GDPR-Friendly Form Collection
The GDPR cares about roles, purposes, data minimization, and subprocessors. When your form vendor cannot read answers, you narrow what they can process on your behalf.
How zero-knowledge supports GDPR
Cyphorm encrypts in the respondent's browser; we store ciphertext without the private key. You remain responsible for lawful basis, notices, retention, and DPA terms with us—but the architecture supports a story where sensitive content is not available to the form host in plaintext.
Data minimization by design
Article 25 of the GDPR requires "data protection by design and by default." Cyphorm's architecture implements this principle at the infrastructure level:
- The processor cannot read personal data — we store only ciphertext, so our processing is limited to storage and transmission of encrypted blobs
- Subprocessor exposure is minimal — our hosting infrastructure handles encrypted data, not personal data in plaintext
- Breach notification scope is narrower — if our infrastructure were compromised, the exposed data would be encrypted and unusable without your private key
Controller responsibilities
Cyphorm reduces processor-side risk, but GDPR compliance remains your responsibility as the data controller:
- Lawful basis — ensure you have a valid legal basis for collecting personal data via your forms
- Privacy notices — inform respondents about how their data will be processed and stored
- Data subject rights — handle access, erasure, and portability requests. Since only you can decrypt submissions, these requests are fulfilled by you, not by Cyphorm
- Retention policies — configure appropriate data retention periods. Cyphorm supports tiered retention (60, 180, or 365 days depending on plan)
- Data Processing Agreement — contact us to establish DPA terms
Cross-border considerations
Because Cyphorm cannot read submission contents, the sensitivity of cross-border data transfer is reduced—though not eliminated. You should still evaluate whether Cyphorm's hosting location and infrastructure align with your transfer mechanism requirements (e.g., Standard Contractual Clauses).
Related
How zero-knowledge works · Can vendors read submissions? · HIPAA-oriented forms