Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector Organisation

Many public sector organisations (PSO) use SaaS solutions from dominant global providers. Implementation of these solutions may raise issues concerning both lawful data processing, and the obligations that those PSOs have to maintain their digital assets. One example is a large Swedish PSO which ad...

Full description

Bibliographic Details
Main Authors: Björn Lundell, Jonas Gamalielsson, Andrew Katz, Mathias Lindroth
Format: Article
Language:English
Published: Danube-University Krems 2022-12-01
Series:JeDEM - eJournal of eDemocracy & Open Government
Subjects:
Online Access:https://jedem.org/index.php/jedem/article/view/749
_version_ 1797978280868970496
author Björn Lundell
Jonas Gamalielsson
Andrew Katz
Mathias Lindroth
author_facet Björn Lundell
Jonas Gamalielsson
Andrew Katz
Mathias Lindroth
author_sort Björn Lundell
collection DOAJ
description Many public sector organisations (PSO) use SaaS solutions from dominant global providers. Implementation of these solutions may raise issues concerning both lawful data processing, and the obligations that those PSOs have to maintain their digital assets. One example is a large Swedish PSO which addressed these issues as part of the adoption and implementation of Microsoft 365. The study identifies challenges and presents an analysis of the organisational implementation of that SaaS solution, exposing legal issues that arose in that context. Findings show an absence of a documented risk analysis related to the PSO's use of that SaaS solution, covering data processing and maintenance of its digital assets. Recommendations are presented to facilitate a PSO's procurement and implementation of such a SaaS solution to address issues around data processing and the processing of digital assets.
first_indexed 2024-04-11T05:20:54Z
format Article
id doaj.art-4db939bf1cdf452583cdb09320837451
institution Directory Open Access Journal
issn 2075-9517
language English
last_indexed 2024-04-11T05:20:54Z
publishDate 2022-12-01
publisher Danube-University Krems
record_format Article
series JeDEM - eJournal of eDemocracy & Open Government
spelling doaj.art-4db939bf1cdf452583cdb093208374512022-12-24T04:25:16ZengDanube-University KremsJeDEM - eJournal of eDemocracy & Open Government2075-95172022-12-0114210.29379/jedem.v14i2.749Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector OrganisationBjörn Lundell0Jonas Gamalielsson1Andrew Katz2Mathias Lindroth3University of SkovdeUniversity of Skövde, SwedenMoorcrofts LLP, UK & University of Skövde, SwedenACF Legal Intl. AB, Sweden Many public sector organisations (PSO) use SaaS solutions from dominant global providers. Implementation of these solutions may raise issues concerning both lawful data processing, and the obligations that those PSOs have to maintain their digital assets. One example is a large Swedish PSO which addressed these issues as part of the adoption and implementation of Microsoft 365. The study identifies challenges and presents an analysis of the organisational implementation of that SaaS solution, exposing legal issues that arose in that context. Findings show an absence of a documented risk analysis related to the PSO's use of that SaaS solution, covering data processing and maintenance of its digital assets. Recommendations are presented to facilitate a PSO's procurement and implementation of such a SaaS solution to address issues around data processing and the processing of digital assets. https://jedem.org/index.php/jedem/article/view/749SaaSlock-inMicrosoft 365public procurement contract terms GDPR
spellingShingle Björn Lundell
Jonas Gamalielsson
Andrew Katz
Mathias Lindroth
Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector Organisation
JeDEM - eJournal of eDemocracy & Open Government
SaaS
lock-in
Microsoft 365
public procurement
contract terms
GDPR
title Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector Organisation
title_full Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector Organisation
title_fullStr Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector Organisation
title_full_unstemmed Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector Organisation
title_short Data Processing and Maintenance in Different Jurisdictions When Using a SaaS Solution in a Public Sector Organisation
title_sort data processing and maintenance in different jurisdictions when using a saas solution in a public sector organisation
topic SaaS
lock-in
Microsoft 365
public procurement
contract terms
GDPR
url https://jedem.org/index.php/jedem/article/view/749
work_keys_str_mv AT bjornlundell dataprocessingandmaintenanceindifferentjurisdictionswhenusingasaassolutioninapublicsectororganisation
AT jonasgamalielsson dataprocessingandmaintenanceindifferentjurisdictionswhenusingasaassolutioninapublicsectororganisation
AT andrewkatz dataprocessingandmaintenanceindifferentjurisdictionswhenusingasaassolutioninapublicsectororganisation
AT mathiaslindroth dataprocessingandmaintenanceindifferentjurisdictionswhenusingasaassolutioninapublicsectororganisation