GDPR Fundamentals

The General Data Protection Regulation (GDPR) is the world's strongest data protection law, governing how organizations process personal data of EU residents. Its principles have influenced privacy legislation worldwide.

Key Principles:Lawfulness, fairness, transparency: You need a legal basis for processing personal data • Purpose limitation: Collect data only for specified, explicit purposes • Data minimization: Collect only what you need • Accuracy: Keep personal data accurate and up to date • Storage limitation: Don't keep data longer than necessary • Integrity and confidentiality: Protect data with appropriate security measures • Accountability: Demonstrate compliance through documentation

GDPR scope depends on the processing and the organisation’s connection with the EU; it is not simply a rule covering every record about an EU citizen anywhere. Consult the EU’s GDPR guidance and qualified advice for your situation. Possible penalties depend on the provision and circumstances.

Encryption Under GDPR

GDPR doesn't mandate specific encryption standards, but it strongly incentivizes encryption:

Article 32(1)(a): Controllers and processors must implement "the pseudonymisation and encryption of personal data" as appropriate security measures.

Article 34(3)(a): If a data breach occurs but the data was encrypted, you may be exempt from the requirement to notify affected individuals directly.

This means encryption isn't just good security — it's a compliance tool that reduces regulatory risk:

Encryption can be one appropriate security measure, but it does not by itself establish GDPR compliance. Assess key custody, access, metadata, purposes, retention and the applicable duties. ZeroLatch Simple allows service-managed recovery, while Private depends on a separately held secret. Browser encryption alone does not mean a processor can never obtain plaintext.

Individual Rights and Dead Man's Switches

GDPR grants individuals several rights over their personal data. Here's how they interact with dead man's switches:

Right to Access (Article 15): Users can request all data a service holds about them. ZeroLatch retains account and operational information as well as encrypted files. What the service can recover depends on Simple or Private custody; client-side encryption alone does not answer that question.

Right to Erasure (Article 17): Users can request deletion of their data. Services must honor this by deleting all user data and vaults.

Right to Data Portability (Article 20): Users can request their data in a portable format. Dead man's switch services should support data export.

Rights of Deceased Persons: GDPR itself doesn't address deceased persons' data, but some member states (like France's CNIL guidelines) extend certain rights to heirs. A dead man's switch provides a privacy-respecting mechanism for post-death data access.