When your data resides on a cloud provider's infrastructure, your ownership rights could be compromised. For example, what's to prevent the cloud provider from deciding to access your data and use it for its own purposes? That's why any contract for cloud services should include language clearly affirming your ownership of your data.
The good news is that well-established cloud vendors are beginning to include language along these lines in their standard contracts. For example, section 10.2 of the Amazon Web Services contract states:
"Your Applications, Data and Content. Other than the rights and interests expressly set forth in this Agreement, and excluding Amazon Properties and works derived from Amazon Properties, you reserve all right, title and interest (including all intellectual property and proprietary rights) in and to Your Content."
It hasn't always been this way with cloud computing, but as customers have voiced their ownership requirements, providers have made improvements in this area. As the cloud continues to evolve, if customers clearly state their needs, then smart cloud providers will listen and respond.
Depending on the nature of your data and how it's processed in the cloud, it may also be necessary for the contract to include language affirming your institution's ownership of the results of any processing of its data that occurs while on the cloud provider's system.
With ownership clarified, the next step is to identify the limitations on how the cloud provider may use your data. In most cases, you'll want to limit the provider's use solely to that which is necessary for it to fulfill its obligations under the contract. It is also prudent to specifically exclude the provider from any mining of your data.
Be ready for the divorce
Once your data and processes have moved to cloud, you become more dependent upon the provider. You could be locked into its services, a situation that increases the cloud providers leverage over you in negotiating contract terms.
I know this sounds like advising someone to find a divorce lawyer before getting married, but to mitigate the risk of vendor lock-in, you need to plan in advance for the eventuality that you may decide to switch to a different provider or bring your data and processes back in-house. With this in mind, the contract should state your rights to access your data on an ongoing basis. Specifically, the contract should:
* Describe the process by which your data will be returned, whether done midterm or upon contract termination.
* State the amount of time the provider will have to turn over your data.
* Specify that the data must be provided in a commonly used format that is pertinent to your expected needs, and not in a proprietary or otherwise inaccessible format.
Sign up for CIO Asia eNewsletters.