From Wikipedia, the free encyclopedia
Jump to navigation Jump to search

CISPE (Cloud Infrastructure Services Providers in Europe) is a non-profit trade association for infrastructure as a service (IaaS) cloud providers in Europe. It was started to aid IaaS providers in explaining their business model to policymakers.[1]

Registered in early 2017, CISPE has been operating since 2015.[2]

The association aims to advocate for an EU-wide cloud-first public procurement policy and engage for a European Digital Single Market including the promotion of high-level security and data protection rules/standards as well as avoiding vendor lock-in.

In June 2020, the association became one the 22 founding members[3] of GAIA-X, announced by the German and French Ministers of Economic Affairs Peter Altmaier and Bruno Le Maire. CISPE joined forces with European cloud users and providers like BMW, EDF, Safran, Atos, Siemens, Bosch, OVHcloud, and Deutsche Telekom.

The CISPE Data Protection Code of Conduct[edit]

To help IaaS providers and their customers to comply with the EU General Data Protection Regulation (GDPR), which entered into force from 25 May 2018, CISPE released the CISPE Data Protection Code of Conduct. On top of the required compliance to meet with the GDPR, the code also ensures that IaaS customers can choose to have their data located and processed exclusively in Europe, and that the supplier will not re-use a customer's data.[4]

The compliance has to be declared by CISPs/IaaS providers service by service.[5]

The CISPE Code of Conduct was launched on 27 September 2016 at the European Parliament,[1][6] and the first thirty services had been declared by the first CISPs/IaaS providers on 14 February 2017.[7]

Announcements received press coverage from Le Monde,[1] InfoDSI,[8] El Pais, La Repubblica,[9] Silicon,[10][11][12] Cloud Magazine, Computer Sweden,[13] Tom's Hardware,[14] L'informaticien,[15][16] Global Security Mag,[17] EU Observer, Politico, Computer Weekly,[18] IAPP,[7] Il corriere della Sicurezza,[19] LeMagIT,[20] Bloomberg Television,[21] ITR Manager,[22],[23] COR.COM,[24] ZDNet,[25][26], IT Channel,[27] EuropaPress,[28][29] 01net,[30] The Register,[31] and CIO Dive.[32]

The CISPE Code has received a positive opinion[33] by the European Data Protection Board on May 19. 2021, and has been finally approved by the competent national Supervisory Authority, CNIL on June 3, 2021.[34] To become operational, i.e. legally effective, the Code requires an accredited monitoring body, first. "Le code de conduite sera opérationnel dès que l’un de ces organismes de contrôle sera agréé par la Commission."[35] To date, 3 Monitoring Bodies have been approved (EY CertifyPoint,[36] Bureau Veritas,[37] LNE[37]).

Reversibility IaaS Code of Conduct[edit]

To anticipate the Free Flow of non-personal Data Regulation (FFoD) that was published in late 2018, the European Commission started the SWIPO (Switching and Porting) Working Groups to develop two codes of conduct[38] for data portability on the Cloud market (one for Infrastructure as a Service, another for Software as a Service).

These codes were developed to specifically answer the regulation requirement of its Article 6 - "Data Porting". CISPE, together with EuroCIO (the association of European CIOs) has been tasked by the European Commission[38] to co-chair the SWIPO IaaS Working Group. The SWIPO IaaS code[39] was handed over to the European Commission in November 2019 during the High-Level Conference on Data Economy of the EU Finish Presidency.[40][41]

Cispe members have declared first services adherent to the Swipo Iaas Code in May 2021.[42]

Environmental impact of cloud infrastructure[edit]

The organization set up a Green Cloud Task Force to discuss questions of environmental impact of data centers.[43] The Task Force worked with the European Commission to develop a self-regulatory initiative to achieve our shared goal of ensuring data centres in Europe are climate neutral by 2030: the Climate Neutral Data Centre Pact. The initiative is led by CISPE and EUDCA.[44]

10 Principles for Fair Software Licensing[edit]

In April 2021, Cispe launched together with the French CIO association CIGREF "10 Principles for Fair Software Licensing" [45] in order to address fair software licensing terms of the frame of the EU Digital Markets Act.[46]

Members and supporting organizations[edit]

Members and supportive organizations manage operations in more than 15 European countries including France, Germany, Italy, Ireland, the United Kingdom, Finland, Sweden, the Netherlands, Spain, Bulgaria, Poland, and Switzerland.

Corporate members of CISPE, or organisations supporting the Code of Conduct, include: Arsys, Art of Automation, Aruba S.p.A., AWS, BIT, Dada, Daticum, Dominion, Enter, Fasthosts, FjordIT, Gigas, Hetzner Online, Home, Host Europe Group, IDS, Ikoula, LeaseWeb, Lomaco, Netalia, Netcetera, Outscale, OVHcloud, Seeweb, Serverplan, SolidHost, UpCloud, VTX, XXL Webhosting, and 1&1 Internet.[47]


The CISPE General Assembly elects a ten-member board.

The composition of the board of directors should at any time take into account composition rules: a majority of the board should be composed with European-headquartered companies; a majority of the board should be composed of small and mid-caps (< €1 billion turnover) and represent at least three different EU countries (considering worldwide headquarter's location). The first chairman of the board is Alban Schmutz.[48]

The general secretary is named by the board. The first general secretary is Francisco Mingorance.[48]

The Board also names a Code of Conduct Task Force (CISPE CCTF) which is in charge of the evolution and improvements of the CISPE Data Protection Code of Conduct.[49]

The organization is open to any member operating at least one IaaS service in one European country and engaging to declare at least one service under the CISPE Code of Conduct within six months.[50]


  1. ^ a b c Fagot, Vincent (27 September 2016). "Protection des données : les hébergeurs européens à l'offensive". Le Monde. Retrieved 28 July 2017.
  2. ^ "Cloud Infrastructure Services Providers in Europe - Transparency Register". Retrieved 28 July 2017.
  3. ^ "Germany, France launch Gaia-X platform in bid for 'tech sovereignty'". POLITICO. 4 June 2020. Retrieved 5 July 2020.
  4. ^ Gutwirth, Serge; Leenes, Ronald; Hert, Paul De; Poullet, Yves (22 February 2012). European Data Protection: In Good Health?. Springer Science & Business Media. ISBN 978-94-007-2903-2.
  5. ^ "Public Register - Current list of services declared under the CISPE Code Of Conduct". Retrieved 28 July 2017.
  6. ^ "Europäische Cloud-Infrastruktur-Anbieter veröffentlichen Verhaltenskodex". Retrieved 28 July 2017.
  7. ^ a b "CISPE announces 30 services comply with its code of conduct". Retrieved 28 July 2017.
  8. ^ "Un code de conduite pour les fournisseurs d'IaaS". Retrieved 28 July 2017.
  9. ^ "Cloud, nuovo codice di condotta europeo: ecco cosa cambia". 28 September 2016. Retrieved 28 July 2017.
  10. ^ "CISPE Kodex: Europas Cloud-Anbieter positionieren sich zum Datenschutz -". 29 September 2016. Retrieved 28 July 2017.
  11. ^ "CISPE, lobby européen du Cloud, publie un code de conduite data". 28 September 2016. Retrieved 28 July 2017.
  12. ^ "AWS Touts CISPE Membership To Help Its Cloud Services Meet EU GDPR". 14 February 2017. Retrieved 28 July 2017.
  13. ^ "Ny organisation ska ge garantier för GDPR i molnet – Amazon är med". Retrieved 28 July 2017.
  14. ^ "Con CISPE un codice di condotta per il Cloud". Retrieved 28 July 2017.
  15. ^ "CISPE : un code de conduite pour la protection des données en Europe". Retrieved 28 July 2017.
  16. ^ "Confiance dans le cloud : AWS rejoint l’initiative CISPE, qui passe en prod !". Archived from the original on 4 July 2017. Retrieved 15 May 2017.
  17. ^ "Certification de la protection des données : des fournisseurs d'infrastructures cloud opérant en Europe déclarent leur conformité au code de conduite relatif à la protection des données". Global Security Mag Online. Retrieved 28 July 2017.
  18. ^ "AWS preps GDPR readiness by signing up to cloud Code of Conduct". Retrieved 28 July 2017.
  19. ^ "Dada aderisce al Codice di condotta sulla protezione dati del CISPE - Il corriere della sicurezza". Retrieved 28 July 2017.
  20. ^ "Les fournisseurs de services Cloud anticipent le RGPD". Retrieved 28 July 2017.
  21. ^ "Колко голяма е заплахата пред сигурността на данните в облака". Retrieved 28 July 2017.
  22. ^ "CISPE anticipe le RGPD et fournit une "marque de conformité"". Retrieved 28 July 2017.
  23. ^ "Datenspeicherung in Europa soll Cloud-Kontrolle verbessern". Retrieved 28 July 2017.
  24. ^ "Cloud, nasce il primo codice di condotta: "I dati dei clienti non si toccano"". 28 September 2016. Retrieved 28 July 2017.
  25. ^ "RGPD : Les fournisseurs cloud prennent de l'avance". Retrieved 28 July 2017.
  26. ^ "Una grande alleanza cloud europea: via al Cispe". 15 February 2017. Retrieved 28 July 2017.
  27. ^ "Un code de conduite pour les fournisseurs d'IaaS". Retrieved 28 July 2017.
  28. ^ "Aprobado el código de conducta en aplicación del Reglamento de Protección de Datos de la UE". 27 September 2016. Retrieved 28 July 2017.
  29. ^ "Gigas garantiza la total privacidad de los datos en la nube". 15 February 2017. Retrieved 28 July 2017.
  30. ^ Maria Teresa Della Mura (15 February 2017). "Cispe: ecco chi aderisce alla coalizione". Retrieved 28 July 2017.
  31. ^ "Cloud industry body sets up new data protection code". Retrieved 28 July 2017.
  32. ^ "Data Protection Certification: Cloud Infrastructure Services Providers operating in Europe declare compliance with CISPE Data Protection Code of Conduct". Archived from the original on 28 July 2017. Retrieved 28 July 2017.
  33. ^[bare URL PDF]
  34. ^ ENGLISH News:; Official Decision (French)
  35. ^ "Délibération 2021-065 du 3 juin 2021". Archived from the original on 13 June 2021. Retrieved 13 June 2021.
  36. ^ "Code of conduct: CNIL grants first accreditation to a monitoring body | CNIL".
  37. ^ a b "Code de conduite : La CNIL délivre deux nouveaux agréments à des organismes de contrôle | CNIL".
  38. ^ a b Anonymous (16 April 2018). "Cloud stakeholder working groups start their work on cloud switching and cloud security certification". Shaping Europe’s digital future - European Commission. Retrieved 5 July 2020.
  39. ^ "High-level Conference on Data Economy". Valtioneuvosto. Retrieved 5 July 2020.
  40. ^ "YouTube". Retrieved 5 July 2020.
  41. ^[bare URL PDF]
  42. ^ "3DS Outscale, Aruba, AWS, CoreTech, Infoclip, Irideos, Leaseweb, OVHcloud, and Scaleway to declare first cloud infrastructure services adhering to SWIPO IaaS Code for data porting". 12 May 2021.
  43. ^[dead link]
  44. ^ "5 keys to understand the Climate Neutral Datacenter Pact". 21 January 2021.
  45. ^ "Cigref and CISPE Launch Ten Principles to End Unfair Practices of Software Gatekeepers". 14 April 2021.
  46. ^ "Cloud : Le torchon brûle entre les entreprises et les éditeurs de logiciels américains". 13 April 2021.
  47. ^ "Implications of the Code of Conduct for Cloud Infrastructure Service Providers in Europe". Archived from the original on 28 July 2017. Retrieved 28 July 2017.
  48. ^ a b "Board of Directors - CISPE - The Voice of Cloud Infrastructures Providers in Europe". Retrieved 28 July 2017.
  49. ^ "CCTF - CISPE - The Voice of Cloud Infrastructures Providers in Europe". Retrieved 28 July 2017.
  50. ^ "Become CISPE Member". Retrieved 8 June 2020.

External links[edit]