| Sumario: | Contemporary developments in information and communication technologies make “command and control”-based legislation, for example, EU Directive 95/46/EC, a decreasingly credible means of providing appropriate privacy protection for personally identifiable information (PII) across wide areas of commercial activity. Current legislation provides limited transparency and oversight, fails to encourage privacy innovation, and lacks the flexibility to effectively and efficiently regulate new technologies and globalized business practices. There is a growing consensus that regional, and ultimately global, data privacy regimes will have to adopt new regulatory approaches, and that such approaches should incorporate, as a key element, a greater focus on “accountability”. This raises two key questions: what is meant by “accountability”, and how might it translate into practical mechanisms for achieving privacy protection? This article considers these questions in the context of “cloud computing”, examining how procedural and technical solutions can be co-designed to demonstrate accountability in order to resolve jurisdictional privacy and security risks within the cloud.
|