Encrypted Forms for GDPR Data Minimization

Client-side encryption can reduce a form provider's access to response contents. It does not make an organization GDPR compliant or remove its responsibilities for the data it collects.

What zero-knowledge encryption can and cannot do

Cyphorm encrypts response contents in the respondent's browser before submission. The intended application flow does not send the owner's private key to the server, so stored response data alone cannot be decrypted by the service.

The service still handles account information, form schema and field labels, ciphertext, and operational metadata such as timestamps or counters where applicable. Encryption does not automatically mean that information is no longer personal data, and it does not determine an organization's lawful basis, purpose, notice, retention, or response to a rights request.

Read the encrypted form overview for the response flow and zero-knowledge trust boundary for the browser-code caveat.

Controller and processor roles

The organization deciding why and how it collects form data will often be the controller for that processing. A service provider may act as a processor for some activities under the applicable agreement and facts. Encryption architecture alone does not decide the legal roles; document the actual purposes, data flows, instructions, and terms.

The European Commission's overview of controller and processor roles explains that controllers remain responsible for their processing principles and processor arrangements.

Minimize what the form collects

Use data minimization to shape the form itself: ask only for data needed for a defined purpose, avoid requesting detailed sensitive information before it is necessary, and keep field labels and free-text prompts from inviting unrelated details.

Cyphorm's encrypted-response model can reduce provider access to answer contents, while field labels, form titles, account details, and operational data may remain visible. The European Commission's GDPR principles overview describes data minimization and storage limitation.

Subprocessors and service terms

Review the service's current privacy materials, contractual terms, hosting arrangements, and subprocessors. Confirm which data each provider handles, the purpose, locations, retention, security duties, and how changes to subprocessors are communicated. Consider email delivery, infrastructure, payment, and other supporting services where they are used.

Record your assessment and ensure required processor terms are in place before collecting personal data. Encryption may limit access to answer contents, but it does not replace reviewing the service relationship.

Data subject rights and retention

Plan how you will respond to access, rectification, erasure, restriction, and portability requests. With encrypted responses, the form owner may need to decrypt and identify relevant entries; the service cannot search stored ciphertext for a person's answer. Design the form and recordkeeping process so your organization can locate the information it is responsible for.

Set a retention period tied to the purpose, remove responses when no longer needed, and account for backups and exported copies. Configure the form product's retention controls to support—not replace—your organization's retention policy.

Cross-border considerations

Identify where the service and its subprocessors process or store relevant data. If information is transferred outside the EEA, determine which transfer mechanism and safeguards apply to your circumstances. Client-side encryption can be a security measure, but it does not automatically remove transfer obligations or settle the legal analysis.

See the European Commission's overview of international data transfers.

Encrypted forms and GDPR FAQ

Does Cyphorm make an organization GDPR compliant?

No. Client-side encryption can limit provider access to response contents, but it does not establish GDPR compliance. Assess legal basis, notices, purposes, retention, rights handling, contracts, subprocessors, and transfers for your use.

What does zero-knowledge encryption change for GDPR?

It can keep response contents encrypted from the form provider in the intended application flow. Account and form metadata remain visible, and encryption does not automatically remove personal-data status or other GDPR duties.

Who handles data subject rights for encrypted form responses?

The organization responsible for the processing must plan how to locate and handle relevant responses. The form owner may need to use the private key to identify or export response contents; the service cannot search plaintext from stored ciphertext alone.