The FTC on a Cloud Computing Witch Hunt

Opinion
Jan 11, 20102 mins

Are privacy protection concerns misdirected?

The Federal Trade Commission (FTC) is hosting a roundtable to discuss the privacy concerns of cloud computing. On the surface this looks like a reasonable move since the blogosphere is full of people—yours truly included—raising issues over security and privacy in the cloud. However, my concern is that without focus this will be a misdirected, pointless witch hunt.

The FTC has broad privacy responsibility as set forth in the FTC, Fair Credit Reporting and Children’s Online Privacy Protection Acts. Its sharpest teeth are the safeguards of the Gramm-Leach-Bliley Act (GLBA). The FTC’s concern with cloud computing is centralization of data, on the assumption that this increases the chance of intentional or inadvertent disclosure.

For privacy protection, I have to ask why we’ll treat cloud computing any differently than other types of hosting we’ve been using for the past 20 years? More specifically, don’t GLBA, Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), Family Educational Rights and Privacy Act (FERPA) and last year’s Health Information Technology for Economic and Clinical Health (HITECH) act define ground rules for protecting privacy, regardless of hosting model? The cloud application isn’t compliant if the underlying infrastructure isn’t compliant.

The FTC is munging together “cloud” as a technology (multi-tenant, dynamic, self provisioning and transient computing resources) and cloud as an application (Facebook, MySpace, Google Apps, Salesforce.com, etc.). The FTC must differentiate between the two or this will be a witch hunt leading to more misinformation and misunderstanding about cloud computing risks.