{"id":1527,"date":"2025-06-11T05:16:16","date_gmt":"2025-06-11T05:16:16","guid":{"rendered":"https:\/\/www.prakantlawoffices.com\/?p=1527"},"modified":"2025-06-11T05:23:59","modified_gmt":"2025-06-11T05:23:59","slug":"who-is-accountable-if-the-cloud-goes-wrong","status":"publish","type":"post","link":"https:\/\/www.prakantlawoffices.com\/index.php\/2025\/06\/11\/who-is-accountable-if-the-cloud-goes-wrong\/","title":{"rendered":"Who is Accountable When The Cloud Goes Wrong?"},"content":{"rendered":"\n<p class=\"has-text-align-left\">Authored by Ms. Gargi Kapoor (Associate at Prakant Law Offices) &amp; Ms. Maitri Khurana (Student at National Law University Odisha)<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"has-text-align-left\">Cloud computing is no longer a buzzword; it\u2019s the quiet backbone of everything we do online. From emails and photos to sensitive government data and financial transactions, it\u2019s all sitting somewhere in \u201cthe cloud.\u201d But as this dependency grows, so do the cracks in the contracts that underpin it.<\/p>\n\n\n\n<p>Let\u2019s be honest: most of us never read cloud service agreements. We click \u201cI agree,\u201d move the operations to AWS, Azure, or Google Cloud, and get on with our days. But these agreements, often dense, one-sided, and boilerplate determine what happens when things go wrong. And that\u2019s exactly where the problem begins.<\/p>\n\n\n\n<p>With the arrival of India\u2019s Digital Personal Data Protection Act, 2023 (\u201c<strong>DPDPA<\/strong>\u201d), the law now clearly spells out who\u2019s responsible for protecting personal data. It places that burden squarely on the Data Fiduciary, usually the business collecting or processing your information.<a href=\"#_ftn1\" id=\"_ftnref1\">[1]<\/a> Supporting the Data Fiduciary is the Data Processor, a third-party service provider like Cloud Service Providers (\u201c<strong>CSP<\/strong>\u201d) who process personal data on behalf of the fiduciary.<a href=\"#_ftn2\" id=\"_ftnref2\">[2]<\/a><\/p>\n\n\n\n<p>But if the business (Fiduciary) is using a cloud provider to store or process your data, and the provider messes up, the business still takes the fall. Section 8 of the DPDPA makes it clear that a Data Fiduciary is liable for compliance even when the processing is carried out by a Data Processor on its behalf.<a href=\"#_ftn3\" id=\"_ftnref3\">[3]<\/a> CSP, the one with the actual control over your data infrastructure remains largely unaccountable unless the contract specifically makes them liable.<a href=\"#_ftn4\" id=\"_ftnref4\">[4]<\/a> And guess what? Most of these contracts don\u2019t.<\/p>\n\n\n\n<p>They\u2019re drafted by the CSPs, not negotiated. They often allow the provider to change terms without notice. They limit or completely waive the CSP\u2019s liability for service disruptions or data breaches. Worse, they typically shift disputes to foreign jurisdictions, making it practically impossible for an Indian user or company to seek recourse.<\/p>\n\n\n\n<p>So, under the current regime, the legal risk lies with the Data Fiduciary, but the operational control lies with the CSP. It\u2019s an accountability mismatch and DPDPA, while well-intentioned, hasn\u2019t resolved it.<\/p>\n\n\n\n<p>Adding to the complexity is the subcontractors. Cloud services today are layered. Your data might be handled by a subcontractor in another country, or even passed along a chain of vendors you\u2019ve never heard of. Yet, as long as you (Data Principal) clicked \u201cagree,\u201d you\u2019re expected to know and control them all.<\/p>\n\n\n\n<p>While DPDPA does allow for cross-border data transfers, regulating it by Section 16, and sector-specific regulators like the RBI impose their own rules (like storing payments data within India), <a href=\"#_ftn5\" id=\"_ftnref5\">[5]<\/a>these rules bring another challenge with the cost of compliance. Localization increases infrastructure costs, especially for Indian startups who depend on global cloud providers to scale quickly.<a href=\"#_ftn6\" id=\"_ftnref6\">[6]<\/a><\/p>\n\n\n\n<p>This isn\u2019t just a tech issue, it\u2019s a legal and policy vacuum. The cloud has evolved, but our contracts haven\u2019t. If India is serious about digital sovereignty, privacy rights, and building a startup ecosystem that\u2019s both competitive and compliant, then the law needs to extend beyond just regulating data fiduciaries. It needs to reimagine cloud contracts.<\/p>\n\n\n\n<p>This could mean mandating transparency about subcontracting, standardizing core terms around liability and jurisdiction, or even empowering regulators to issue model cloud agreements. But more than anything, it means recognizing that cloud providers aren\u2019t just vendors, they\u2019re critical infrastructure operators. And in a world where data is power, they can\u2019t be allowed to operate in legal grey zones. Because when the cloud goes wrong, someone has to be held accountable.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><a href=\"#_ftnref1\" id=\"_ftn1\">[1]<\/a> Section 2(i) of the DPDPA, a Data Fiduciary is any person or entity that determines the purpose and means of processing your personal data. On the other side of the relationship is the Data Principal (customer), the individual whose personal data is being collected, as defined under Section 2(j).<\/p>\n\n\n\n<p>The DPDPA puts a duty on fiduciaries to process data only with the principal\u2019s free, informed, and unambiguous consent as per Section 6 and for lawful, specified purposes. It provides that the consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.<\/p>\n\n\n\n<p><a href=\"#_ftnref2\" id=\"_ftn2\">[2]<\/a> Section 2(k) of the DPDPA defines that a Data Processor is anyone who processes personal data personal data on behalf of a Data Fiduciary.<\/p>\n\n\n\n<p><a href=\"#_ftnref3\" id=\"_ftn3\">[3]<\/a> The Digital Personal Data Protection Act, 2023 \u00a78.<\/p>\n\n\n\n<p><a href=\"#_ftnref4\" id=\"_ftn4\">[4]<\/a> T Lynn, \u2018Dear Cloud, I Think We Have Trust Issues: Cloud Computing Contracts and Trust\u2019 in T Lynn, JG Mooney, L van der Werff and G Fox (eds), <em>Data Privacy and Trust in Cloud Computing<\/em> (Palgrave Macmillan 2021).<\/p>\n\n\n\n<p><a href=\"#_ftnref5\" id=\"_ftn5\">[5]<\/a> Reserve Bank of India, \u2018Storage of Payment System Data\u2019.<\/p>\n\n\n\n<p><a href=\"#_ftnref6\" id=\"_ftn6\">[6]<\/a> Justice B.N. Srikrishna Committee, <em>White Paper on Data Protection Framework for India<\/em> (27 November 2017).<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authored by Ms. Gargi Kapoor (Associate at Prakant Law Offices) &amp; Ms. Maitri Khurana (Student at National Law University Odisha) Cloud computing is no longer a buzzword; it\u2019s the quiet backbone of everything we do online. From emails and photos to sensitive government data and financial transactions, it\u2019s all sitting somewhere in \u201cthe cloud.\u201d But [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[13,15,14,12,11],"class_list":["post-1527","post","type-post","status-publish","format-standard","hentry","category-blog","tag-cloud-computing","tag-data-protection","tag-dpdp-act","tag-privacy","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/posts\/1527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/comments?post=1527"}],"version-history":[{"count":3,"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/posts\/1527\/revisions"}],"predecessor-version":[{"id":1530,"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/posts\/1527\/revisions\/1530"}],"wp:attachment":[{"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/media?parent=1527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/categories?post=1527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prakantlawoffices.com\/index.php\/wp-json\/wp\/v2\/tags?post=1527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}