Research Topic
Privacy
Cloud Security Alliance Code of Conduct for GDPR Compliance (Updated - September 2020)
It’s like treating infectious diseases, you can slow them down but it’s a continuous battle.
What you do at work affects personal accounts. Some basic tips: It’s like going to the gym, take it one step at a time. Make your email a fortress. Enable MFA. Complex passwords with a password manager. Don’t be quick to grant permissions.
Why should my organization care about privacy if we have nothing to hide?
Privacy is a foundational property of well-designed systems. It reduces systemic risk, constrains unintended data reuse, limits breach impact, and enables compliance, auditing, and governance at scale. By minimizing unnecessary exposure and enforcing clear data boundaries, privacy enables systems to remain robust under failure, support responsible data sharing, and sustain trust.
Which international organizations does this group overlap with for developing privacy frameworks and standards?
Privacy Level AgreementPrivacyData Privacy EngineeringConfidential Computing
Discuss this topic in Circle
View discussion community
Participate
How to Maintain Privacy in the Cloud
CSA Research crowd-sources the knowledge and expertise of security experts and helps address the challenges and needs they’ve experienced, or seen others experience, within the cybersecurity field. Each publication is vendor-neutral and follows the peer review process outlined in the CSA Research Lifecycle. We recommend getting started by reading the following documents.
CSA Code of Conduct for GDPR Compliance
The CSA Code of Conduct is designed to offer both a compliance tool for GDPR compliance and transparency guidelines regarding the level of data protection offered by the Cloud Service Provider. No matter whether you are an enterprise Data Protection Officer using cloud services or a Cloud Service Provider, the CSA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The code is designed to offer both a compliance tool for GDPR compliance and transparency guidelines regarding the level of data protection offered by the Cloud Service Provider. This can be used to submit a self-assessment to the CSA STAR Registry.
Privacy Level Agreement Code of Conduct Translation in 10 Languages
CSA in the context of an agreement with OneTrust has translated the Privacy Level Agreement Code of Conduct (GDPR Code of Conduct) v3.1 in 10 languages in order to facilitate their easier adoption by organizations in the corresponding countries. Provided translations are in the following languages: Spanish (ES), German (DE), French (FR), Italian (IT), Japanese (JA), Danish (DA), Dutch (NL), Portuguese (PT), Romanian (RO), and Swedish (SV).






