The triumvirate of cloud providers — Amazon, Google, and Microsoft — and a handful of major enterprise software and infrastructure vendors formed the Trusted Cloud Principles initiative to advocate for data privacy and human rights protections in the cloud era. 

Recognizing individuals' privacy under international human rights law forms the foundation of the effort, which the group describes as an expansion of pre-existing commitments.

The alliance, which also includes Atlassian, Cisco, IBM, Salesforce, and SAP, highlighted concerns over governments that “seek to gain access to data under laws that do not adequately protect human rights and the rule of law, and conflict with laws of other countries.”

The cloud service providers pledged to protect the “privacy and security of our customers’ data in all jurisdictions through policy and technology.” The group of nine also committed to lobby governments, and work with other tech companies and public interest groups to ensure the free flow of data, promote public safety, and protect privacy and data security in the cloud.

Each of the signatory companies follow internal procedures when governments request data and respond accordingly. This effort aims to more broadly highlight shared concerns and specific principles the companies hope to be enacted globally. 

“While I believe the intentions are in the right place, it’s easy to see the myriad things that can go wrong. I think it’s easier to write principles than it is to live by them,” Maribel Lopez, founder and principal analyst at Lopez Research, wrote in response to questions. 

“What is considered a reasonable government request?” she asked. “And if the government disagrees with you, how far are you willing to go? At least we’re starting a dialogue that allows for pushback.”

For what it’s worth, the companies committed to five principles:

  • Governments should engage customers first, with only narrow exceptions.
  • Customers should have a right to notice.
  • Cloud providers should have a right to protect customers’ interests.
  • Governments should address conflicts of law.
  • Governments should support cross-border data flows.

The coalition noted that every company involved already seeks to live by these principles every day, adding “we believe there is tremendous value in standing up for them together. These principles are the beginning of a journey and not a destination, and we may add to them over time.”

The group, while representing many of the largest cloud companies, could also bolster its effort by attracting other signatories. 

“Cloud providers will jump on board in principle. In practice it remains to be seen and they will always protect their interests. Regional behavior may vary,” Sid Nag, Gartner’s VP of cloud services and technologies, wrote in response to questions. 

The companies have little leverage to push governments to follow and adhere to basic international human rights accords, he said, adding that customers can also voice their support for these principles.

One of the signatories, Cisco, also recently published a New Trust Standard framework designed to assess an organization’s trustworthiness and reach like-minded agreements with its customers and suppliers. 

A spokesperson for Trusted Cloud Principles concluded: “When governments come directly to providers like us for requesting access to customer data without their knowledge — in some cases for legitimate reasons but in other cases for reasons that could hinder basic human rights — it creates a tension that needs to be addressed through both technology and policies."