Use our LinkedIn Login to download this post to PDF or save it to MyLibrary!
With the rate of change in technology happening as quickly as it is today, legal concerns are building up everywhere.
Both cannot keep pace with how fast things are suddenly happening.
And given Moore’s Law, this pace is not about to slow down either — which also means there are going to be some headaches as well as opportunities in dealing with the legal circles…
Identify the Constants
No matter how fast anything changes there are some constants that must be taken into account.
As cloud computing gets its name from the fact that everything you do seems to be available anywhere, then where is your data really located?
How is it being stored?
Who is responsible for its security?
Laws are usually based upon entities and/or sovereignties and it creates boundaries in which the protection of the law is supposed to be applied.
Given the nature of cloud computing then, a key question about cloud computing remains unresolved in the law books as well the courts.
Questions as to which law applies to your organization’s data in the cloud are basically simple:
The law as applied to where you are located?
The law as applied to where your data is located? Or
The law where the data subject is located?
The answers, however, are not simple.
Especially if you have cloud services in other countries, international consensus on this issue has not yet been tested.
Verify Affects of Geographic Region
As most contracts provide which laws under which any disputes could be resolved, and the location of the court where such disputes could be heard, it’s essential for a cloud-computing contract to identify the geographic region within which the data centers hosting your data, and potentially the headquarters of the cloud provider, may be located, and to address the cloud provider’s obligations to keep your data in those regions.
Otherwise, the overlaps and potential conflicts between the possible governing laws could make legal and data access compliance impossible.
Controlling 3rd Party Access to Your Data?
As risk management focuses on retaining some measure of control, your contract with the cloud provider should require the cloud provider to notify you regarding its receipt of any 3rd party request to access your data.
Be sure to specify the time frame within which such notice should be provided.
post continues after these free offers
Today's Featured Free Offer
You're Doing it Wrong
Change Management for Your Organization
I am a recovering change management consultant. Over the last 20 years or so, I’ve focused my career primarily in the people change management space. My job was to help companies realize the ROI of their multi-million dollar investments – whether they be investments in organizational redesign, new systems or large scale business transformations – by mitigating resistance, creating buy-in and driving adoption. The way to do that was to get the people on-board with what was happening. If they stopped resisting what was inevitable and just adopted the change, then all would be right in the “corporate” world. And I use the term “corporate” as a catch-all. These challenges and my project work spanned industries and organizations, from non-profit and government to privately owned and publicly traded enterprises.
The challenge is and always will be people. People will make or break the success of any change a company wants to make. So my job was part data analysis, part coaching, part writing, part training and part shrink. Get into the heads of the people to figure out what they wanted and find a way to make this change something they want. Or better yet – need. Call it marketing. Call it change management. Call it what you want. No matter how you slice and dice it, or whatever you call it, I was doing it wrong. And so are you.
If we apply the “Ask, Listen and Do” mindset to this problem, we as change management professionals can increase our effectiveness while enabling organizations to actually realize the ROI of their big dollar investments.
Let’s look at 2 different change management models to see the difference and similarities: Lewin's Change Management Model and Prosci's ADKAR Model and 3-Phase Process.
Offered Free by: POPin
post continues from above
And make it paramount that in ALL cases notice should be given ahead of granting access to any of your organization’s data.
Also, make your cloud provider to make an obligation to limit the disclosure of your data to the extent legally possible, and to cooperate with your efforts to appropriately manage the release of any data.
The Last Word
Most of this can be performed proactively by a due diligence investigations of the cloud provider’s standard practices and procedures.
These will reveal that it has a policy in place that meets your data access requirements, and you should codify this in the contract, and include a copy of that policy as an attachment.
Credit is due to Thomas Trappler for sharing much of this information. Thomas is the director of software licensing at the University of California, Los Angeles, and a nationally recognized expert, consultant and published author in cloud computing risk mitigation via contract negotiation and vendor. He offers several guides to cloud computing contracts.
Discover More About Our Project Insights Series
More Content In This Series…
- 5 Strong Reasons Your Company Should Move to Agile Development
- HR and IT Need to Combine Efforts on Workforce Analytics
- Tips On Picking The Right Project Manager
- Our Top 25 Viewed Posts for 2016
- Introducing Our Features for Everyone
- HR Software Solutions Renews Its Relationship with The HRIS World
- Is Your HR Management Strategizing for Success?
- The Myths Many Believe About Home Office…
- Is ‘Which Project Methodology is Best?’ the Right Question?
- Big Data for Predicting Job Performance: Big Dollar$? or Big Whup ?
- Online Service for Booking SAP Consultants
- What Is the Key to Fully Utilizing Big Data in HR?
- How Do You Know When You Are Asking the Right Questions?
- Just What Is HRIS? (Intro Part 1 of 6)
- Is The Rate of Change in Technology Initiating Legal Concerns?
- Performing a Needs Assessment on Project Management (Intro Part 4 of 6)
- The Role of a Product Owner in Agile Projects
- Can You Name the 7 Steps to Effective Project Management?
- Your Guide to Effectiveness: 5 Top Process Improvement Books
- Is Your HRIS Up to Par?
- Reassessing the Management in Project Management (Intro Part 5 of 6)
- Need Help Searching for a Payroll Service Provider?
- HR Undercover: Buying Software (Part 2 of 3)
- No Time to Document Business Processes? Really??
- Avoiding Common End-User Training Mistakes
- Should You Try to Learn Six Sigma on Your Own?
- Lean Six Sigma vs. Six Sigma – Which Is for You?
- Looking at Project Management From Outside the Box (Intro Part 6 of 6)
- How Cloud Service Interruptions Are Only Symbolic
- The Key Components of Solid End-User Training
- How to Ensure A Successful HRIS Implementation – Part 2 of 2
- Open Source HR Software? or Closed Source? Which Shall It Be?
- A Beginner’s Guide to Cloud Applicant Tracking Systems
- What is Business Process Reengineering?
- How Mobile Technology Can Improve Your Recruitment Process
- Manage Your Project’s Expectations Before They Manage You — In Court…
- Managing Conflicts Within Your Team
- How Big Data Can Refine Recruiting
- Would These 2 Things Make a Difference in Your Projects?
- Can Feasibility Studies Be Contributing to Implementation Pains?
- Managing A Global Workforce
- The Importance of Keeping Users in Mind When Adopting New HR Tech
- Analytics Can Help Keep Your Company Strong
- Will Technology Take Over Recruiting?
- Why All the Pain When It Comes to Implementations?
- The Evolution of HR Technology
- Why Are Implementation Costs Higher Than Initial Estimates?
- HR Undercover: Replace Your System Not Your Staff (Part 3 of 3)
- Systematic & Effective Planning for Your HRIS Project (Intro Part 3 of 6)
- BEFORE Searching for A New HRIS System (Intro Part 2 of 6)
- RFP? Or Scenario? Which Shall It Be?
- HR Undercover: Challenge and Change (Part 1 of 3)
- How Do You Reduce the Implementation Pain Points? (part 2)
- How Do You Reduce the Implementation Pain Points? (part 1)
- How To Discern Between A Trend and A Fad?
- Embracing Agile Business: Is Your Company Agile Enough to Thrive?
- How to Ensure A Successful HRIS Implementation – Part 1 of 2
- Can You List 5 Not-So-Obvious Benefits of Using Six Sigma?
- You Need to Find the Ideal Data Integration Software Provider, But How?
- How Basecamp Impacts Project Management Execution
- Basecamp Will Definitely Change the Way You Do Project Management
- Why Add Customer Feedback to the SLCD?
- Applying Six Sigma to Transactions and Services
- Great Project Management? Strategy and Vision, Not Ownership of Results
- Why Process Management and Improvement is Becoming Paramount
- Are You Learning Project Management the Right Way?
- How Do You Overcome the Change Management Process?
- Obtain A PMP Certification While Maintaining Your Work Schedule
- Troubleshooting and Business Processes in the Cloud Are… Different
- Need a KPI Template? We Have More than 15,000 KPI’s for You!
- The King of ROI is Beyond Knowledge and Great Skill Sets
- What Can Happen When the RFI is Overlooked
- How PMP Certification Can Enhance Career Prospects
- Get – and Keep – Your Project Management Certification
Our Social Media Presence
Where to Follow Us!
Garrett is the publisher, editor, writer forThe HRIS World Research Group, which includes The HRIS World, The HRIS World Research, The HRIS World Jobs, The HRIS World News, and The HRIS World Videos
With more than 20 years in roles as a client executive sponsor (#thwCES), project manager as well as functional / technical lead, Garrett is sought for his expertise for project insights, thought leadership, and team management globally.
He has been involved in large-scale and complex implementations since 1991 and has recently moved his operations to be with his wife in Brazil.
Garrett has had the pleasure of working with some of the greatest talents in the industry, and constantly shares his experiences and knowledge through content and webinars.
He maintains his fluency in Portuguese, German, French, and English with his various endeavors and contacts..
When not working, you will have to be adventurous to stay up with him as Garrett loves motorcycling, gunnery, boating, sailing, flying, and sports fishing -- and accompanying his wife on her various likes
About The HRIS World Research Group
The HRIS World blog, which is read by more than 50,000 from more than 160 countries monthly, manages to have more than 550,000 pages viewed monthly. 40%+ of the audience are decision-makers in their organization (and about half of that being C-levels!).
As CEO for CGServices USA Inc, he focuses on multi-provider, multi-line implementations consultation for HRIS systems
Council and Education Member of Gerson Lehrman Group Council, helping institutions of the world leaders meet, engage and manage experts across a wide range of sectors and disciplines.
Your Invite to Contribute to The HRIS World blog
If you'd like to provide a post, a series of posts, or even be a regular contributor to any of The HRIS World blogs, click the blue contact us button on the bottom right of your screen to send us a message or reach us through our social media for details...
You can always contact Garrett via email, social media, or by leaving a comment below...
Latest posts by Garrett O'Brien (see all)
- Shouldn’t feel guilty about coffee addiction? Even just a little? - Wed, 26-Apr-2017
- Stop Being Tracked on ALL Your Browsers with ONE Plugin - Tue, 25-Apr-2017
- Searching with the Right Keywords and the Right Technique? - Mon, 24-Apr-2017
- The Top 10 Qualities That Influence Millennials In Their Choice of Company - Mon, 17-Apr-2017
- How Cybercrime Can Impact Human Resources and Your Business - Mon, 10-Apr-2017