Skip to content

GDPR and cloud tools: what SMBs need to know

Practical GDPR compliance guide for SMBs using cloud tools: Google Workspace, AWS and Shopify. Obligations, best practices and pitfalls to avoid.

Updated on 3 October 2023

GDPR applies in the cloud too

The General Data Protection Regulation applies to any company that processes the personal data of European residents, whatever the tool used. Using Google Workspace, AWS or Shopify does not exempt you from your obligations. These providers act as processors of your data, but you remain responsible for the processing. This guide clarifies your obligations and the best practices to put in place.

Your role and your cloud provider’s role

The GDPR distinguishes between the data controller (you) and the processor (your cloud provider). You decide which data to collect, why and how to process it. Your cloud provider processes the data according to your instructions and commits contractually to protection measures.

Each cloud provider offers a data processing addendum (DPA) that formalizes these commitments. Google Workspace, AWS and Shopify all have a GDPR-compliant DPA. Verify that you have accepted the DPA of each provider you use.

Concrete obligations for SMBs

Processing register

Document each processing activity involving personal data: which data, for what purpose, on what legal basis, for what retention period and with which processors. This register is mandatory for all companies, whatever their size.

Informing individuals

Inform the individuals whose data you process: customers, prospects, employees. Your privacy policy must be clear, accessible and complete. It must mention the cloud processors you use and any data transfers outside the EU.

Individual rights

Set up procedures to respond to requests to exercise rights: access, rectification, deletion, portability. You have one month to respond. Google Workspace and Shopify provide tools to export and delete a user’s data.

Data security

Set up security measures suited to the risks: encryption, access control, backups, monitoring. Cloud providers secure the infrastructure, but the configuration and usage are your responsibility.

Best practices by tool

Google Workspace

Enable 2FA for all users, configure data regions to store data in Europe, limit external file sharing and set up a data retention policy with Google Vault.

AWS

Encrypt data at rest and in transit, use IAM with the principle of least privilege, enable CloudTrail for auditing and configure AWS Config to monitor your infrastructure’s compliance.

Shopify

Configure your privacy policy and your cookie consent banner, limit data collection to what is strictly necessary, and set up procedures to delete customer data on request.

LCMH supports SMBs in GDPR compliance for their cloud tools.

To go further on Google Workspace security, read our article on data protection in Google Workspace.


Sources

  1. CNIL, GDPR: Where to Start. cnil.fr/fr/rgpd-par-ou-commencer
  2. CNIL, Using Data Processors. cnil.fr/fr/sous-traitance
  3. Google, GDPR and Google Workspace. cloud.google.com/privacy/gdpr

Frequently asked questions

Are US cloud tools GDPR-compliant?
The main cloud providers (AWS, Google, Microsoft) have adapted their services to the GDPR with data processing addendums (DPA), standard contractual clauses and storage options in Europe. Compliance also depends on your configuration and your internal practices.
Do you need a DPO to use cloud tools?
Appointing a DPO (Data Protection Officer) is mandatory for public bodies and for companies whose core activity involves large-scale, regular and systematic monitoring of individuals. For most SMBs, an internal GDPR contact is enough.
What should you do in case of a data breach in the cloud?
You must notify the CNIL, the French data protection authority, within 72 hours of discovering the breach if it presents a risk to individuals' rights. If the risk is high, you must also inform the individuals concerned. Document the incident, the measures taken and the consequences.

Related Articles