Cloud computing data processing – KNF guidelines for supervised entities
On January 24th 2020 Polish Financial Supervision Committee published extensive guidelines on the matters related to processing by supervised entities of information using public or hybrid cloud computing services. KNF also informs that they will organize trainings in order to explain the guidelines to market participants.
The KNF guidelines are rather extensive and detailed, they form a sort of compilation of all previous KNF’s communications in the matters relating to outsourcing. What’s important, the guidelines apply to all kinds of supervised entities, including but not limited to:
- banks,
- insurance companies,
- investment firms,
- payment services providers (small payment institutions, national payment institutions,
- e-money institutions,
- rating agencies,
- SKOKs,
The scope of guidelines covers inter alia the following fields:
- classification of information,
- classification of cloud computing services,
- risk assessment,
- technical and organizational standards,
- contracts with cloud computing services provider,
- plan for processing information via cloud computing,
- requirements for providers of cloud computing services,
- cryptography,
- monitoring of cloud computing environment,
- documenting activities related to cloud computing,
- KNF reporting obligations.
What’s important, the supervised entities shall apply the guidelines prior to using the cloud computing (public or hybrid) services.
We invite you to contact our Law Firm, which offers services such as:
- payment services,
- representation in front of KNF,
- legal design of internal systems and bye-laws so that they comply with EBA and KNF guidelines.