GDPR·This article was drafted with the help of artificial intelligence, then reviewed and approved by our team before publishing.

GDPR: How Do You Exercise Your Rights in a Zero-Knowledge Encrypted Cloud?

GDPR: How Do You Exercise Your Rights in a Zero-Knowledge Encrypted Cloud?

Published by May Software

The General Data Protection Regulation (GDPR), applicable since 25 May 2018, grants several rights to people whose personal data is processed. These rights continue to apply when a service uses end-to-end encryption — sometimes described as zero-knowledge — but their implementation must take account of what the provider can actually see and process.

The key point is simple: encryption protects data, but it does not place a service outside the GDPR. Conversely, the GDPR does not require a zero-knowledge provider to create a secret decryption key that would weaken security for all users. Compliance depends on an architecture and procedures that allow people to exercise their rights without bypassing encryption.

What are your main rights?

Chapter III of the GDPR provides, in particular, for:

  • the right of access (Article 15), allowing you to find out whether personal data concerning you is being processed, obtain a copy and receive information about the processing;

  • the right to rectification (Article 16), allowing inaccurate data to be corrected and incomplete data to be completed;

  • the right to erasure (Article 17), in the circumstances set out in the Regulation;

  • the right to restriction of processing (Article 18), which, in certain cases, temporarily restricts the use of data without necessarily deleting it;

  • the right to data portability (Article 20), allowing you to retrieve certain data in a structured, commonly used and machine-readable format;

  • the right to object (Article 21), particularly to processing based on legitimate interests or carried out for direct marketing purposes.

These rights are not absolute. Their application depends on factors such as the nature of the data, the legal basis for processing and any statutory retention obligations. The right to data portability, for example, has a narrower scope than the right of access: it applies to automated processing based on consent or a contract and to data provided by the individual or generated through their activity.

What a zero-knowledge cloud changes

With a conventional cloud service, files are generally encrypted in transit and on the provider’s storage systems. However, the provider controls the keys required to operate the service and may technically be able to access the content in certain circumstances.

With May·Secret, files are encrypted in the browser before they are uploaded. The private key required for decryption never leaves the device in unencrypted form. The server therefore receives and stores encrypted files that it cannot read on its own.

This distinction separates two sets of data:

  1. account and technical data that May·Secret can process directly, such as the email address, subscription information, file size or technical timestamps;

  2. file contents and certain encrypted metadata, which only the user can make readable using their decryption secrets.

Responses to GDPR requests must cover the personal data that is actually being processed. A zero-knowledge architecture determines how that data can be provided; it does not justify dismissing a request as a matter of principle.

Right of access: providing a copy without weakening encryption

The right of access allows individuals to obtain a copy of the personal data being processed, together with information about its purposes, recipients, retention period and the other matters listed in Article 15.

In a zero-knowledge service, the provider can supply the account and technical data it holds in an accessible form. For files, a self-service area that allows the authenticated user to download and decrypt them locally can be an appropriate way to provide access.

The provider must not present its inability to read files as a general exemption. It must explain the architecture clearly, allow users to retrieve their files and separately process the other personal data it holds. This approach is consistent with guidance from the European Data Protection Board, which encourages self-service tools when they provide complete, secure and intelligible access.

Rectification: correcting what can be corrected

Profile information must be correctable through the account or on request. For encrypted data, the provider cannot modify content on the user’s behalf when it cannot read that content. It must, however, provide the features needed to replace, rename or update the relevant items on the client side.

Encryption therefore does not prevent the right to rectification. It simply leaves operations involving unencrypted content to the person who holds the key.

Erasure: distinguishing between the trash, permanent deletion and legal obligations

The right to erasure applies in the circumstances set out in Article 17, for example when the data is no longer necessary, when consent is withdrawn and there is no other legal basis for retaining it, or when the processing is unlawful.

On May·Secret, ordinary deletion first moves a file to the trash so that it can be restored. The user can then request its permanent deletion. Deleting the account also causes the files associated with it to be removed from active storage.

An overly absolute promise should nevertheless be avoided: certain account, billing or security data may have to be retained for a specified period in order to comply with a legal obligation or establish, exercise or defend legal claims. The privacy policy must identify the relevant categories and their retention periods. Any backups must also be subject to documented retention and deletion procedures.

End-to-end encryption reinforces the confidentiality of residual copies: without the required key, their content remains unintelligible. It does not replace a rigorous deletion and backup policy.

Portability: retrieving the relevant data, not necessarily the entire account

The right to data portability does not cover all data available under Article 15. It mainly applies to data provided by the individual, or generated through their use of the service, where processing is automated and based on consent or the performance of a contract.

From the account page, May·Secret allows users to export a JSON file summarising their profile data and a technical inventory of their files. Each file can also be downloaded and decrypted individually in its original format from the vault.

This distinction matters: the JSON export facilitates the reuse of structured data, while local downloads restore access to the unencrypted content. Direct transmission to another provider is required only where it is technically feasible.

Objection and restriction: rights linked to the purpose of processing

The right to object applies in particular to processing based on legitimate interests. On its own, it does not require a provider to stop processing that is essential to perform the contract. An objection to direct marketing must, however, be respected without requiring the individual to provide a reason.

Restriction does not necessarily mean suspending access to the account. Depending on the request, it involves marking the data concerned and temporarily stopping certain operations while retaining the data. The response must therefore be tailored to the processing in question rather than automatically resulting in the service being blocked.

Is May·Secret a controller or a processor?

Zero-knowledge encryption does not, by itself, determine the legal role of a service provider.

May·Secret is a controller for processing activities whose purposes and essential means it determines, including account creation, billing, service security and communications necessary for the service to operate.

When a business customer uses May·Secret to store personal data for its own purposes — client, employee or patient records, for example — the customer is generally the controller of that processing and May·Secret may act as a processor for the hosting service. The precise roles must be assessed for each processing activity and governed by the contractual provisions required under Article 28.

The fact that the provider cannot read the content is an important security safeguard, but it is not enough, on its own, either to create or exclude either legal role.

How can you exercise your rights with May·Secret?

You can use the features available in your account or email privacy@may-secret.fr. A response must be provided without undue delay and, in principle, within one month. This period may be extended by two months where justified by the complexity or number of requests; the individual must then be informed of the extension and the reasons for it within the first month.

To protect personal data, May·Secret may ask for information that is strictly necessary to verify the requester’s identity where there are reasonable doubts.

If you are not satisfied with the response, you may lodge a complaint with the CNIL or with your competent supervisory authority.

Privacy and data protection rights complement each other

The GDPR does not mandate a particular technology. It requires technical and organisational measures appropriate to the risks and lists encryption among the possible measures in Article 32.

A well-designed zero-knowledge cloud can reconcile two objectives: preventing the provider from accessing file contents and giving users practical ways to access, correct, export or delete their data. This protection depends as much on the cryptographic architecture as it does on clear procedures, contracts and retention periods.

To learn more, visit our Trust, Security and Privacy Policy pages.

Sources

This article provides general information and does not constitute legal advice for any particular situation.

Ready to store your files with full confidentiality?

The blog letter

Get our next posts by email, as soon as they're published.

May·Secret only uses storage strictly necessary for the service to work: a preference cookie to remember this notice and an authentication token in local storage, deleted on sign-out. No tracking or advertising cookies. Learn more