3. The Opportunities and Challenges of Cloud Computing
3. The Opportunities and Challenges of Cloud
Computing
The adoption of new digital technologies, and the challenges arising from it are the subject of important
EU regulations such as, among others, Regulations (EU) 2016/679 and 2018/1807 (known as GDPR and
free flow of non-personal data), Directive 2016/1148 (known as the NIS Directive), and national security
legislation, such as Law 133/2019 (National Security Perimeter for Cyber (Perimetro di Sicurezza Nazionale
Cibernetica, PSNC) 2.
3.1 Technological Autonomy
In order to govern and manage the country’s digital transformation processes, as recognised by the main
European institutions, autonomy in the control of the digital infrastructure of the Cloud and, consequently,
of the storage and processing of data appears to have enormous strategic importance3.
It is well known, however, that the market shares of European companies’ Cloud infrastructures represent
a residual value (less than 10%) compared to those held by non-EU companies4. However, this criticality
is not only limited to digital services and platforms, but also, and most importantly, to the infrastructures
that enable them to function.
Given such a contractual weakness of the EU, the massive adoption of Cloud technology for the provision
of PA services is subject to risks such as in the case of unilateral changes in the terms of services: increased
costs or service interruption, or to actions that are potentially beyond the control of the country. Achieving
technological autonomy has important implications, not only in terms of the possibility of exerting
direct control over data and services, but also in terms of promoting an ecosystem of technologies
(Cloud Computing, IoT, Artificial Intelligence, Quantum Computing) which is essential for the country’s
development.
3.2 Control over Data
The operation of cloud services by providers in non-EU countries poses an additional risk due to the
regulations in place in those countries. As it is well known, non-EU legislation5 may allow - provided certain
circumstances - unilateral requests to the CSP to provide access to data. These cases involve the possibility
for a non-EU country to access data (or data flows) that are particularly sensitive and strategic for the
EU Member States’ citizens and institutions. In this perspective, within the framework of the strategy, it is
necessary to clearly determine - via a classification procedure - the types of data that can be managed
by a non-EU provider through a Public Cloud and which data instead will need to be managed by a
Cloud provider that meets specific security requirements in order to reduce the risk that the data may
be accessible to non-EU governments. The management of such risks does have, inevitably, not only
technological but also geopolitical implications that should receive adequate consideration.
2
Conversion into law, with amendments, of Leg. Decree 21 September 2019, no. 105, on urgent provisions
concerning the National Cyber Security Perimeter.
3
OECD (2019) Regulation and IRC: challenges posed by the digital transformation. 20th meeting of the
Regulatory Policy Committee, 17-18 April 2018, OECD Conference Centre, Paris, France.
4
See,
for
example,
https://www.gartner.com/en/newsroom/press-releases/2019-07-29-gartner-saysworldwide- iaas-public-cloud-services-market-grew-31point3-percent-in-2018 and https://www.idc.com/getdoc.
jsp?containerId=prUS45552219 and https://www.forbes.com/sites/steveandriole/2019/11/20/forrester-research-getscloud--computing-trends-right/#5b30ee4468a2.
5
Examples are the National Intelligence Law of the People’s Republic of China, the Clarifying Lawful Overseas
Use of Data Act (CLOUD Act) or the Foreign Intelligence Surveillance (FISA).
7