Your expert for questions
Sören Scholz
Sören Scholz

Head of Certification Body for Services

Tel.: +49 1516 1272117

Cloud Services and Data Protection

The use of cloud services has experienced a global boom for years and is now an integral part of every modern IT infrastructure. High flexibility combined with low complexity are clear advantages of modern cloud applications. Despite the naturalness with which cloud services have become part of everyday life, various challenges arise from both an information security and data protection perspective.

Cloud solutions are often used to process sensitive data, such as personal data. It is not uncommon for the data to be transferred to an external cloud service provider or to the systems provided by the provider. A mandatory prerequisite for processing such data is the data protection-compliant operation of the service in accordance with the provisions of the General Data Protection Regulation (GDPR).

Until now, it has been difficult for cloud providers to obtain independent certification that their individual cloud services meet the requirements of the GDPR. There was no officially accredited data protection certification to demonstrate data protection compliance for the respective processing operations for each service. Typically, various ISO certifications were used, but these do not constitute certification within the meaning of Art. 42 GDPR.

This is where the (currently still) national data protection certification “AUDITOR” (European Cloud Service Data Protection Certification) comes into play for cloud service providers that carry out data processing operations as part of contract processing pursuant to Art. 28 GDPR.

Your Advantages of Data Protection Certification at a Glance

Data protection proof

As a cloud provider, you can use the AUDITOR certificate to demonstrate GDPR compliance to your B2B customers. Cloud customers are only permitted to work with cloud providers that can demonstrate sufficient guarantees of data protection compliance. AUDITOR certification thus ensures security and transparency and builds trust.

Reduction of legal and financial risks

With the AUDITOR certification and the integrated protection class concept, you create added value for your customers and investors by reducing their risks, uncertainties and control costs for working with data processors in accordance with Art. 28 GDPR.

Competitive advantages and cross-border data traffic

Create a competitive advantage over your market participants by demonstrating GDPR-compliant cross-border data transfer and processing in accordance with Articles 28 and 46 of the GDPR.

Dry runs and consideration of existing certifications

Certification clients can already undergo systematic gap analysis through so-called dry runs (Articles 24, 42, and 83 GDPR) and thus identify and reduce their legal and financial risks. Considering the relevant ISO standards, existing certifications such as ISO/IEC 27001 can also be considered.

European Recognition

AUDITOR certification is intended to be effective and recognized at both the national and EU member state levels. The AUDITOR conformity assessment program and AUDITOR certification criteria have been reviewed and approved by the DAkkS and the responsible data protection supervisory authority (LDI NRW) and approved by the EDPB as the “European Data Protection Seal”.

Stay up to date

The AUDITOR certification criteria are managed by an independent international panel of experts and partners and are continuously updated to consider changes in regulations, case law and EDPB publications.

Our Expertise, Your Advantage

Logo: Auditor

The path to your data protection certification “AUDITOR”

Your company should prepare accordingly for data protection so that it can be completed with as little cost and time as possible.

Key prerequisites for certifying cloud services are:

  • conformity with the requirements of the respective criteria catalog
  • adequate data protection and cloud expertise among all parties involved
  • and the assurance of the cloud service provider that the certification process can be completed in a timely and cost-effective manner.

The implementation phase and actual AUDITOR certification according to the AUDITOR criteria catalog follows a standardized process, which follows this cycle:

Implementation Phase

In this phase, you must ensure that you meet all the requirements for certification. This includes having implemented the relevant data processing procedures for the cloud services to be certified in such a way that they comply with the requirements of the GDPR. You should also have conducted a risk analysis and documented how you deal with risks that could affect the confidentiality, integrity, or availability of personal data. Dry runs (trial runs/pre-audits) have proven to be a useful tool in preparing for certification.

During a dry run, an external service provider can review and assess the implementation of existing requirements within your company and the cloud service under consideration regarding the desired “AUDITOR” certification and identify potential for improvement. While specific areas are examined, a comprehensive audit comparable to an initial certification is not performed.

The following graphic shows an example of a dry run:

Important: PwC Certification Services GmbH does not offer any consulting or dry runs for the implementation of AUDITOR-compliant cloud services.

Application assessment (Stage 1 document review)

When you are ready, you can apply for certification. During the assessment of the submitted application documents, we will check, among other things, whether:

  • The information about the applying organization and the subject of certification is sufficient to conduct the determination.
  • The certification requirements are clearly defined and documented by the certification body and have been made available to the applying organization.
  • The certification body has the competence and capability to carry out the certification activities,
  • the scope of the desired certification, the locations of the applying organization’s activities, the time required to conduct the determinations and all other aspects that influence the certification activity are considered (language, security conditions, threats to impartiality, etc.).

Based on this information, we will prepare a detailed certification offer including a certification agreement.

Determination (Level 2 Audit)

If the assessment of the application documents has resulted in a positive evaluation result and the certification offer has been confirmed/accepted in writing, the detailed planning and implementation of the determination (Level 2 audit) begins. This always includes an on-site audit and, if necessary, additional determination methods in accordance with the AUDITOR conformity assessment program and covers all relevant locations of the organization for the data processing operations to be certified. In addition to the documentation, the determination team uses interviews with employees to review the processes and procedures of the cloud service in accordance with the specifications of the AUDITOR criteria catalog.

Assessment and certification decision

The certification body assesses and decides the standard-compliant implementation of the requirements and, if necessary, corrective actions resulting from the audit. You will only receive the certificate, which is valid for a maximum of three years, once all nonconformities have been resolved and the AUDITOR requirements have been met.

Surveillance activities (interim audit)

To verify compliance with the GDPR of the certified cloud services and to ensure that they continue to meet the requirements of the AUDITOR criteria catalog, surveillance activities are carried out regularly. Based on an interim audit and suitable random samples, the certification body must determine whether the certified data processing operations continue to meet the certification criteria according to the specified protection class. The annual interim audit must be carried out no earlier than after the end of the sixth and no later than the end of the twelfth month from the date of certification or the corresponding dates in subsequent years.

The following points are considered during the interim audit, among others:

  • The determination team leader conducts the interim audit on-site according to the agreed schedule and consultation with the cloud provider.
  • The scope of the interim audit must be selected so that at least the changes to the data processing operations that have occurred since the last audit are examined using investigative methods.
  • As part of the monitoring, the certification body checks whether recognized certificates are still valid. When recertifying the recognized certification, the expiry period of the AUDITOR certification is extended to the term of the recognized certificate, but not more than the standard term of the AUDITOR certification of 3 years or, in the case of other recognized third-party certificates, to the shortest term.

Recertification

After three years, you must undergo recertification to ensure that you continue to meet the requirements of the AUDITOR criteria catalog.

Recertification must generally be completed during the term of the current certificate. This also applies to the transfer of accredited certifications from other certification bodies. To facilitate this, the recertification assessment should be completed 45 days before the certificate expiration date, if possible, but no later than 36 months after the certification assessment. For this reason, it is important to consider during planning that the deadlines for processing any identified deviations may need to be adjusted. The date for completing the on-site assessment should be scheduled at least three weeks before the certificate expiration date to allow for the assessment of the measures taken and for the certification body to provide a final assessment of the process.

If the recertification activities are successfully completed before the expiration of the existing certification, the expiration date of the new certification can be based on the expiration date of the existing certification. The issuance date of the new certificate must be the date of the recertification decision or a later date.

We’re happy to answer your questions about the AUDITOR data protection certification for cloud providers in accordance with the GDPR.

Contact our experts

Data Protection Certification Briefly

The Subject of Certification

The subject of the AUDITOR process is the processing of personal data that is carried out in or with the help of products or services. The AUDITOR process examines the data processing operations that the private sector cloud provider carries out as a processor within the scope of contract processing pursuant to Art. 28 GDPR. It also examines data processing operations that the cloud provider carries out as the controller to conclude and implement the contract with the cloud user regarding the provision of the cloud service and to fulfill legal obligations.

When determining the subject of certification, three components are important that cloud providers as addressees of the AUDITOR certification process must consider:

  1. personal data
  2. technical systems (infrastructure, hardware and software used to process personal data) and
  3. processes and procedures related to processing operations.

Data processing operations that the cloud provider carries out as the controller to conclude and implement the contract with the cloud user for the provision of the cloud service include, for example:

  • to be able to conclude the contract: data that the provider either needs to provide a technical interface or to decide whether its current interfaces are suitable for the cloud user’s technical basis for using the service. The data that can be processed includes, for example, technical data for providing the service, such as the browser and device type used, the operating system version, unique device identifiers, and information about the mobile network. This includes, for example, the name, telephone number, address, and email address to send an offer.
  • those for implementation: data that results from the processing of the data agreed in the legally binding agreement for order processing to maintain the service regarding the conceptual objective of the service, as well as usage data2 to be able to bill for service usage accordingly. Examples of data that may be processed include payment information (e.g., bank details), usernames and passwords for logging into the cloud service, or user-specific quality indicators (e.g., for monitoring or service provision). These include, for example, the name, a telephone number, an address, and an email address for sending an invoice.
  • those required to fulfill legal obligations: data necessary to detect anomalies related to critical infrastructure (e.g. login and logoff data for user accounts and IP addresses, location data, etc.).

In contrast, the following examples do not represent data processing operations carried out by a cloud provider as data controller to enter or fulfill a contract with a cloud user:

  • Data processing operations for market research and analysis (e.g. collecting and analyzing data to gain insights into market trends, customer preferences and behavior),
  • Data processing operations for marketing purposes (e.g. collecting and processing data to provide information about related products),
  • Data processing operations for (operational) business optimization that are not related to the cloud service (e.g. using data to optimize internal processes and procedures to save costs).

The AUDITOR Criteria Catalogue

The AUDITOR Criteria Catalogue is the testing standard for the data protection certification of cloud services in accordance with the requirements of the GDPR. It describes the data protection requirements for the processing of personal data on the part of the contractor (cloud provider). However, the data protection requirements for the client (cloud user) are not addressed.

The AUDITOR Criteria Catalogue contains “criteria,” “explanations,” “implementation instructions,” and “evidence.” The “criteria” refers to the normative requirements that must be met to obtain a certificate based on the AUDITOR Criteria Catalogue. The implementation instructions are based on existing industry standards, norms, and best practices, such as the criteria for ensuring data security based on ISO/IEC 27002 and the BSI C5.

The AUDITOR Protection Class Concept

The protection level and thus the requirements for the technical and organizational measures (TOM) of the cloud service are differentiated in the protection class concept according to different “protection classes.” The protection class has a dual function: Firstly, it describes the protection requirements of data processing operations. Secondly, it specifies the requirements for the technical and organizational measures that the cloud provider must fulfill.

To clarify this dual function, the protection class distinguishes between two components: the protection requirement classes and the protection requirement classes. The protection requirement class describes the protection requirements for data processing operations based on general characteristics. The protection requirement class describes in general terms the technical and organizational requirements that must be met by the cloud provider for cloud services of the respective class. A corresponding protection requirement class is defined for each protection requirement class. The cloud user can obtain the protection class of a cloud service from the cloud provider’s AUDITOR certificate.

The Modularity Concept

A central element of the AUDITOR certification process is the AUDITOR modularization concept, which describes the horizontal and vertical modularization of data processing operations. The AUDITOR modularization concept increases the flexibility of certification. For example, it is possible to certify a cloud service in its entirety or just a single data processing operation of the cloud service. Furthermore, the modularity concept serves as the basis for the recognition of equivalent certifications within the scope of an AUDITOR certification or for the consideration of other certifications that were not issued by an accredited certification body.

The AUDITOR Conformity Assessment Scheme

It describes the specific requirements, rules, and test procedures that must be used to assess the conformity of data processing operations within the scope of AUDITOR certification. It contains all principles that the certification body must comply with and essentially encompasses requirements for the certification body and the certification process. The AUDITOR Conformity Assessment Scheme is managed and continuously developed by the competence network Trusted Cloud e.V. as the scheme owner.

Valid Data Protection Certificates

Our Data Protection Certificates Create Trust!

They confirm to the cloud provider that the certified data processing operations comply with the relevant requirements of the GDPR and the BDSG (German Federal Data Protection Act) in accordance with the AUDITOR criteria catalog for the listed protection class and recoverability class. To maintain data protection certification, it undergoes an annual interim audit.

Data protection certification grants the right to refer to the certificates we have been awarded according to established rules. This helps our clients and protects the PwC brand.

Cloud provider

Musterstraße 1, 12345 Musterstadt, Musterland

Certification subject: Unique designation of the certification subject

Protection class: 1/2/3

Recoverability class: 1/2/3

Certification basis: AUDITOR Conformity Assessment Scheme V1.1 (2024-09-10)

Test basis: AUDITOR Criteria Catalog V1.0 (2024-06-05)

Certificate number: PwC-GDPR-000

Certification decision: YYYY-MM-DD

Certificate valid from: YYYY-MM-DD

Certificate valid until: YYYY-MM-DD

Date of initial certification: YYYY-MM-DD

Number of recertifications: 0

Testing laboratory / inspection body: If applicable, involved subcontractor

Contact in case of complaints or non-conformities:

Short report: PDF file (certification result, from which the exact certification subject (including version or functional status), the Evaluation procedures (including the criteria underlying the certification (if applicable, with version information) and an indication of criteria that were not applicable) and the evaluation result (see DSK Section 7.8).)

Our Expertise, Your Advantage

PwC Certification Services as an Accredited Certification Body

Data protection certifications in accordance with the GDPR may only be conducted by certification bodies accredited by the national accreditation body according to DIN EN ISO/IEC 17065 and authorized by the responsible data protection authority. PwC Cert is one such certification body, accredited by the DAkkS (German Accreditation Body) and authorized by the HBDI. The accreditation is valid only for the scope of accreditation listed in the certificate appendix (registration number: D-ZE-16030-01-00). We are therefore your competent certification partner for demonstrating your GDPR compliant cloud services. Further information about our accreditations and authorizations can be found here.

Documents for download

Further information

You might also be interested in

Contact us
Sören Scholz
Sören Scholz

Head of Certification Body for Services

Tel.: +49 1516 1272117