A 10-point checklist for a compliance-ready cloud migration
Cloud migration looks like a technical project, but from a data protection standpoint it is a compliance project. Here are the points to settle before you start.
Cloud migration usually begins as an infrastructure project. Viewed through a data protection lens, however, the same project is a compliance exercise, and most technical decisions carry legal consequences.
1. Build a data inventory. Which system processes which personal data, in which category, on what lawful basis? Without this inventory the migration plan will be incomplete.
2. Confirm data residency in writing. Your provider should contractually commit to where data is physically held. The word "cloud" does not name a location.
3. Clarify whether any cross-border transfer occurs. Backups, log systems and support access are frequently overlooked. If the support team sits abroad, that is access too.
4. Define controller and processor roles. The contract must state clearly which layer belongs to whom; ambiguity becomes expensive at the moment of an incident.
5. Set retention and destruction periods. A backup kept indefinitely creates non-compliance. Define a period for every data category.
6. Simplify access rights before migrating. Do not carry excessive permissions into the cloud; migration is a natural opportunity to clean them up.
7. Settle encryption decisions. Encryption in transit and at rest are separate matters. Determine who holds the keys.
8. Plan logging and traceability. You must be able to answer who accessed which data and when.
9. Refresh your breach notification process. Detecting and reporting a breach works differently in a cloud environment; how quickly the provider will inform you belongs in the contract.
10. Write the exit scenario first. In what format and how quickly you get your data back, and how remaining copies are destroyed, should be clear before you migrate.
Most of these points are contractual rather than technical. That is why having legal and IT in the same room during a migration is far cheaper than correcting matters afterwards.