers the ability to manage and automate operations for data centers regardless of the architecture.
Story image
Honeywell launches Data Center Suite for business outcomes
Honeywell has launched its Data Center Suite, a portfolio of outcome-based software offerings to help data centre managers and owners.
Story image
SoftIron announces its newest flagship offering, HyperCloud
SoftIron has announced HyperCloud, the world's first full turnkey, completely integrated and supported Intelligent Cloud Fabric and the company's newest flagship offering.
Story image
Digital Transformation
Nanyang Technological University Singapore builds digital brand presence
Leveraging the customisation features of Sitefinity DX, non-technical users could upload content and create design pages and boost work productivity. 
Story image
Fortinet unveils compact firewall for hyperscale data centres, 5G networks
"Fortinet’s dedication to pushing the boundaries of what is possible in security performance has yielded the most powerful compact firewall yet."
Story image
Data Centre Maintenance / Management
Schneider Electric backs new Leading Edge data centre in Australia
As a result of the new project, regional Australian businesses and communities will likely have greater access to distributed cloud networks.
Story image
Data center
Macquarie Asset Management acquires stake in ST Telemedias VIRTUS Data Centres
"We will further strengthen VIRTUS' focus on sustainability by backing investment in its technology and enhancing the lifecycle management of its equipment."
Story image
SnapLogic named Visionary in two Magic Quadrant categories
SnapLogic has announced that it is the only iPaaS (Integrated Platform as a Service) vendor to be named a Visionary in two Magic Quadrant categories.
Story image
Worldwide 5G mobile data traffic exploding - report
"With 5G, there is a wider range of deployment scenarios, forcing vendors to provide comprehensive solutions to support every need."
Story image
Data center
Australia’s data centre pioneer still leading after 22 years
We look at the fascinating success of Macquarie data centre's over its 22 year life span and how they continue to innovate in a highly contested sector.
Story image
Growth in hyperscale data centres to increase shortage of IT workers
New Zealand's tech worker capacity is set to come under increasing pressure as the number of hyperscale data centres grows.
Story image
Zetaris is changing the way we think about data virtualisation
Zetaris was launched on the Microsoft Marketplace and Ingram Micro Cloud Marketplace in Australia in 2020 and has since expanded into nine global markets.
Story image
Talend announces support for Amazon Redshift Serverless
Talend has announced its support for Amazon Redshift Serverless, with the company saying the integration reinforces its commitment and leadership in supporting businesses.
Story image
Google Cloud Platform
Google Cloud to open first cloud region in NZ - among others
Google Cloud has announced plans to bring three new cloud regions, one each in New Zealand, Malaysia and Thailand.
Story image
VMware extends collaboration with Microsoft for enterprise workloads in Azure
Mutual customers will have the choice to purchase Azure VMware Solution through the VMware Cloud Universal program.
Story image
Software Defined Wide Area Network
Axiata, Versa Networks partner for enterprise SASE in Asia
Axiata has partnered with Versa Networks to deliver Secure Access Service Edge (SASE) technology to rapidly digitalising Asian enterprises.
Story image
DCI Data Centers breaks ground on AKL02 center
DCI Data Centers has commenced construction on Auckland's largest data center.
Story image
DCI plans to build new cloud edge data centre in Canberra
DCI is one of the first to commit to the Precinct which has a focus on defence, space, cybersecurity and high-tech manufacturing sectors.
Story image
Equinix invests $23m to expand ME2 data centre in Melbourne
Equinix has completed the second phase expansion of its ME2 International Business Exchange data centre, located in Port Melbourne.
Story image
Cloudera launches all-in-one data lakehouse cloud service
CDP One makes it faster, easier and less risky for businesses to move to the cloud and migrate existing workloads to a modern data architecture.
Story image
Digital Transformation
NTT launches its Cyberjaya 6 data center in Malaysia
NTT expands its hyperscaler footprint in Malaysia with its sixth data center facility, supporting the growing digital economy.
Story image
Sustainable IT
Empyrion DC announces 40MW green data center in South Korea
Empyrion DC has announced it is developing a 40MW green data center in Gangnam, Seoul, South Korea (GDC).
Story image
Data analytics
Srisawan Hospital to enhance patient experience with InterSystems TrakCare
The new Srisawan Hospital in Bangkok has chosen InterSystems TrakCare to help create enhanced patient experiences and promote further digital engagement.
Story image
Data Protection
iseek secures Queensland Government data centre contract
iseek secures the Queensland Government's core network data centre as-a-service contract after a competitive procurement process undertaken by the CITEC.
Story image
ManageEngine unveils SaaS availability of Analytics Plus
ManageEngine's Analytics Plus is now available as a software as a service (SaaS) offering, enabling users to set up a completely functional and integrated analytics platform anywhere in under a minute.
Story image
InterSystems releases updates to its IRIS data platform
Provider of next-generation solutions InterSystems has announced a series of new releases to its award-winning InterSystems IRIS data platform.
Story image
Stellar financial result after major strategic moves by Superloop
We get a glimpse under the hood at the financial results from 2022 for the connectivity giant Superloop.
Story image
Sustainable IT
New report calls for tighter guidelines on data centre sustainability
A new Cushman & Wakefield report is calling for water consumption and carbon emissions to be measured in addition to power usage.
Story image
Edge Computing
NTT launches Edge-as-a-Service to accelerate automation
"Minimum latency, maximum processing power, and global coverage are exactly what enterprises need to accelerate their digital transformation journeys.”
Story image
Seagate announces next gen advanced storage arrays
The new Exos X systems feature up to twice the performance of the previous generation and enhanced enterprise-class durability, the company states.
Story image
Machine learning
Oracle announces MySQL HeatWave for Amazon Web Services
MySQL HeatWave is a service that combines OLTP, analytics, machine learning, and machine learning-based automation. 
Story image
VMware advances multi-cloud management with VMware Aria
Managing apps and infrastructure in a multi-cloud, especially public cloud, and multi-technology environment is complex.
Story image
NCS, FPT Software launch Strategic Delivery Centre in Vietnam
The new partnership is designed to support increasing demand for high quality digital services across the region.
Story image
Network Infrastructure
Vertiv launches solutions to better manage edge computing
Vertiv has introduced new power and cooling solutions for the edge of the network, including the addition of lithium-ion models to a leading on-line UPS family.
Story image
Optical Networking
NEC predicts AON as a next-generation infrastructure
NEC's open optical transmission devices support multi-vendor configurations, allowing customers to procure and combine equipment from multiple vendors.
Aws Marketplace
Learn how to implement a backup and recovery plan for a new generation of Kubernetes-based modern applications
Link image
AWS Marketplace
Whitepaper: A practical guide for mitigating risk in today’s modern applications
Link image