Abstract
[INTRODUCTION] The term “cloud computing” means the remote storage of software applications, tools, and data accessed through the internet. Cloud customers enter into subscription agreements with providers who give 24/7, on-demand, as-needed access to software, storage, and networking services owned and managed by providers through a web browser. “Many businesses are transitioning to the cloud for data storage, remote work, and collaboration.” Cloud providers operate their software as a software-as-a-service (“SaaS”) model, under which customers pay a subscription fee to access the software. Netflix and Amazon Prime Video are examples of subscription services that deliver television programs and videos through the internet. At its most basic level, cloud computing, or SaaS, is a method for delivering software applications on demand over the internet. Cloud computing services contracts offer diverse access contracts ranging from private and public cloud services to “highly individualized services designed specifically for a single client.” Facebook, Twitter, and Instagram are examples of cloud computing, as are email services such as Gmail and Yahoo Mail. Netflix and Hulu are cloud computing applications that allow consumers to remotely access videos. Spotify and Apple Music are cloud platforms that give consumers access to immense collections of music. Lawyers and law students use cloud computing any time they access “Gmail, Facebook, WESTLAW, LEXIS or Google Documents.” Law firms, for example, are increasingly entering into subscription agreements as opposed to having software installed in their offices. Amazon Web Services, Google Drive, Apple iCloud, Microsoft OneDrive, and Dropbox offer an on-cloud platform to consumers, businesses, and governmental users, accessible 24/7 from any geographic location. Cloud computing represents a transformative IT paradigm “offer[ing] seamless access to servers, networks, storage, development tools and applications via the internet” as opposed to investing in equipment, training, and infrastructure. “Proper identity protection practices and access control policies are necessary to help provide integrity and confidentiality of data in the cloud. Malicious cyber actors (MCAs) frequently target cloud environments due, in part, to their remote nature and shared security models.” This Article makes the case that cloud providers often open the door to third-party cybercriminal breaches by misconfiguring their software or failing to implement reasonable measures against breaches. Part II explains how cloud computing works and demonstrates why it is displacing sales, leases, and the licensing of software in an information-based economy. Part III demonstrates that service level agreements (“SLAs”) that customers sign with cloud providers limit damages to the end user to a limited amount. This is an empirical study of the cloud computing service level agreements of Amazon Web Services (“AWS”), Microsoft Azure, Google Cloud, Oracle Cloud, Salesforce, and IBM Cloud, which together hold 70% of the global cloud computing market and are the six largest U.S. cloud providers. Part III documents how these U.S.-based cloud providers draft their SLAs to be indecipherable for the average American user, who reads at the sixth grade level. The world’s largest cloud providers are drafting their terms of use in a way that cannot be understood by many of their users. Cloud computing customers have a duty to read, but U.S. courts and legislatures have no corresponding duty to make their user agreements readable. The six largest cloud providers use contract limitations, such as caps on damages, to make it cost-prohibitive to file suit. When the cost of filing a lawsuit in state or federal court, traveling to a distant venue, and hiring a lawyer is greater than what is at stake, users have theoretical rights but not a meaningful remedy for a provider’s substandard services. The six largest U.S. cloud providers disclaim warranties and cap damages to a nominal amount below the cost of filing suit but no longer require their users to agree to mandatory pre-dispute arbitration. While cloud providers contractually limit their liability and disclaim all warranties, customers still face potential risks related to data breaches and data loss. Part IV proposes a new tort for negligent enablement of cloud data breaches that will hold cloud computing providers responsible for lost or compromised personal, business, and government data. Cloud providers will be accountable for negligently enabling third-party cybercriminals to compromise or misappropriate users’ personal data. The negligent enablement tort will give all customers a meaningful remedy when their data is compromised due to a cloud provider’s misconfiguration, insufficient cloud platform security, or other forms of vendor negligence. The legal reforms proposed in this Article will be an important first step in realigning legal incentives, giving cloud customers recourse for the negligent enablement of cloud data breaches.
Included in
Computer Law Commons, Information Security Commons, Internet Law Commons, Privacy Law Commons, Torts Commons