Cloud 101CircleEventsBlog
Register for CSA’s free Virtual Cloud Trust Summit to tackle enterprise challenges in cloud assurance.

CSA Official Press Release

Published 09/20/2023

EU Cloud Code of Conduct Collaborates with Cloud Security Alliance to Further Harmonize GDPR Compliance

EU Cloud Code of Conduct Collaborates with Cloud Security Alliance to Further Harmonize GDPR Compliance

New collaboration to further harmonize GDPR compliance

Brussels and Seattle – Sept. 20, 2023 – Starting in November 2023 and through a specific framework, the Cloud Security Alliance (CSA) community will have access to an approved and European Data Protection Board (EDPB)-endorsed GDPR compliance solution designed for the cloud.

On one side of this collaboration, we have the EU Cloud Code of Conduct (EU Cloud CoC), a pioneer initiative and market standard for robust data protection within the cloud sector. On the other, we have the Cloud Security Alliance (CSA), a global leader widely reputed for the development and administration of various IT and cyber security certifications.

It is exactly this mutual mission of developing effective and accessible standards for the cloud industry that constitutes the very foundation of this collaboration. Against this background, the EU Cloud CoC and CSA are joining forces to enable trust building and, ultimately, the broader dissemination of cloud services globally.

Concretely, this step will allow the CSA community to declare adherence to the EU Cloud CoC via the platform. In this context, Cloud Service Providers that have successfully completed their GDPR verification by the accredited Monitoring Body of the Code, SCOPE Europe, will have their compliance mark displayed in the STAR Registry, a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings.

This initiative is an essential resource for cloud users, empowering them to gain a thorough understanding of available offerings through the Registry and enabling them to make informed choices when seeking cloud services.

Finally, given the abundant synergies driving this collaboration, that derive from both parties’ strong commitment to best practices in compliance, the goal is to work continuously for the design of robust cloud-specific instruments.

Addressing this achievement, Jim Reavis, CEO and co-founder, Cloud Security Alliance: "Our mission at CSA is to assist companies in ensuring a secure cloud computing environment, while simultaneously adhering to often-complex data privacy regulations. With this collaboration, it will now be even easier for companies around the globe to assess a cloud service provider's adherence to cloud security and data privacy best practices."

Gabriela Mercuri, Managing Director of SCOPE Europe, added: "The materialization of this collaboration is a product of a meaningful exchange between the two organizations, our shared values and objectives when it comes to the development of robust and workable industry standards. As SCOPE Europe, we firmly believe this collaboration will foster trust in cloud services and enable businesses to innovate and growth through the deployment of this key technology."

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at, and follow us on Twitter @cloudsa.

About the EU Cloud Code of Conduct
The EU Cloud Code of Conduct is an approved and fully legally operational Code of Conduct pursuant to Article 40 GDPR. Defining clear requirements for Cloud Service Providers to implement Article 28 GDPR, the Code covers all cloud service layers (IaaS, PaaS, SaaS), has its compliance overseen by an accredited monitoring body, and represents the vast majority of the European cloud industry market share.

Media Contacts
Kristina Rundquist
ZAG Communications for CSA
[email protected]

Amanda Miteniece
SCOPE Europe
[email protected]

Share this content on your favorite social network today!

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.

For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.