A fair cloud market requires a sense of responsibility | 11 Fair Principles

A fair cloud market requires a sense of responsibility | 11 Fair Principles

September 14, 2026
Cloud computing has delivered significant benefits, but it has also fundamentally changed the relationship between customers and suppliers. Organizations that rely on cloud platforms become dependent on providers for system availability, security configurations, and the processing of personal data. This requires a strong sense of responsibility from both parties. Without it, situations can arise where customers are left wondering whether their provider is complying with the law, or even whether their organization is exposed to security risks.
2026-07-22 Versie 2 Fair Principles Deel 1

A healthy cloud market depends on customers and suppliers understanding the responsibilities that come with their position and acting accordingly. To help raise awareness, CIO Platform Nederland together with the three sister associations in Belgium, Germany, and France developed the 11 Fair Principles. These principles, recently updated, promote cooperation between cloud providers and customers based on trust, transparency, and professional conduct.

An essential element of such cooperation is that each party complies with the laws and regulations applicable to its services. For suppliers, this means, among other things, taking their role as a data processor under the GDPR seriously and fulfilling the obligations that come with it.

The 11 Fair Principles of CIO Platform Nederland

The law applies to suppliers too
In discussions about privacy and cloud services, much of the attention tends to focus on the customer's responsibilities. This is understandable, as under the GDPR the customer is typically the data controller and therefore carries important obligations.

However, suppliers that process personal data also have legal obligations. These obligations stem directly from the GDPR and do not arise only when they are included in a contract. A processor must implement appropriate technical and organizational security measures, manage subprocessors responsibly, report data breaches in a timely manner, and ensure that personal data is processed only in accordance with agreed instructions.

A supplier is therefore responsible not only for delivering a technically sound service, but also for organizing the data-processing activities within that service in a responsible manner. Customers should not have to push suppliers to meet these obligations—although, unfortunately, that is sometimes still necessary.

From written agreements to Professional Conduct
The Data Processing Agreement (DPA) is an important component of the relationship between customer and supplier. It defines arrangements regarding processing instructions, security measures, subprocessors, and the support the supplier provides to help customers comply with the GDPR.

However, a contract alone is not sufficient to determine whether a service is trustworthy. What ultimately matters is how the service operates in practice. The key questions are whether security measures are effective, whether risks are adequately managed, whether processes function properly when incidents occur, and whether a supplier can demonstrate how personal data is being processed.

This requires professional supplier conduct. In its guidelines on the role of the processor, the European Data Protection Board (EDPB) emphasizes that a processor is not merely a party executing instructions without any responsibility of its own. A professional processor is expected to possess the expertise, resources, and safeguards necessary to process personal data responsibly.

This principle also aligns with the broader concept of fair cooperation between organizations and suppliers. Those who possess the specialist knowledge and technical capabilities required to deliver a service also bear the responsibility to apply that expertise with due care.

The supply chain Is becoming increasingly important
One of the challenges of today's cloud market is that services are rarely delivered by a single supplier. Behind every cloud platform lies a network of data centers, network providers, security vendors, and other specialized parties.

As a result, transparency is becoming increasingly important. Customers must be able to understand which parties are involved in processing personal data and what safeguards apply throughout the chain. Suppliers, in turn, must maintain sufficient oversight and control over the parties with whom they work.

The EDPB specifically highlighted this issue in Opinion 22/2024. Suppliers cannot simply provide a formal list of subprocessors and consider their responsibilities fulfilled. Customers must be given sufficient insight into the supply chain and the measures in place to ensure that personal data is adequately protected.

Non-compliance has consequences
As noted, both parties have distinct responsibilities. Customers must carefully select their suppliers, assess risks, and actively manage supplier relationships. Suppliers must ensure that their services are secure, transparent, and delivered in compliance with the law.

This principle is also reflected in recent regulatory enforcement actions. In 2025, the French data protection authority CNIL addressed IT service provider Mobius Solutions over shortcomings in fulfilling its obligations as a processor. Regulators outside the EU are paying attention as well. In the United Kingdom, Advanced Computer Software Group was held accountable in 2025 for insufficient security measures following a ransomware incident that had occurred three years earlier.

These cases do not suggest that suppliers are somehow always in the dock. Rather, they demonstrate that every participant in the digital supply chain must take responsibility for the quality and security of the overall ecosystem.

Towards a mature cloud market
Discussions about cloud services and privacy are sometimes reduced to a single question: who is responsible when something goes wrong? While understandable, that perspective does not always help move the market forward. A more important question is how organizations and suppliers can work together to ensure that digital services are designed and operated in a reliable manner, minimizing the likelihood of problems occurring in the first place.

Achieving this requires clearly defined roles, fair agreements, and a willingness on all sides to take responsibility. This is precisely the perspective emphasized by the 11 Fair Principles of CIO Platform Nederland, Beltug, Cigref en VOICE.

If you have any comments or questions, please contact Arnoud van Gemeren, Strategic Advisor.   

Close