Achieving GDPR compliance: encryption strategies in the cloud

X

Customer success stories
Achieving GDPR compliance: encryption strategies in the cloud

The challenge

The removal of the EU/US Privacy Shield has led to uncertainty for companies using public cloud services from providers outside the EU. Nevertheless, the numerous benefits of the public cloud have prompted companies to move away from traditional data center environments. In this context, our customer, a successful B2C online store platform for electrical appliances, wanted to use AWS core services while complying with data protection laws, in particular GDPR. With a focus on encryption, the client wanted to increase security and empower their team. To achieve this, they partnered with Alice&Bob.Company.

"At the beginning of the project, we were able to clarify many fundamental questions about KMS, AWS Organizations, multi-account structures, and IAM integrations with Microsoft AD in a workshop. That was an excellent start."

Freerk Ohling, Cloud Solution Architect at Alice&Bob.Company

Our solution

To create a solid foundation, Alice&Bob.Company initiated an initial warm-up project to familiarize itself with the customer's environment. Workshops and analyses were held to assess the services currently in use and identify potential improvements for securing personal data. The main focus was on the use of AWS KMS (Key Management Service) and the migration to the encrypted use of S3, EBS, EFS, ElastiCache and CloudFront. In addition, Alice&Bob.Company identified optimization opportunities related to multi-account structures, which ultimately led to the decision to use AWS Service Control Tower instead of a self-created landing zone.

In the second phase of the collaboration, Alice&Bob.Company worked with the client to implement the measures and plans they had developed. Recognizing that security was of paramount importance, they leveraged AWS' broad security portfolio. The customer's use of these services and the creation of a joint security roadmap were key project outcomes.

Cloud technologies used

AWS Key Management Service (AWS KMS)

Managed service for creating and managing encryption keys

Amazon Elastic Compute Cloud (EC2)

Scalable virtual servers in the cloud.

Amazon Simple Storage Service (S3)

Object-based storage for any amount of data.

Amazon Elastic Block Store (Amazon EBS)

Block storage for EC2 instances

Amazon Elastic File System ( Amazon EFS)

Scalable file storage for AWS services

Amazon CloudFront

Content delivery network (CDN) for fast data transfer

AWS Control Tower

Simplifies the setup and management of a secure, multi-tier AWS environment

AWS Lambda

Execute code without server provisioning.

Results

Within just three months, the client saw significant improvements in their confidence and overall level of security within their AWS cloud platform. Alice&Bob.Company provided education and empowerment, ensuring the client understood the implications of the US-EU Privacy Shield termination and the business implications. By removing barriers and facilitating the continuation of the client's cloud journey, Alice&Bob.Company closed the gap between regulatory requirements and cloud technology.

A key outcome of the project was the implementation of a lightweight microservice for the Asset Server. This integration of KMS with S3 and CloudFront delivered long-term value and improved data security and privacy. Ultimately, Alice&Bob.Company's cloud security expertise saved the client six months and instilled a sense of confidence in data protection in the cloud. This success story illustrates the importance of encryption in protecting personal data and highlights the value of working with experienced cloud consultants.

Our solutions

Discover our solutions and formats that support you in the areas of digitalization, innovation & cloud:
All solutions
Arrow to the rightArrow to the right

Audit Preparation

Your solution for compliance challenges
Arrow to the right

AWS Housekeeping

Continuous improvement and increased efficiency of your cloud platform
Arrow to the right

AWS Cloud Security Assessment

Maximum security for your AWS environment
Arrow to the right
Questions?
We look forward to getting to know you!
Thank you - your message has been sent.
Unfortunately something went wrong when sending the form :(