openstack-manuals/doc/arch-design-draft/source/legal-requirements.rst
daz 86526ea775 [arch-design-draft] Add legal content
Migrate legal content from the  current guide to the draft guide

Change-Id: I38d6bf96704a0e77419f067e47eb26da7a69b308
Implements: blueprint arch-guide-mitaka-reorg
2015-12-22 17:15:23 +11:00

1.3 KiB

Legal requirements

Most countries have legislative and regulatory requirements governing the storage and management of data in cloud environments. This is particularly relevant for public, community and hybrid cloud models, to ensure data privacy and protection for organizations using a third party cloud provider.

Common areas of regulation include:

  • Data retention policies ensuring storage of persistent data and records management to meet data archival requirements.
  • Data ownership policies governing the possession and responsibility for data.
  • Data sovereignty policies governing the storage of data in foreign countries or otherwise separate jurisdictions.
  • Data compliance policies governing certain types of information needing to reside in certain locations due to regulatory issues - and more importantly, cannot reside in other locations for the same reason.

Examples of such legal frameworks include the data protection framework of the European Union, and the requirements of the Financial Industry Regulatory Authority in the United States. Consult a local regulatory body for more information.