OVH und der Schutz personenbezogener Daten

Information regarding Brexit

Despite the end of the transition period during which the United Kingdom continued to apply European Union law, that occurred on December 31st, transfers of personal data to the United Kingdom will be able to continue, at least provisionally, without the need to apply Chapter V of the General Data Protection Regulations ("GDPR") relating to data transfers to countries outside the European Union.

Indeed, the European Union and the United Kingdom have agreed, as part of the Trade and Cooperation Agreement of December 24, that as of January 1, the effective date of the said agreement, the United Kingdom will not be considered as a third country to the Union for transfers of personal data, for a new transitioning period of four (4) months that may be, if necessary, extended for two (2) additional months, i.e. until July 1st (the “specified period”).

This is applicable provided that the said agreement is effectively ratified by both parties and that no substantial changes are made to the data protection regime of the United Kingdom on December 31, 2020 without the approval of the European Union. This should remain the case insofar as both the United Kingdom and the European Union have an interest in facilitating data flows.

In this case, the OVHcloud services located in the United Kingdom will be able to continue to process personal data under unchanged conditions until the end of the said specified period.

Please note, however, that if you do not have an establishment in the European Union, but are processing, as a processor or data controller, from the United Kingdom, data of persons who are in the territory of the Union as provided for in Article 3 of the GDPR, you are required since January 1 to appoint a representative in the Union, in accordance with Article 27 of the GDPR.

This new transitional arrangement should allow time for the European Commission to decide, pursuant to Article 45 of the GDPR, whether or not the United Kingdom has an adequate level of protection of personal data.

If so, the Commission will issue an adequacy decision and data transfers to the United Kingdom will be able to continue on such a basis without need to further formalities at the end of the specified period.

Conversely, in the absence of an adequacy decision, data transfers from the Union to the United Kingdom may no longer take place at the end of the specified period, unless appropriate safeguards are put in place as provided for in Article 46 of the GDPR, and notably if rights are recognized and effective remedies are available in the United Kingdom for European data subjects.

What would be the impacts for OVHcloud customers if the European Commission does not provide adequacy decision by the end of the specified period? In particular in relation to their use of OVHcloud services?

Several situations must be distinguished:

You are a customer of an OVHcloud European entity and only use OVHcloud services hosted in European Data Centers (excluding services hosted in the OVHcloud data center located in the United Kingdom)
If you are a customer of a European OVHcloud entity (not OVH Limited, the UK-registered OVHcloud entity), and you are using OVHcloud services hosted in one or more European OVHcloud data centers only (excluding the OVHcloud data center located in the UK), a lack of adequacy decision regarding the United Kingdom would have no impact.

Indeed, in this case, your data remains hosted in the European Union, and OVHcloud refrains from unilaterally changing such location and in particular from transferring your data to its data center in the United Kingdom.

In addition, OVHcloud teams located in the United Kingdom would not be in charge of the administration of the services provided to European customers (except OVHcloud UK customers) hosted in European data centers. As a result, no processing of data associated with the said Services would be carried out remotely from the United Kingdom.

Finally, if OVHcloud was to receive a request from a United Kingdom authority to obtain communication of the data you host in one of its European data centers, OVHcloud would, in accordance with its policy, oppose such a request unless it is made in accordance with Article 49 of the GDPR or an international agreement, such as a mutual legal assistance treaty, in force with the United Kingdom.

Warning: If you are working from the United Kingdom on the data and solutions that you host as part of your OVHcloud European services, or if you use a third-party service provider located in the United Kingdom, you should ensure that the appropriate safeguards are in place on your side according to article 46 of the GDPR.
You are a customer of an OVHcloud European entity and use services hosted in the OVHcloud Data Center located in the United Kingdom.
Use of services hosted in OVHcloud's UK data center, by definition, involves hosting, and therefore transferring, the data you use in connection with such services to the UK. In addition, the OVHcloud teams located in the United Kingdom may be involved in the administration of these services.

In this context, in accordance with its contractual commitments, and in particular Article 6 "Location and transfers of personal data" of the Appendix "Processing of Personal Data", OVHcloud would set up a data transfer agreement in accordance with the standard contractual clauses adopted by Decision No. 2010/87/EU of the European Commission of February 5, 2010 (the "Standard Contractual Clauses") or equivalent.

Nevertheless, while the implementation of these standard contractual clauses is, in accordance with Article 46 of the GDPR, a necessary prerequisite for such data transfers in non-adequate third countries, it does not systematically constitute by itself a sufficient guarantee; supplementary measures may be necessary.

In absence of adequacy decision from the European Commission concerning the United Kingdom by the end of the specified period, you should therefore ensure that, in addition to the above-mentioned standard contractual clauses, appropriate supplementary measures (such as encryption of your data) are put in place if necessary in the light of your activity and the new legal order of the United Kingdom.

In this respect, OVHcloud invite you to follow the 01/2020 recommandations adopted on November 10 by the European Data Protection Board (“EDPB”).

Likewise, if you operate from the United Kingdom on the data and solutions that you host as part of your OVHcloud services, or if you use a third party service provider located in the United Kingdom, you should ensure, in the absence of adequacy decision, that the appropriate safeguards are put in place according to article 46 of the GDPR.

OVHcloud also remain at your disposal should you have any questions regarding the security measures implemented by OVHcloud.
You are a customer of OVH Limited, a UK-based entity of OVHcloud.
If you are a customer of OVH Limited, a UK-registered entity of OVHcloud, OVHcloud's UK-based teams may participate in the administration of your services, and as such may perform certain processing activities (data storage, end-of-contract deletion, etc.), which even if performed remotely as part of services hosted in European data centers, may constitute data transfers under the GDPR if no adequacy decision is provided by the Commission.

In addition, as a company governed by English law, OVH Limited falls under the jurisdiction of the United Kingdom, it may have to respond to requests from the authorities of the United Kingdom, notably judicial or governmental authorities, to communicate data hosted by its customers in its services.

Therefore, if the European Commission does not issue an adequacy decision concerning the United Kingdom by the end of the specified period, and you wish to use the OVHcloud services to process personal data submitted to the GDPR, you should, in accordance with Article 46 of the GDPR, ensure that appropriate safeguards are in place.

As such, OVH Limited will support you and implement a data transfer agreement that complies with the standard contractual clauses adopted by the European Commission Decision No. 2010/87/EU of February 5, 2010 (the "Standard Contractual Clauses") or equivalents.

Nevertheless, if in this case, the Standard Contractual Clauses are a necessary prerequisite pursuant to Article 46 of the GDPR, they do not always constitute by themselves a sufficient guarantee. Therefore, it will be up to you to put in place any supplementary measures (such as encryption of your data) that may be necessary in view of your processing activities and the new legal framework of the United Kingdom.

In this respect, OVHcloud invite you to follow the 01/2020 recommandations adopted on November 10 by the European Data Protection Board (“EDPB”).

OVHcloud also remain at your disposal for any questions concerning the security measures implemented by OVHcloud.
Concerning the personal data collected and processed by OVHcloud as “data controller”.
Pursuant to the Terms of Services in force, OVHcloud collects and processes, as data controller, certain data about you, such as your identification information or customer account data, your interactions with the OVHcloud support, your billing data and consumption history, or technical data relating to the use of your Services.

OVH Limited, an OVHcloud entity located in the United Kingdom, may participate in the above data processing activities.

If the European Commission does not provide adequacy decision concerning the United Kingdom by the end of the specified period, OVHcloud will put in place appropriate safeguards in accordance with Article 46 of the GDPR and the commitments stipulated in Part 2 of the Annex "Processing of Personal Data".

For more details regarding the data collected and the processing carried out on such data, you may consult Part 2 of the above-mentioned Annex "Processing of Personal Data"; being specified that the data you host and use in the context of your OVHcloud services are not concerned.

Der Anhang „Verarbeitung personenbezogener Daten“ von OVHcloud wird weiterentwickelt. Die Änderungen gegenüber der Vorgängerversion vom 25. Mai 2018 sind folgende:

  • Weitere Details und mehr Transparenz bezüglich der Datenverarbeitung durch OVHcloud als für die Datenverarbeitung Verantwortliche (siehe Teil 2);
  • Klarstellung des Verfahrens zum Ändern oder Ernennen von Unterauftragnehmern (siehe Artikel 7 „Unterauftragsvergabe“);
  • Vereinfachung des Verfahrens durch die systematische Umsetzung der in der Verordnung (EU) 2016/679 (DSGVO) vorgesehenen angemessenen Garantien, wenn Sie personenbezogene Daten in unseren Rechenzentren hosten, die außerhalb der Europäischen Union liegen;
  • Weitere Informationen zur Kontaktaufnahme mit dem Datenschutzteam von OVHcloud bei allen Fragen zu Ihren persönlichen Daten (siehe Artikel 13 „Kontakt“).

Zugang zur neuen Version des Anhangs „Verarbeitung personenbezogener Daten“ von OVHcloud

OVH wurde 1999 gegründet und ist heute mit Standorten in 19 Ländern einer der weltweit führenden Anbieter im Cloud-Bereich. Die Zufriedenheit unserer über einer Million Kunden und der Schutz ihrer personenbezogenen Daten liegen uns besonders am Herzen.

Laden Sie unsere offizielle Dokumentation herunter

Thumbnail

Wenn Sie sich dazu entscheiden, alle oder einen Teil der in Ihrem Unternehmen verarbeiteten Daten auszulagern und bei OVH zu hosten, vertrauen Sie uns auch einen Teil Ihrer sensibelsten Daten an. Wir sind uns der Herausforderungen bewusst, die eine solche Auslagerung für Ihr Unternehmen bedeuten kann, vor allem, wenn es um die Übereinstimmung mit Datenschutzrichtlinien geht. Aus diesem Grund stellen wir Ihnen möglichst umfassende Informationen zum Schutz personenbezogener Daten zur Verfügung.

Regelungen zum Schutz personenbezogener Daten

Es gibt verschiedene Texte von internationaler, europäischer oder nationaler Reichweite, die für den Schutz personenbezogener Daten einzuhalten sind. Dies sind die wichtigsten:

OVH verpflichtet sich dazu, seine Pflichten gemäß dieser Richtlinien, insbesondere der Datenschutz-Grundverordnung (DSGVO), einzuhalten. Aufgrund dieser Konformität sind auch OVH Kunden dazu in der Lage, einen ersten Teil Ihrer eigenen Verpflichtungen zu erfüllen. Wir empfehlen all unseren Kunden, genauestens auf diese Konformitätsnormen zu achten. Weiterhin können vor allem bei der Erhebung und Verarbeitung bestimmter Arten personenbezogener Daten spezifischere Richtlinien hinzukommen, die es einzuhalten gilt. Das ist beispielsweise der Fall bei Gesundheits- und Militärdaten etc. Es obliegt dem Kunden, die geltenden Bestimmungen für sein Geschäft zu ermitteln und anzuwenden. Die Wahl des richtigen Dienstleisters − gerade im Cloud-Bereich − ist essenziell, um die eigenen Pflichten beim Schutz personenbezogener Daten zu erfüllen.

Der Data Protection Officer (DPO) von OVH: ein Spezialist zur Einhaltung der Datenschutzrichtlinien

„OVH hat sich entschieden, einen DPO zu ernennen, dessen Rolle und Aufgaben zum Teil durch die europäischen Vorschriften bestimmt werden. Der DPO ist vollkommen unabhängig bei der Erfüllung seiner Aufgaben: Er garantiert, dass die internen Datenschutzbestimmungen der OVH Gruppe mit den europäischen Richtlinien übereinstimmen.“

Grégory Gitsels - Data Protection Officer

 

Grégory Gitsels, der DPO bei OVH, verfügt über alle notwendigen Ressourcen, um seine Rolle frei von Interessenskonflikten und vollkommen unabhängig zu erfüllen. Er berät die operativen Mitarbeiter und Führungskräfte des Unternehmens hinsichtlich der Verpflichtungen und Best Practices, die von OVH für den Umgang mit personenbezogenen Daten einzuhalten sind. In der Praxis bedeutet das, er sensibilisiert und schult die Mitarbeiter des Unternehmens, beantwortet Ihre Fragen zum Thema Privacy, ergreift Maßnahmen zu „Privacy by Design" und „Privacy by Default" (vor allem bei der Entwicklung neuer Angebote), pflegt Kontakte zu Aufsichtsbehörden, ... Außerdem ist er der Ansprechpartner für alle Kunden, die Garantien zu den ergriffenen Maßnahmen benötigen, um Ihre Konformität mit Richtlinien wie der DSGVO zu gewährleisten.

Mein Kunden-AccountVertriebskontaktWebmail OVHcloud Blog

Willkommen bei OVHcloud!

Melden Sie sich an, um Ihre Produkte und Dienste zu verwalten sowie Bestellungen aufzugeben und nachzuverfolgen.

Einloggen