Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Internet and Other Technologies

Cloud Computing: Service Models, Deployment Models and Legal Issues

Updated 11 October 2026 · Fact-checked

Cloud computing means using servers, storage, software and networks over the internet on demand and paying for what you use. Service models are IaaS, PaaS and SaaS. Deployment models are public, private, community and hybrid. In answers, cover benefits, risks, and legal issues such as data protection, jurisdiction and security duties.

Understand Cloud Computing

Cloud computing is the delivery of computing resources, such as servers, storage, databases, networking and software, over the internet. You do not buy and run your own hardware. You rent capacity from a provider and use it when needed. Billing usually follows usage.

The usual features are on-demand self-service, broad network access, resource pooling (many customers share the provider's infrastructure), rapid elasticity (scale up or down quickly) and measured service. Learn these five as a list. They define what counts as cloud.

There are two ways to classify clouds. Service models tell you how much the provider manages for you: IaaS (Infrastructure as a Service) gives virtual machines, storage and networks; PaaS (Platform as a Service) gives a ready platform to build and run applications; SaaS (Software as a Service) gives finished software used through a browser. Deployment models tell you who owns and uses the cloud: public, private, community and hybrid.

The benefits are lower upfront cost, speed, scalability, easier backup and access from anywhere. The risks are data breach, loss of control, vendor lock-in, service outage, weak access management and unclear legal position when data sits in another country or with a third party.

For a CS, the legal angle matters most. The company that owns the data stays responsible for it even when a provider hosts it. You must think about the contract (service level, liability, exit, audit rights), the IT Act, 2000 and its rules on reasonable security practices, sector rules on data location, and CERT-In incident reporting directions. State these in plain words and link them to the facts given.

Key rules to remember

Service model split (who manages what)
IaaS: provider manages hardware and virtualisation; you manage OS, apps, data | PaaS: provider also manages OS and runtime; you manage apps and data | SaaS: provider manages everything; you manage use and data
The more control you hand over, the less customisation you keep. Data responsibility stays with you in all three.
Deployment models
Public = shared, provider-owned | Private = single organisation | Community = shared by organisations with common needs | Hybrid = two or more models combined
Hybrid lets sensitive data stay private while other workloads use public cloud.
Five essential characteristics
On-demand self-service + broad network access + resource pooling + rapid elasticity + measured service
Use as a definition checklist.
Examples to quote
IaaS: virtual servers and storage | PaaS: application development and database platforms | SaaS: email, CRM, accounting software
Generic examples are safe. Do not rely on brand names for marks.

How to solve Cloud Computing questions

Use this order for any cloud computing question, whether it asks for a definition, a comparison or a case on legal risk.

  1. 1Define cloud computing in one or two lines and name its key features.
  2. 2Identify what the question wants: service model, deployment model, benefits, risks or legal issues.
  3. 3For models, state the meaning, who manages what or who owns it, and one example each.
  4. 4If the question is a case, pick the model the facts point to and give the reason from the facts, such as sensitivity of data or need for scale.
  5. 5List risks and link each to a control, such as encryption, access control, audit rights or exit clause.
  6. 6For legal points, cover data protection duty, contract terms, jurisdiction and location of data, sector rules and incident reporting.
  7. 7Conclude with a clear recommendation or view in one line, and add a compliance or drafting point such as key clauses in the cloud agreement.

Quickest way: Model, Risk, Law, Clause

When to use it: Use when you have little time or the question is a short note or case-based advice.

  1. Write the definition and name the model that fits.
  2. Give two benefits and two risks tied to the facts.
  3. State the legal duty: the data owner remains accountable, reasonable security practices apply, check sector rules on data location.
  4. End with three contract clauses: security standards, audit and breach notice, exit and data return.

Common mistakes in Cloud Computing

  • Mixing up IaaS, PaaS and SaaS or giving only definitions.

    Students memorise names without the idea of who manages what.

    Fix: Always explain the split of responsibility and add one example for each.

  • Saying the cloud provider alone is responsible for data security.

    It sounds logical that the host handles security.

    Fix: State that the customer, as data owner, stays accountable and must secure the arrangement by contract and controls. Security is shared.

  • Treating hybrid cloud as just using two providers.

    The word hybrid is read loosely.

    Fix: Define hybrid as a combination of two or more deployment models, for example private plus public, that remain distinct but work together.

  • Claiming India has one rule that bans all cross-border cloud storage.

    Students hear about data localisation and overgeneralise.

    Fix: Say that localisation duties depend on the sector and the law applicable, for example specific regulator directions, and that general data must be handled under the applicable data protection and IT law. Check the question for the sector.

  • Listing benefits and risks as generic bullet points with no link to the facts.

    Students write memorised notes for a case-based paper.

    Fix: Tie each point to the facts, such as a bank's sensitive data or a start-up's need to scale.

Worked examples

Example 1

Distinguish between IaaS, PaaS and SaaS with examples. Advise which suits a small company that only needs an online accounting tool.

Show the solution
  1. IaaS: the provider supplies virtual servers, storage and networking. You install and manage the operating system, applications and data. Example: renting virtual machines.
  2. PaaS: the provider supplies a platform with operating system, runtime and tools. You build and manage your applications and data. Example: a platform used to develop and host a web application.
  3. SaaS: the provider supplies complete software over the internet. You only use it and manage your own data and users. Example: online accounting or email software.
  4. The company needs a ready tool, not servers or development. It has no IT team to manage infrastructure.
  5. SaaS fits because it needs no installation or maintenance and costs are subscription based.

Answer: IaaS gives infrastructure, PaaS gives a development platform and SaaS gives finished software. The company should choose SaaS. It must still check data security terms, backup and exit rights in the contract.

Example 2

A listed Indian company plans to move its customer data and payment records to a public cloud hosted abroad. As Company Secretary, advise on the legal and compliance issues.

Show the solution
  1. Identify the issue: sensitive customer and payment data moving to a third-party public cloud outside India.
  2. The company remains the data owner and stays accountable for protecting the data, even though the provider hosts it. The IT Act, 2000 and its rules on reasonable security practices expect appropriate security measures.
  3. Check sector rules: payment data may be subject to regulator directions on where it must be stored. Confirm what applies before moving.
  4. Check applicable data protection law and the company's privacy notices and consents for transfer of data.
  5. Review the contract: security standards, encryption, access control, breach notification, audit rights, sub-contracting, jurisdiction and governing law, liability and data return on exit.
  6. Ensure incident reporting to CERT-In is possible within the required time by building the duty into the contract.
  7. Consider risk reduction: a hybrid model that keeps payment data in a private or India-based environment while using public cloud for other workloads.

Answer: The company can use the cloud only after confirming that sector rules on data location and applicable data protection duties are met and that the contract secures audit, breach notice and exit rights. If payment data must stay in India, a hybrid or India-hosted option is the safer course. The board should record the risk assessment.

Exam tips

  • Answer comparison questions with a short table-like list in sentences: meaning, control, example, suitability. Do not write only definitions.
  • In case questions, state the model first, then the legal issue, then the clause or action. This follows provision, analysis, conclusion.
  • Never name a section or rule unless you are sure. Use plain words such as reasonable security practices and sector-specific directions.
  • The paper is open book, so use it to confirm rule wording, but plan your answer structure before you search so you do not lose time.
  • Always end with a practical drafting point such as audit rights, breach notice or exit and data return.

Practice questions from Internet and Other Technologies

Cloud Computing: frequently asked questions

What is the difference between IaaS, PaaS and SaaS?

They differ in how much the provider manages. IaaS gives infrastructure, PaaS gives a platform to build applications, and SaaS gives ready-made software. Control is highest in IaaS and lowest in SaaS.

What are the deployment models of cloud computing?

Public cloud is shared and owned by a provider. Private cloud is used by one organisation. Community cloud is shared by organisations with common needs. Hybrid combines two or more of these.

Does Indian law require all cloud data to stay in India?

There is no single rule for all data. Some sectors, such as payments, have regulator directions on data storage location. Check the sector and the applicable law in each question before concluding.

Who is responsible for data security in the cloud?

Responsibility is shared. The provider secures its infrastructure, but the customer as data owner stays accountable for its data and must control access, encryption and contract terms.