MarketplaceCommunityDEENDEENProductsCloud ServicesRoadmapRelease NotesService descriptionCertifications and attestationsManaged ServicesBenefitsSecurity/DSGVOSustainabilityOpenStackMarket leaderBusiness NavigatorPricesPricing modelsComputing & ContainersStorageNetworkDatabase & AnalysisSecurityManagement & ApplicationsPrice calculatorSolutionsIndustriesHealthcarePublic SectorScience and researchAutomotiveMedia and broadcastingRetailUse CasesArtificial intelligenceHigh Performance ComputingBig data and analyticsInternet of ThingsDisaster RecoveryData StorageTurnkey solutionsTelekom cloud solutionsPartner cloud solutionsSwiss Open Telekom CloudReferencesPartnerCIRCLE PartnerTECH PartnerBecome a partnerAcademyTraining & certificationsEssentials trainingFundamentals training coursePractitioner online self-trainingArchitect training courseCertificationsCommunityCommunity blogsCommunity eventsLibraryStudies and whitepaperWebinarsBusiness NavigatorMarketplaceSupportSupport from expertsAI chatbotShared ResponsibilityGuidelines for Security Testing (Penetration Tests)Mobile AppHelp toolsFirst stepsTutorialStatus DashboardFAQTechnical documentationNewsBlogFairs & eventsTrade pressPress inquiriesRadio OTCMarketplaceCommunity

0800 3304477 24 hours a day, seven days a week

Write an E-mail 

Book now and claim starting credit of EUR 250
ProductsCloud ServicesManaged ServicesBenefitsBusiness NavigatorPricesPricing modelsPrice calculatorSolutionsIndustriesUse CasesTurnkey solutionsSwiss Open Telekom CloudReferencesPartnerCIRCLE PartnerTECH PartnerBecome a partnerAcademyTraining & certificationsCommunityLibraryBusiness NavigatorMarketplaceSupportSupport from expertsHelp toolsTechnical documentationNewsBlogFairs & eventsTrade pressPress inquiriesRadio OTC
  • 0800 330447724 hours a day, seven days a week
  • Write an E-mail 
Book now and claim starting credit of EUR 250

Meeting data protection requirements with the cloud

by Redaktion
EU Cloud Code of Conduct logo in front of a stylized world map, symbolizing data protection and cloud compliance in the Open Telekom Cloud.
EU Cloud Code of Conduct: Data protection standard also met by the Open Telekom Cloud.
 

In this article, you will learn

  • which data protection certifications cloud users should look for,
  • the certification strategy followed by the Open Telekom Cloud,
  • and which additional agreements are important for professionals bound by confidentiality or involved in processing social data.

One of the most fundamental and frequently asked compliance questions regarding the cloud is:  "Can personal data be processed in the cloud?" or "How is data protection handled in the cloud?"

GDPR is key – how do cloud providers demonstrate their GDPR compliance?

Since 2018, the EU GDPR (General Data Protection Regulation) has been the central framework for data protection in Europe. In response, SCOPE Europe—together with cloud providers and EU authorities—developed a code of conduct: the EU Data Protection Code of Conduct for Cloud Service Providers, commonly referred to as the EU Cloud Code of Conduct (EU Cloud COC). The purpose of the EU Cloud COC is to ensure consistent application of European data protection standards in cloud computing, in line with the GDPR.

The EU Cloud COC defines the rights and obligations concerning the handling of personal data in the cloud. It specifically refers to Articles 28 and 40 of the GDPR. Article 28 regulates personal data processing in outsourcing scenarios (such as cloud services) and sets clear rules for cloud service providers. Article 40 allows industries (like cloud providers) to support GDPR compliance by establishing their own codes of conduct.  

For years, the EU Cloud COC was one of the most prominent proofs of a cloud provider’s GDPR compliance. Regular audits by independent bodies make it a reliable and binding quality assurance tool. Over time, additional certifications and attestations have emerged, further confirming compliance with data protection requirements. Among these, ISO/IEC 27018 and ISO/IEC 27701 are particularly noteworthy. From a customer perspective, ISO 27701 has recently gained prominence. This accredited certification confirms that the cloud provider has implemented and continues to improve a Privacy Information Management System (PIMS). 

Double certification for data protection: EU Cloud COC and ISO 27701

Most recently, in July 2025, SCOPE Europe again certified the Open Telekom Cloud under the EU Cloud COC. "This reconfirms that the Open Telekom Cloud fully meets the requirements of the EU GDPR," explains Daniel Fussy, a certification expert at Open Telekom Cloud. In addition, the Open Telekom Cloud holds certification under ISO 27701. 

For special use cases and professional groups with stricter data protection needs than those set by the GDPR, the Open Telekom Cloud also offers legally binding commitments under § 203 of the German Criminal Code (StGB) and § 35 of the German Social Code I (SGB I). These enable the cloud to be used for processing social data or by professionals with confidentiality obligations.

All Open Telekom Cloud certificates at a glance

On our certificate page you will find a complete list of all current security certifications of the Open Telekom Cloud – regularly checked and updated.

Go to the certificate overview
 

The certification landscape is changing  

For a long time, the EU Cloud COC was seen as the gold standard in data protection. "But today, most of our customers are requesting ISO 27701 as proof of our data protection compliance," says Fussy. As a result, the Open Telekom Cloud has decided not to renew its EU Cloud COC certification after 2025. "The Code of Conduct has served both us and our customers well over the years," he adds. However, due to changes in the legal landscape, demand for it has declined. It is foreseeable that ISO 27701 will establish itself as the new standard over the next two to three years. But even that may change. A new player is gaining attention in the data protection landscape: AUDITOR, formerly known as GDPR CC. With AUDITOR, the first certification under Article 42 of the EU GDPR is emerging—one that also offers legal enforceability.

Although AUDITOR is not yet widely requested, it provides a higher level of binding assurance for cloud users regarding GDPR compliance. “As the Open Telekom Cloud team, we intend to take a closer look at AUDITOR and, if appropriate, start the certification process,” says Fussy.


This content might also interest you
 

Verschiedene Pokale stehen vor einer Holzwand

Our certifications

To meet the very latest security and data protection requirements, all of our services are subject to strict rules and are regularly checked by independent specialists.

 
Hände eines Mannes auf einer Laptop Tastatur, im Vordergrund des Bildes ein digitales Schloss in einer Cloud

Gold standard in the cloud industry: Open Telekom Cloud certified according to BSI C5:2020, and SOC 1, SOC 2, SOC 3

The Open Telekom Cloud meets the strict requirements of the BSI C5:2020 cloud test certificates as well as the SOC 1, SOC 2 and SOC 3 requirements catalog.

 
Illustration mit Weltkugel und Sternen mit dem Schriftzug DORA – Digital Operational Resilience Act

The financial sector on the path to the DORA age

DORA places new demands on IT security in the financial sector. Learn how to successfully build digital resilience.

The Open Telekom Cloud Community

This is where users, developers and product owners meet to help each other, share knowledge and discuss.

Discover now

Free expert hotline

Our certified cloud experts provide you with personal service free of charge.

 0800 3304477 (from Germany)

 +800 33044770 (from abroad)

 24 hours a day, seven days a week

Write an E-Mail

Our customer service is available free of charge via E-Mail

Write an E-Mail

AIssistant Cloudia

Our AI-powered search helps with your cloud needs.