CISPE explained
CISPE (Cloud Infrastructure Services Providers in Europe) is a non-profit trade association for infrastructure as a service (IaaS) cloud providers in Europe. It was started to aid IaaS providers in explaining their business model to policymakers.[1]
Registered in early 2017, CISPE has been operating since 2015.[2]
The association aims to advocate for an EU-wide cloud-first public procurement policy and engage for a European Digital Single Market including the promotion of high-level security and data protection rules/standards as well as avoiding vendor lock-in.
In June 2020, the association became one the 22 founding members[3] of GAIA-X, announced by the German and French Ministers of Economic Affairs Peter Altmaier and Bruno Le Maire. CISPE joined forces with European cloud users and providers like BMW, EDF, Safran, Atos, Siemens, Bosch, OVHcloud, and Deutsche Telekom.
The CISPE Data Protection Code of Conduct
To help IaaS providers and their customers to comply with the EU General Data Protection Regulation (GDPR), which entered into force from 25 May 2018, CISPE released the CISPE Data Protection Code of Conduct. On top of the required compliance to meet with the GDPR, the code also ensures that IaaS customers can choose to have their data located and processed exclusively in Europe, and that the supplier will not re-use a customer's data.[4]
The compliance has to be declared by CISPs/IaaS providers service by service.[5]
The CISPE Code of Conduct was launched on 27 September 2016 at the European Parliament,[6] and the first thirty services had been declared by the first CISPs/IaaS providers on 14 February 2017.[7]
Announcements received press coverage from Le Monde, InfoDSI,[8] El Pais, La Repubblica,[9] Silicon,[10] [11] [12] Cloud Magazine, Computer Sweden,[13] Tom's Hardware,[14] L'informaticien,[15] [16] Global Security Mag,[17] EU Observer, Politico, Computer Weekly,[18] IAPP,[7] Il corriere della Sicurezza,[19] LeMagIT,[20] Bloomberg Television,[21] ITR Manager,[22] Heise.de,[23] COR.COM,[24] ZDNet,[25] [26] ElEconomista.es, IT Channel,[27] EuropaPress,[28] [29] 01net,[30] The Register,[31] and CIO Dive.[32]
The CISPE Code has received a positive opinion[33] by the European Data Protection Board on May 19. 2021, and has been finally approved by the competent national Supervisory Authority, CNIL on June 3, 2021.[34] To become operational, i.e. legally effective, the Code requires an accredited monitoring body, first. "Le code de conduite sera opérationnel dès que l’un de ces organismes de contrôle sera agréé par la Commission."[35] To date, 3 Monitoring Bodies have been approved (EY CertifyPoint,[36] Bureau Veritas,[37] LNE[37]).
Reversibility IaaS Code of Conduct
To anticipate the Free Flow of non-personal Data Regulation (FFoD) that was published in late 2018, the European Commission started the SWIPO (Switching and Porting) Working Groups to develop two codes of conduct[38] for data portability on the Cloud market (one for Infrastructure as a Service, another for Software as a Service).
These codes were developed to specifically answer the regulation requirement of its Article 6 - "Data Porting". CISPE, together with EuroCIO (the association of European CIOs) has been tasked by the European Commission[38] to co-chair the SWIPO IaaS Working Group. The SWIPO IaaS code[39] was handed over to the European Commission in November 2019 during the High-Level Conference on Data Economy of the EU Finish Presidency.[40] [41]
Cispe members have declared first services adherent to the Swipo Iaas Code in May 2021.[42]
Environmental impact of cloud infrastructure
The organization set up a Green Cloud Task Force to discuss questions of environmental impact of data centers.[43] The Task Force worked with the European Commission to develop a self-regulatory initiative to achieve our shared goal of ensuring data centres in Europe are climate neutral by 2030: the Climate Neutral Data Centre Pact. The initiative is led by CISPE and EUDCA.[44]
10 Principles for Fair Software Licensing
In April 2021, Cispe launched together with the French CIO association CIGREF "10 Principles for Fair Software Licensing" [45] in order to address fair software licensing terms of the frame of the EU Digital Markets Act.[46]
Members and supporting organizations
Members and supportive organizations manage operations in more than 15 European countries including France, Germany, Italy, Ireland, the United Kingdom, Finland, Sweden, the Netherlands, Spain, Bulgaria, Poland, and Switzerland.
Corporate members of CISPE, or organisations supporting the Code of Conduct, include: Arsys, Art of Automation, Aruba S.p.A., AWS, BIT, Dada, Daticum, Dominion, Enter, Fasthosts, FjordIT, Gigas, Hetzner Online, Home, Host Europe Group, IDS, Ikoula, LeaseWeb, Lomaco, Netalia, Netcetera, Outscale, OVHcloud, Seeweb, Serverplan, SolidHost, UpCloud, VTX, XXL Webhosting, and 1&1 Internet.[47]
Organization
The CISPE General Assembly elects a ten-member board. The composition of the board of directors should at any time take into account composition rules: a majority of the board should be composed with European-headquartered companies; a majority of the board should be composed of small and mid-caps (< €1 billion turnover) and represent at least three different EU countries (considering worldwide headquarter's location). The first chairman of the board is Alban Schmutz.[48]
The general secretary is named by the board. The first general secretary is Francisco Mingorance.
The Board also names a Code of Conduct Task Force (CISPE CCTF) which is in charge of the evolution and improvements of the CISPE Data Protection Code of Conduct.[49]
The organization is open to any member operating at least one IaaS service in one European country and engaging to declare at least one service under the CISPE Code of Conduct within six months.[50]
External links
Notes and References
- Web site: Protection des données : les hébergeurs européens à l'offensive. Vincent. Fagot. 27 September 2016. Le Monde. 2017-07-28.
- Web site: Cloud Infrastructure Services Providers in Europe - Transparency Register. 2017-07-28. Ec.europa.eu.
- Web site: 2020-06-04. Germany, France launch Gaia-X platform in bid for 'tech sovereignty'. 2020-07-05. POLITICO.
- Book: Gutwirth. Serge. European Data Protection: In Good Health?. Leenes. Ronald. Hert. Paul De. Poullet. Yves. 2012-02-22. Springer Science & Business Media. 978-94-007-2903-2. en.
- Web site: Public Register - Current list of services declared under the CISPE Code Of Conduct. Cispe.cloud. 28 July 2017.
- Web site: Europäische Cloud-Infrastruktur-Anbieter veröffentlichen Verhaltenskodex. Cloudcomputing-insider.de. 2017-07-28.
- Web site: CISPE announces 30 services comply with its code of conduct. Iapp.org. 2017-07-28.
- Web site: Un code de conduite pour les fournisseurs d'IaaS. Infodsi.com. 2017-07-28.
- Web site: Cloud, nuovo codice di condotta europeo: ecco cosa cambia. 28 September 2016. Repubblica.it. 2017-07-28.
- Web site: CISPE Kodex: Europas Cloud-Anbieter positionieren sich zum Datenschutz - silicon.de. 29 September 2016. Silicon.de. 2017-07-28.
- Web site: CISPE, lobby européen du Cloud, publie un code de conduite data. 28 September 2016. Silicon.fr. 2017-07-28.
- Web site: AWS Touts CISPE Membership To Help Its Cloud Services Meet EU GDPR. 14 February 2017. Silicon.co.uk. 2017-07-28.
- Web site: Ny organisation ska ge garantier för GDPR i molnet – Amazon är med. Computersweden.idg.se. 2017-07-28.
- Web site: Con CISPE un codice di condotta per il Cloud. Tomshw.it. 2017-07-28.
- Web site: CISPE : un code de conduite pour la protection des données en Europe. Linformaticien.com. 2017-07-28. 10 March 2017. https://web.archive.org/web/20170310002457/http://www.linformaticien.com/actualites/id/41816/cispe-un-code-de-conduite-pour-la-protection-des-donnees-en-europe.aspx. dead.
- Web site: Confiance dans le cloud : AWS rejoint l'initiative CISPE, qui passe en prod ! . 2017-05-15 . dead . https://web.archive.org/web/20170704064959/http://www.linformaticien.com/actualites/id/43122/confiance-dans-le-cloud-aws-rejoint-l-initiative-cispe-qui-passe-en-prod.aspx . 4 July 2017 . dmy-all .
- Web site: Certification de la protection des données : des fournisseurs d'infrastructures cloud opérant en Europe déclarent leur conformité au code de conduite relatif à la protection des données. Global Security Mag Online. 2017-07-28.
- Web site: AWS preps GDPR readiness by signing up to cloud Code of Conduct. Computerweekly.com. 2017-07-28.
- Web site: Dada aderisce al Codice di condotta sulla protezione dati del CISPE - Il corriere della sicurezza. Ilcorrieredellasicurezza.it. 15 February 2017 . 2017-07-28.
- Web site: Les fournisseurs de services Cloud anticipent le RGPD. Lemagit.fr. 2017-07-28.
- Web site: Колко голяма е заплахата пред сигурността на данните в облака . Bloombergtv.bg. 2017-07-28.
- Web site: CISPE anticipe le RGPD et fournit une "marque de conformité". Itrmanager.com. 2017-07-28.
- Web site: Datenspeicherung in Europa soll Cloud-Kontrolle verbessern. Heise.de. 27 September 2016 . 2017-07-28.
- Web site: Cloud, nasce il primo codice di condotta: "I dati dei clienti non si toccano". Corrierecomunicazioni.it. 28 September 2016. 2017-07-28.
- Web site: RGPD : Les fournisseurs cloud prennent de l'avance. Zdnet.fr. 28 September 2016 . 2017-07-28.
- Web site: Una grande alleanza cloud europea: via al Cispe. Corrierecomunicazioni.it. 15 February 2017. 2017-07-28.
- Web site: Un code de conduite pour les fournisseurs d'IaaS. Itchannel.info. 2017-07-28.
- Web site: Aprobado el código de conducta en aplicación del Reglamento de Protección de Datos de la UE. 27 September 2016. Europapress.es. 2017-07-28.
- Web site: Gigas garantiza la total privacidad de los datos en la nube. 15 February 2017. Europapress.es. 2017-07-28.
- Web site: Cispe: ecco chi aderisce alla coalizione. Maria Teresa Della Mura. 15 February 2017. 01net.it. 2017-07-28.
- Web site: Cloud industry body sets up new data protection code. Theregister.co.uk. 2017-07-28.
- Web site: Data Protection Certification: Cloud Infrastructure Services Providers operating in Europe declare compliance with CISPE Data Protection Code of Conduct. Ciodive.com. 2017-07-28. https://web.archive.org/web/20170728114839/http://www.ciodive.com/press-release/20170214-data-protection-certification-cloud-infrastructure-services-providers-oper/. 28 July 2017. dead.
- https://edpb.europa.eu/system/files/2021-05/edpb_opinion_202117_cispecode_en_0.pdf
- Web site: 2021-06-11 . The CNIL approves the first European code of conduct for cloud infrastructure service providers (IaaS) CNIL . https://web.archive.org/web/20210611222413/https://www.cnil.fr/en/cnil-approves-first-european-code-conduct-cloud-infrastructure-service-providers-iaas . 2021-06-11 . 2024-06-18 . cnil.fr.
- Web site: Délibération 2021-065 du 3 juin 2021. live. 2021-06-13. www.legifrance.gouv.fr. https://web.archive.org/web/20210613153812/https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000043632207 . 13 June 2021 .
- Web site: Code of conduct: CNIL grants first accreditation to a monitoring body | CNIL.
- Web site: Code de conduite : La CNIL délivre deux nouveaux agréments à des organismes de contrôle | CNIL.
- Web site: Anonymous. 2018-04-16. Cloud stakeholder working groups start their work on cloud switching and cloud security certification. 2020-07-05. Shaping Europe’s digital future - European Commission. en.
- Web site: High-level Conference on Data Economy. 2020-07-05. Valtioneuvosto. en-US.
- High-Level Conference on Data Economy 25.11.2019 (day 1) . 2019-11-25 . Liikenne- ja viestintäministeriö . 2024-06-18 . YouTube.
- https://api.hankeikkuna.fi/asiakirjat/2d0f4123-e651-4874-960d-5cc3fac319b6/3b0ad494-bb45-419b-8853-786754d1b287/LIITE_20191009135505.pdf
- Web site: 3DS Outscale, Aruba, AWS, CoreTech, Infoclip, Irideos, Leaseweb, OVHcloud, and Scaleway to declare first cloud infrastructure services adhering to SWIPO IaaS Code for data porting. 12 May 2021.
- https://cispe.cloud/climate-neutral-data-centre-pact-task-force/
- Web site: 5 keys to understand the Climate Neutral Datacenter Pact. 21 January 2021.
- Web site: Cigref and CISPE Launch Ten Principles to End Unfair Practices of Software Gatekeepers. 14 April 2021.
- Web site: Cloud : Le torchon brûle entre les entreprises et les éditeurs de logiciels américains. 13 April 2021.
- Web site: Implications of the Code of Conduct for Cloud Infrastructure Service Providers in Europe. Idc.com. 2017-07-28. https://web.archive.org/web/20170728115212/http://www.idc.com/getdoc.jsp?containerId=EMEA42512717. 28 July 2017. dead.
- Web site: Board of Directors - CISPE - The Voice of Cloud Infrastructures Providers in Europe. Cispe.cloud. 2017-07-28.
- Web site: CCTF - CISPE - The Voice of Cloud Infrastructures Providers in Europe. Cispe.cloud. 2017-07-28.
- Web site: Become CISPE Member. Cispe.cloud. 2020-06-08.