Souveraineté des données

A presentation at Brest is AI in March 2020 in Brest, France by Horacio Gonzalez

Slide 1

Slide 1

Souveraineté des données. Horacio Gonzalez @LostInBrittany

Slide 2

Slide 2

Who are we? Introducing myself and introducing OVH OVHcloud

Slide 3

Slide 3

Horacio Gonzalez @LostInBrittany Spaniard lost in Brittany, developer, dreamer and all-around geek Flutter

Slide 4

Slide 4

OVHcloud: A Global Leader 200k Private cloud VMs running 1 Dedicated IaaS Europe 30 Datacenters Own 20Tbps Hosting capacity : 1.3M Physical Servers 360k Servers already deployed Netwok with 35 PoPs

1.3M Customers in 138 Countries

Slide 5

Slide 5

OVHcloud: Our solutions Cloud Web Hosting Mobile Hosting Telecom VPS Containers ▪ Dedicated Server Domain names VoIP Public Cloud Compute ▪ Data Storage Email SMS/Fax Private Cloud ▪ Network and Database CDN Virtual desktop Serveur dédié Security Object Storage Web hosting Cloud Storage Over the Box ▪ Licences Cloud Desktop Securities MS Office Hybrid Cloud Messaging MS solutions

Slide 6

Slide 6

Do you remember old times? The stories of the grumpy old dev…

Slide 7

Slide 7

In a time almost forgotten When even internet was young…

Slide 8

Slide 8

Data was a scarce resource Mon IBM PC 5155 in the 80s and its big 360 KB floppy disks

Slide 9

Slide 9

Even in big systems… A big mainframe disk from 1985… at 1000$ / MB

Slide 10

Slide 10

Things have changed a lot And we all have some tens of GB in the pocket

Slide 11

Slide 11

Data centers instead of mainframes With petabytes of data capacity…

Slide 12

Slide 12

You are losing me… WTF is a Petabyte? 1 PB = 1 000 TB = 1 000 000 GB

Slide 13

Slide 13

How much data is produced in a year? In 2018 we produced 18 zettabytes 1 ZB = 1 000 EB = 1 000 000 PB

Slide 14

Slide 14

How do we produce so much data? In 2018 every minute: ● Twitter users sent 473,400 tweets ● Snapchat users shared 2 million photos ● Google processes more than 2.5 million searches

Slide 15

Slide 15

Not all the data is the same Some are more important that other

Slide 16

Slide 16

But for all there are critical questions Who is the owner of the data? Who can access the data? Who can monetize the data? Who does control the data?

Slide 17

Slide 17

What are the risks? For an enterprise and for an individual

Slide 18

Slide 18

Data is the new oil, they say In any case, data is vital to business

Slide 19

Slide 19

Risk: data theft The first we think of…

Slide 20

Slide 20

Risk: industrial spying The chic version of data theft…

Slide 21

Slide 21

Risk: data loss Either permanent or temporary

Slide 22

Slide 22

Risk: data alteration Accidental… or not

Slide 23

Slide 23

Risk: no access to data No internet, no cloud…

Slide 24

Slide 24

External risk factors: Geopolitics

Slide 25

Slide 25

External risk factors: Geoeconomics

Slide 26

Slide 26

External risk factors: Distortion of competition

Slide 27

Slide 27

But today we look at another one What rules apply to data? Which jurisdictions?

Slide 28

Slide 28

Data sovereignty Who controls the data… and why should I care?

Slide 29

Slide 29

Data has ethical value For good… and for evil

Slide 30

Slide 30

Data has economic value Fortunes are built around data

Slide 31

Slide 31

Data has a strategic value Key to the independence

Slide 32

Slide 32

Data sovereignty The idea that data are subject to the laws of the nation it is collected

Slide 33

Slide 33

It began with Snowden And the revelations on the PRISM program

Slide 34

Slide 34

And the CLOUD Act The CLOUD Act states that American companies must provide information properly requested by law enforcement “regardless of whether such communication, record, or other information is located within or outside of the United States.”

Slide 35

Slide 35

EU & US: very different views on data Privacy vs Profit

Slide 36

Slide 36

General Data Protection Regulation Protects all personal data for European citizens

Slide 37

Slide 37

New rights for individuals ● The right to access ● The right to be forgotten ● The right to data portability ● The right to have information corrected ● The right to receive a Breach notification

Slide 38

Slide 38

Irresistible force paradox What happens when an unstoppable force meets an immovable object?

Slide 39

Slide 39

Answer: nobody knows for sure And unknowns are never good news…

Slide 40

Slide 40

Data Sovereignty and SaaS Spoiler: it’s complicated

Slide 41

Slide 41

Reminding cloud service models The problem is different for each model

Slide 42

Slide 42

Data Sovereignty and SaaS Well… it’s complicated…

Slide 43

Slide 43

SaaS: Where the data will be stored? Not easy to know in many cases… How about when accessing from the EU to a service hosted in US via un VPN UK?

Slide 44

Slide 44

SaaS: data livecycle Do GDPR protections apply to that SaaS?

Slide 45

Slide 45

SaaS: who owns the data? And what jurisdiction applies?

Slide 46

Slide 46

SaaS: how is data secured And will you get informed from a breach?

Slide 47

Slide 47

Data Sovereignty and IaaS/PaaS A bit clearer

Slide 48

Slide 48

You are using your own services In a third part platform

Slide 49

Slide 49

GDPR is a powerful tool And most providers try to show conformity

Slide 50

Slide 50

But often you have some work to do There is a subtle difference between GDPR ready et GRPD compliant

Slide 51

Slide 51

Vendor lock-in Easy to get in, impossible to get out

Slide 52

Slide 52

Having only a cloud provider Comforting sensation of simplicity

Slide 53

Slide 53

One Cloud to run your apps all Is it really a good idea?

Slide 54

Slide 54

What could possibly go wrong?

Slide 55

Slide 55

Specialy if my data is strategic What can I do?

Slide 56

Slide 56

I can always go away Can’t I?

Slide 57

Slide 57

Well, not so simple… Vendor lock-in

Slide 58

Slide 58

Technical vendor locking Proprietary APIs and products

Slide 59

Slide 59

Cost-based vendor locking Data transfer prices

Slide 60

Slide 60

What can I do then? Quit the Cloud? Going raise goats in Larzac?

Slide 61

Slide 61

The European reaction What cloud do we want?

Slide 62

Slide 62

There are European alternatives Transparent and compiant

Slide 63

Slide 63

European players are ready Alternative solutions respecting our values and rules

Slide 64

Slide 64

Trusting on European actors Building ecosystems, growing champions

Slide 65

Slide 65

Cloud of confiance European initiatives to leverage on European ecosystems

Slide 66

Slide 66

France and Germany initiatives Building souvereign clouds

Slide 67

Slide 67

Protect critical data From extra-territorial threads

Slide 68

Slide 68

Initiatives like GaiaX Transnational working groups Industrial partners

Slide 69

Slide 69

What that means for you? ● Empowering companies and institutions ○ To take more out of your data ● Based on standards and openness ○ A complete offering ● Your data get protected

Slide 70

Slide 70

Conclusion That’s all, folks!