Data Lakehouse Compliance Frameworks for Multi-Cloud Environments with a Focus on GDPR and HIPAA
-
DOI:
https://doi.org/10.67228/30715717/IJDEIC-2019PII4G3PPublished 09-11-2019
Data Lakehouse, Multi-Cloud, GDPR, HIPAA, Compliance Framework, Data Governance, Security Architecture, Data Privacy, Regulatory Compliance, Cloud Computing Issue
Section
ArticlesHow to Cite
[1]V. Sethi and D. Sharma, “Data Lakehouse Compliance Frameworks for Multi-Cloud Environments with a Focus on GDPR and HIPAA”, IJDEIC, vol. 2, no. 2, pp. 01–12, Sep. 2019, doi: 10.67228/30715717/IJDEIC-2019PII4G3P.Abstract
The rapid adoption of data lakehouse architectures across multi-cloud environments offers organizations the scalability and flexibility needed to manage large volumes of structured and unstructured data. However, ensuring compliance with stringent data protection regulations such as the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA) presents significant challenges. This paper explores the compliance landscape for data lakehouses in multi-cloud deployments, identifying architectural considerations, policy requirements, and best practices necessary to ensure regulatory adherence. We propose a compliance framework that integrates security controls, data governance, and auditability tailored to both GDPR and HIPAA, while accounting for the complexity of hybrid and multi-cloud ecosystems. Case studies and implementation strategies are also discussed to demonstrate practical application.
References
[1] Alhadeff, J., Van Alsenoy, B., & Dumortier, J. (2012). “The GDPR and its implementation in cloud computing environments”. Springer.
[2] Al-Ruithe, M., Benkhelifa, E., & Hameed, K. (2016). A conceptual framework for designing data governance for cloud computing. “Procedia Computer Science, 94”, 160–167. https://doi.org/10.1016/j.procs.2016.08.025
[3] Carstensen, J., Morgenthal, J. P., & Golden, B. (2012). “Cloud computing: Assessing the risks”. IT Governance Publishing.
[4] Cohen, I. G., & Mello, M. M. (2018). HIPAA and protecting health information in the 21st century. “JAMA, 320”(3), 231–232. https://doi.org/10.1001/jama.2018.5630
[5] European Parliament and Council of the European Union. (2016). “Regulation (EU) 2016/679 (General Data Protection Regulation)”. Official Journal of the European Union.
[6] Hashizume, K., Rosado, D. G., Fernández-Medina, E., & Fernandez, E. B. (2013). An analysis of security issues for cloud computing. “Journal of Internet Services and Applications, 4”(1), 1–13. (https://doi.org/10.1186/1869-0238-4-5
[7] Kaisler, S., Armour, F., Espinosa, J. A., & Money, W. (2013). Big data: Issues and challenges moving forward. “2013 46th Hawaii International Conference on System Sciences”, 995–1004. https://doi.org/10.1109/HICSS.2013.645
[8] Marchini, R. (2010). “Cloud computing: A practical introduction to the legal issues”. BSI Standards.
[9] McDonald, K. T. (2010). “Above the clouds: Managing risk in the world of cloud computing”. IT Governance Publishing.
[10] Mitchell, C. J. (2015). Privacy, compliance and the cloud. In C. J. Mitchell (Ed.), “Guide to security assurance for cloud computing” (pp. 3–14). Springer. https://doi.org/10.1007/978-3-319-25988-8_1
[11] Newcombe, L. (2012). “Securing cloud services: A pragmatic approach to security architecture in the cloud”. IT Governance Publishing.
[12] Rosenbaum, S. (2010). Data governance and stewardship: Designing data stewardship entities and advancing data access. “Health Services Research, 45”(5 Pt 2), 1442–1455. https://doi.org/10.1111/j.1475-6773.2010.01140.x
[13] Trinckes, J. J., Jr. (2013). “The definitive guide to complying with the HIPAA/HITECH privacy and security rules”. CRC Press.
[14] Ticher, P. (2018). “Data protection and the cloud: Are you really managing the risks?” IT Governance Publishing.
[15] Wu, S. S. (2016). “A guide to HIPAA security and the law” (2nd ed.). American Bar Association.
[16] Zissis, D., & Lekkas, D. (2012). Addressing cloud computing security issues. “Future Generation Computer Systems, 28”(3), 583–592. [https://doi.org/10.1016/j.future.2010.12.006](https://doi.org/10.1016/j.future.2010.12.006)
Downloads
How to Cite
[1]V. Sethi and D. Sharma, “Data Lakehouse Compliance Frameworks for Multi-Cloud Environments with a Focus on GDPR and HIPAA”, IJDEIC, vol. 2, no. 2, pp. 01–12, Sep. 2019, doi: 10.67228/30715717/IJDEIC-2019PII4G3P.