This report examines the use of cloud-based services by public sector entities across the EU. It evaluates compliance with GDPR, focusing on contractual arrangements, data transfers, and the security of data processing. The document highlights common shortcomings, such as inadequate data protection clauses, lack of proper risk assessments, and non-compliance with international data transfer requirements. Recommendations emphasize the need for stronger safeguards, detailed risk evaluations, and compliance with GDPR principles to ensure the lawful use of cloud services.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2023-01-17
Last updated: 08 Aug 2025
Category: Miscellaneous
Subcategory: Report