Aller au contenu
NNextHop
References

Sources and bibliography.

All legal texts, technical reference frameworks and public data feeds cited on the site. Centralised reference, updated together with the methodology and score changelog pages.

All sources listed here are public and institutional. Links point to the homepage or the stable rubric of the issuing body, never to a document URL likely to evolve.

Category

US laws and regulations

US federal texts that create extraterritorial exposure for cloud providers subject to US jurisdiction.

CLOUD Act, Public Law 115-141 (2018)

Law authorising US authorities to require a provider subject to their jurisdiction to deliver data stored anywhere in the world.

Foreign Intelligence Surveillance Act, Section 702

US intelligence legal tool that permits, without an individual warrant, the collection of communications of non-US persons located outside the USA from US electronic service providers.

Stored Communications Act, 18 U.S.C. Chapter 121

Historic framework for the right of access to data stored by communications providers. Amended by the CLOUD Act in 2018.

National Security Letters (NSL)

FBI administrative injunctions without prior judicial review, accompanied by a gag order. Primarily concern telecommunications records.

Category

EU regulations

Legal framework applicable to personal data and digital services in the European Union.

Regulation (EU) 2016/679 (GDPR)

General Data Protection Regulation, applicable since 25 May 2018. Governs all processing of personal data of individuals located in the EU.

Regulation (EU) 2023/2854 (Data Act)

Data regulation adopted at the end of 2023 governing the sharing and portability of data generated by connected objects and cloud services. Includes switching obligations and protection against illicit transfers.

Regulation (EU) 2022/1925 (DMA)

Digital Markets Act, which regulates the practices of large digital gatekeepers. Targets interoperability and the limitation of anti-competitive practices.

Regulation (EU) 910/2014 (eIDAS)

Regulation on electronic identification and trust services. Notably defines assurance levels for electronic signature, timestamping and archiving.

Regulation (EU) 2019/881 (Cybersecurity Act)

Strengthens the mandate of ENISA and establishes a European cybersecurity certification framework (legal basis of the upcoming EUCS).

Category

French laws and doctrines

National texts structuring the sovereign digital agenda in France.

Law n 78-17 of 6 January 1978 (Informatique et Libertes)

Founding French law on personal data protection. Amended to align with the GDPR since 2018. Remains the national legal basis and confers powers to the CNIL.

SecNumCloud v3.2 reference framework (ANSSI)

ANSSI qualification for cloud service providers, March 2022 version. Includes explicit requirements of extraterritorial immunity and European capital control.

Cloud-au-centre doctrine (DINUM)

Prime Minister circular of 5 July 2021. Requires the use of a SecNumCloud-qualified service for the most sensitive State data.

Reglement general de protection (RGS)

General security reference framework applicable to the information systems of administrative authorities, transversal complement of sectoral qualifications.

Category

European case law

Structural decisions of the Court of Justice of the European Union on international transfers of personal data.

Schrems I ruling, CJEU C-362/14 (2015)

Invalidates the Safe Harbor agreement between the EU and the United States. First signal on the limits of US law against the European data protection standard.

Schrems II ruling, CJEU C-311/18 (2020)

Invalidates the Privacy Shield and conditions any EU-US transfer via standard contractual clauses on an impact analysis taking US law into account. Unavoidable reference for cloud choices since 2020.

Category

Technical standards and certifications

Technical security reference frameworks used to evaluate providers on the certifications criterion.

ISO/IEC 27001

International standard for information security management. Minimum baseline required for most public and regulated markets.

ISO/IEC 27017

Code of good practice for security controls specific to cloud computing. Complements ISO 27001 in the cloud services context.

Esquema Nacional de Seguridad (ENS)

Spanish national security scheme, functional equivalent of European national qualifications. Levels Low, Medium, High.

ISAE 3402

International audit standard applicable to service organisations, attesting to operational controls by an independent third party.

SOC 2 (AICPA)

US audit report on security, availability, confidentiality and integrity controls of service providers. Very frequent among US actors and global SaaS players.

BSI Cloud Computing Compliance Criteria Catalogue (C5)

Reference framework of the German federal office for information security, frequently used as a baseline for German public procurement.

Hebergeur de Donnees de Sante (HDS)

Mandatory French certification to host personal health data. Managed by the Agence du numerique en sante.

Category

Public data sources

External data feeds used on NextHop to enrich provider profiles and analysis modules.

ANSSI, list of qualified providers

Official list of providers qualified SecNumCloud, HDS, PASSI, PDIS and others. Regularly updated by the agency.

ENISA, cybersecurity knowledge bases

Publications and inventories of the European Union Agency for Cybersecurity: guides, recommendations, sectoral studies.

European Central Bank, reference exchange rates

Pivot EUR rates used for multi-currency price conversions in the cloud catalogue.

ElectricityMaps, carbon intensity of the electricity mix

Open data on the hourly carbon intensity of European electricity grids. Used for the carbon footprint calculation per region.

CNIL, decisions and guidelines

Decisions, sanctions and recommendations of the French data protection authority, mobilised on the immunity and hosting criteria.

EDPB, recommendations and opinions

Opinions of the European Data Protection Board, notably recommendations 01/2020 on supplementary measures post-Schrems II.