“Hi! Building management here. Just wanted to inform you that we recently listened in on a phone call between your CEO and a major customer. Unfortunately, these extraordinary measures were necessary because we believed the call could possibly pertain to vital interests of building management and owners. If you look to page 342, section 523q of our service agreement, you’ll see that we retain the right to listen in on communications over building phone lines in “extraordinary circumstances.” And after all, we own the lines so we can do whatever we want.”

Imagine getting a message like this from the building management of your office? I’m pretty sure few businesses would stand for this kind of snooping. However, it appears that in the world of cloud services, especially hosted email, this kind of thing is perfectly OK.

As outlined in this CNN article, Microsoft recently discussed how they read the email of a Hotmail subscriber and the justifications under which they did this. Leaving out the validity of Microsoft’s reasoning and how they believed this action was necessary to prevent the theft of company secrets, is anyone who uses these services really comfortable with this?

First off, Microsoft isn’t the only company that defines the right to read email or other hosted content under specific circumstances, pretty much all the major players like Google and Yahoo also do so. And in the specific circumstances of this situation, it was clearly not a case of Microsoft just snooping on someone. Police going to a court of law with similar suspicions might have been granted a warrant to tap the email.

But that’s one of the bigger issues here. In situations like this, the hosted email provider is police, judge and jury. They basically get to unilaterally decide if they need to read the customer email or not.

However, to me the biggest issue here is how it, once again, underlines one of the potential problems of cloud-based and hosted services. In the end, if the data isn’t fully under your control, you’re never sure who may have access to it.

Often I’ll speak to a provider of cloud-based services and, when the discussion turns to organizations that won’t choose cloud because of security and regulatory compliance concerns, there’s always a kind of underlying, almost condescending attitude of “oh, when will these old school firms realize that cloud is super secure and private.”

But it seems like we are regularly reminded that these businesses afraid of the security and privacy limitations of cloud and hosted services are often right. This is why it’s important for organizations using these services to be very upfront about their requirements and to ensure that all agreements and terms of service clearly define if the customer’s data can ever be accessed or shared.

Because in the end, someone may think they have a perfectly valid reason to read your email. But that doesn’t mean that they should.