Has anyone addressed the potential conflicy between the US CLOUD Act and GDPR on a practical level? We have been choosing CSP regions located in EEA countries however the extra-territorial nature of CLOUD would not necessairly be addressed. Is data encryption, with the keys held on premise a potential way to treat this risk?
-----------------------------------------------------------
Steve Wilme CISSP-ISSAP, ISSMP MCIIS