Make sure no one has unwanted access to your data!
11 June 2025Data is one of the most valuable assets of an organization. Do you know where and how this data is stored? More and more organizations rely on American Cloud providers such as Microsoft, Google and Amazon, but this entails serious privacy risks. Make sure no one has unwanted access to your data!
American legislation can make your data inaccessible
The Cloud Act gives American authorities access to data stored with American companies, regardless of where the servers are located. This means that even if a European organization stores its data in a data center within the EU, American intelligence services can still gain access.
This creates a conflict between American legislation and European regulations, which entails serious privacy and security risks.
Recently, a public prosecutor of the ICC was denied access to his email by Microsoft. The sanctions were imposed by the US after the ICC issued arrest warrants against Israeli Prime Minister Benjamin Netanyahu and former Defense Minister Yoav Gallant. As a result, American providers such as Microsoft can be fined if they continue to provide services to the ICC.
What Cloud solutions are there?
- Public cloud is a cloud environment that you share with multiple organizations. Examples are Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform.
- Private cloud is a cloud environment used exclusively for your organization. This gives you more control over security and data, and can be hosted on-premise (at the organization itself) or by an external service provider.
- Hybrid cloud combines both public and private cloud environments. You can then keep sensitive data in the private cloud and store less sensitive data in the public cloud.
- Multi-cloud is a combination of multiple cloud services from different providers. This can help spread risks and leverage the best technologies from different providers.
What can you do if your data is in an American cloud?
- Choose a Dutch host! Or at least move to a European location to safeguard the privacy of data, users and employees. Here the GDPR regulations apply, which European organizations must comply with. Unfortunately, it still falls under the Freedom Act when the data is with an American company. A European Cloud provider as large as Microsoft, Amazon or Google unfortunately does not yet exist.
- Ensure that the MSP (the Cloud provider) is at least ISO 27001 certified.
- Ensure that the data is encrypted, making it better protected against unwanted access.
- Create awareness within your company and explain the risks of the American cloud.
How do you choose the right solution?
We are happy to help you choose the right solution. This depends on various factors specific to your organization and needs.
After assessing your needs regarding scalability, security and investment budget, we advise you on which type of solution best suits your organization. This depends, among other things, on the desired flexibility and whether you want to have control over data and infrastructure yourself.
Do you choose SaaS, PaaS or IaaS?
There are various ready-made cloud software solutions available with services that are interesting for every organization. Do you opt for a standard package or do you want custom software developed? Do you need help choosing the package? Do you want control over virtual machines and infrastructure yourself? Ask your MSP for help, then you can be sure you are making the right choice.
Choice for a Managed Service Provider (MSP)
Choose a reliable Managed Service Provider and ask about uptime guarantees. Are there Service Level Agreements (SLAs) and is there 24/7 support? Is there an ISO 27001 certification?
In conclusion
Infracom offers its own Dutch cloud environment that many of its customers use. We are an ISO 27001 certified Dutch host.