fechar
fechar
Sua Rede do Amanhã
Sua Rede do Amanhã
Planeje seu caminho rumo a uma rede mais rápida, segura e resiliente projetada para os aplicativos e usuários aos quais você oferece suporte.
          Experimente a Netskope
          Get Hands-on With the Netskope Platform
          Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
            Líder em SSE. Agora é líder em SASE de fornecedor único.
            Líder em SSE. Agora é líder em SASE de fornecedor único.
            A Netskope estreia como líder no Quadrante Mágico™ do Gartner® para Single-Vendor SASE
              Protegendo a IA generativa para leigos
              Protegendo a IA generativa para leigos
              Learn how your organization can balance the innovative potential of generative AI with robust data security practices.
                Modern data loss prevention (DLP) for Dummies eBook
                Prevenção Contra Perda de Dados (DLP) Moderna para Leigos
                Get tips and tricks for transitioning to a cloud-delivered DLP.
                  Livro SD-WAN moderno para SASE Dummies
                  Modern SD-WAN for SASE Dummies
                  Pare de brincar com sua arquitetura de rede
                    Compreendendo onde estão os riscos
                    Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                        Os 6 casos de uso mais atraentes para substituição completa de VPN herdada
                        Os 6 casos de uso mais atraentes para substituição completa de VPN herdada
                        Netskope One Private Access is the only solution that allows you to retire your VPN for good.
                          A Colgate-Palmolive protege sua “propriedade intelectual "” com proteção de dados inteligente e adaptável
                          A Colgate-Palmolive protege sua “propriedade intelectual "” com proteção de dados inteligente e adaptável
                            Netskope GovCloud
                            Netskope obtém alta autorização do FedRAMP
                            Escolha o Netskope GovCloud para acelerar a transformação de sua agência.
                              Let's Do Great Things Together
                              A estratégia de comercialização da Netskope, focada em Parcerias, permite que nossos Parceiros maximizem seu crescimento e lucratividade enquanto transformam a segurança corporativa.
                                Netskope solutions
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange (CE) provides customers with powerful integration tools to leverage investments across their security posture.
                                  Suporte Técnico Netskope
                                  Suporte Técnico Netskope
                                  Nossos engenheiros de suporte qualificados estão localizados em todo o mundo e têm diversas experiências em segurança de nuvem, rede, virtualização, fornecimento de conteúdo e desenvolvimento de software, garantindo assistência técnica de qualidade e em tempo hábil.
                                    Vídeo da Netskope
                                    Treinamento Netskope
                                    Os treinamentos da Netskope vão ajudar você a ser um especialista em segurança na nuvem. Conte conosco para ajudá-lo a proteger a sua jornada de transformação digital e aproveitar ao máximo as suas aplicações na nuvem, na web e privadas.

                                      New Google Terms of Service – What Do These Changes Mean For UK Organisations?

                                      Feb 27 2020

                                      On 21st February, Google customers in the UK were informed that Google was updating its Terms of Service from 31 March 2020. As of that date, and in response to the UK leaving the EU, the US arm of Google will become the data controller responsible for UK customer data (previously this role was fulfilled within the EU by Google Ireland).

                                      Reaction to this news among CISOs has varied, but I thought it would be useful to capture some items worth thinking about.

                                      Firstly, will this move of Google see an exodus of customers looking for a local service alternative? Probably not.  

                                      For enterprises that are concerned by the US Cloud Act, it’s worth remembering that from a practical point of view the Act requires confirmation that the data subject at the centre of order is a US citizen. Further assessments take place as part of the order, such as whether the request to the cloud provider breaches local law; whether there is an executive agreement in place; whether there are defeating arguments in place against the order; and whether there is a need for a comity analysis by a US court. These steps easily debunk myths that the US Cloud Act simply allows the US to demand access to any information.  

                                      For CISOs whose organisations are still in the EU this February, existing GDPR regulations allow you to store and process data in any jurisdiction as long as that data is processed in compliance with the GDPR. For UK CISOs, this may be the root of a concern, as their organisations move outside of broader EU protection over the coming 12 months. There is a 12 month negotiation period during which all EU protections are still afforded to UK citizens, but by the time the clock runs down we will be hoping to see the UK government review and ratify the Data Protection Act 2018 as part of its comprehensive review of all legislation that is impacted by the country’s exit from the EU. This Act was finalised as the UK enactment of the EU GDPR legislation so should provide a lot of reassurances on data protection, but it will still also need to go to the EU for ratification of ‘adequacy approval’ to confirm its equivalency to GDPR to allow for UK-EU and EU-UK data transfers.

                                      The other item UK CISOs will want to watch in the coming year will be the status of a UK – US Privacy Shield framework agreement. Privacy Shield replaced the US Safe Harbor agreement and promises that “HR and non-HR’” data transferred to the US has the same protection as if it is held in an EU jurisdiction. Until now, UK organisations were able to sign up for EU-US Privacy Shield, but as the UK has left the EU this protection will need clarifying over the next few months. Switzerland has its own Privacy Shield agreement with the US and the most obvious model would be for the UK to do likewise.  

                                      If Privacy Shield is not a consideration, Standard Contractual Clauses (SCCs) are the fall back for organisations wanting a contractual agreement that covers the fundamentals of data protection. A review of existing contracts to determine which international data transfer agreement is in place is recommended. This is definitely worth preparing for as the average enterprise uses 2,415 distinct cloud services and apps – and there is no way at all that these all have a contract in place, with specified contract clauses which conform to organisational and regulatory data protection policies.

                                      Earlier I asserted that we wouldn’t see an exodus of Google’s UK customer base migrating to local service providers, so what do I think we might see? I believe that without a current market dominance in the productivity segment, we will see very large enterprise G Suite customers in a good position to make demands about where their own data is held, even if these demands fall outside of the normal Google operational model. There are significant flagship G Suite customers in the UK and it may be that they can attain exceptions for their own data residency.  

                                      For those G Suite customers who are not so powerful, but are still uncomfortable with their data potentially sitting within the US jurisdiction, I think the EUUG is a fascinating model to consider.  EUUG is the European User Group for Enterprise and Cloud Data Protection, and it was formed initially to give some of Europe’s financial institutions unionised empowerment in negotiations with Microsoft. UK CISOs can perhaps take heart from the naming of this group and the fact that they are still in Europe even if they are no longer in the EU.

                                      In the future, perhaps distrust around international data protection will see more organisational coalitions formed, with cloud customers creating groups of organisations that can resist unilateral decisions around data residency and jurisdiction.

                                      author image
                                      Neil Thacker
                                      Neil Thacker is a veteran information security professional and a data protection and privacy expert well-versed in the European Union GDPR.
                                      Neil Thacker is a veteran information security professional and a data protection and privacy expert well-versed in the European Union GDPR.

                                      Mantenha-se informado!

                                      Assine para receber as últimas novidades do Blog da Netskope