This is going to be interesting, as this renders a number of high-profile service providers (Microsoft, Amazon, etc) unsuitable for anything related to personal data in the EU. I suspect there will be multiple attempts at getting a new treaty in place before there are any actual consequences, though.
That interpretation depends heavily on how much trust you place in the regional concept of data processing. AWS claims compliance with e.g. CISPE [1] which explicitly certifies specific cloud services such as to "Enable(s) data storage and processing exclusively within the EU". AFAIK this agreement applies to the transfer of data out of the EU for processing in the US.
Note that not all AWS services are covered by CISPE. It's intentionally only scoped to low-level IaaS services like EC2/EBS.
Comments
This is going to be interesting, as this renders a number of high-profile service providers (Microsoft, Amazon, etc) unsuitable for anything related to personal data in the EU. I suspect there will be multiple attempts at getting a new treaty in place before there are any actual consequences, though.
That interpretation depends heavily on how much trust you place in the regional concept of data processing. AWS claims compliance with e.g. CISPE [1] which explicitly certifies specific cloud services such as to "Enable(s) data storage and processing exclusively within the EU". AFAIK this agreement applies to the transfer of data out of the EU for processing in the US.
Note that not all AWS services are covered by CISPE. It's intentionally only scoped to low-level IaaS services like EC2/EBS.
[1] https://aws.amazon.com/compliance/cispe/