Cloud computing

We assist businesses with contractual matters and compliance assessments of cloud service agreements, where business continuity, data protection, and vendor dependency converge. We support clients in selecting the type of cloud computing best suited to their objectives and strategic choices. We assist businesses throughout the qualification process for cloud services under ACN requirements, in accordance with the Regulation for Public Administrations on cloud infrastructure and services, and conduct internal audits in preparation for CSA STAR certification.

With the Data Act and DORA, the focus has shifted from contract negotiation alone to risk governance: portability, reversibility, and oversight of critical providers are now obligations, not merely contractual options.

We also provide training on contractual and data protection matters aimed at the proper adoption of cloud computing models.

What we do

  • Cloud contracts — IaaS, PaaS and SaaS; SLAs, exit strategies, and reversibility.
  • ACN qualification — assistance with the qualification of cloud services by ACN.
  • Data governance — data location, data sovereignty, and certifications.
  • Privacy aspects — appointment of data processors, sub-processors, and transfers (Art. 28 GDPR).
  • DORA — oversight of critical ICT third-party providers in the financial sector.
  • Portability and switching — migration and interoperability rights under the Data Act.
  • Business continuity and incidents — management of business continuity and security incidents.

Data Act — Regulation (EU) 2023/2854. Applicable from September 2025, it introduces switching rights between cloud providers, interoperability obligations, and rules on access to data generated by connected devices.
GDPR — Regulation (EU) 2016/679. Article 28 governs the relationship with the provider as data processor and the chain of sub-processors.
DORA — Regulation (EU) 2022/2554. In the financial sector, it governs the oversight of critical third-party providers, including cloud service providers.
Certification and security. The European cybersecurity certification scheme for cloud services (EUCS) is still under development; the Cyber Resilience Act is relevant to components.

How we work

Cloud governance sits at the intersection of contract and architecture: what is negotiated and what is technically feasible must align, otherwise the exit strategy remains on paper.

Would you like to be contacted?


Contact information