<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GDPR on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/gdpr/</link>
    <description>Recent content in GDPR on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 19 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/gdpr/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Data Act vs CLOUD Act: who really controls your data in the cloud?</title>
      <link>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</link>
      <pubDate>Fri, 19 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</guid>
      <description>&lt;p&gt;For years, the world operated on a simple assumption: data has a physical place of residence. If it was stored on a server in Dublin, it fell under Irish and European law. That assumption collapsed in 2018, when the United States enacted the CLOUD Act — a law that grants American authorities access to data controlled by US companies, regardless of where that data is physically stored in the world. Several years later, Brussels responded with its own protective framework: the Data Act, now fully applicable, which attempts to limit the extraterritorial access of third-country authorities to data held within the European Union.&lt;/p&gt;
&lt;p&gt;Here is what these two texts actually provide, where they collide, and why the only truly robust protection against this conflict remains technical impossibility of access.&lt;/p&gt;
&lt;h2 id=&#34;the-american-cloud-act-access-based-on-control-not-location&#34;&gt;The American CLOUD Act: access based on control, not location&lt;/h2&gt;
&lt;p&gt;The &lt;strong&gt;CLOUD Act&lt;/strong&gt; (&lt;em&gt;Clarifying Lawful Overseas Use of Data Act&lt;/em&gt;), enacted in March 2018, amended US law by adding &lt;strong&gt;18 U.S. Code § 2713&lt;/strong&gt;. This provision requires any provider of electronic communication services or remote computing services to preserve, back up, or disclose the contents of a communication or any record pertaining to it, whenever that data is in the provider&amp;rsquo;s possession, custody, or control, &lt;strong&gt;regardless of whether the data is located inside or outside the United States&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It is precisely this final clause that changes everything. The criterion is no longer the physical location of the server, but the control exercised by the parent company over its subsidiaries. A US company operating data centres in Europe therefore remains subject to American legal demands, even for data stored entirely on European soil.&lt;/p&gt;
&lt;h2 id=&#34;the-european-data-act-a-legal-barrier-to-extraterritorial-access&#34;&gt;The European Data Act: a legal barrier to extraterritorial access&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Regulation (EU) 2023/2854&lt;/strong&gt;, known as the Data Act, entered into force on 11 January 2024 and has been fully applicable since 12 September 2025, with certain provisions phased in through 2026 and 2027. Its &lt;strong&gt;Article 32&lt;/strong&gt; directly addresses the question of international governmental access to data.&lt;/p&gt;
&lt;p&gt;The text establishes a clear rule: any decision or judgment of a court or administrative authority of a third country requiring a data processing service provider to transfer or give access to non-personal data held in the European Union &lt;strong&gt;is recognised and enforceable only if it is based on an international agreement&lt;/strong&gt;, such as a mutual legal assistance treaty (MLAT), in force between the requesting country and the Union, or between that country and the relevant Member State.&lt;/p&gt;
&lt;p&gt;In the absence of such an agreement, Article 32 provides a second avenue, but one that is strictly circumscribed: the foreign decision may only be enforced if the legal system of the third country requires that the request be reasoned, proportionate, and sufficiently specific — for example, by establishing a clear link to specific individuals or offences — and if the recipient&amp;rsquo;s reasoned objection can be submitted to the review of a competent court in that third country.&lt;/p&gt;
&lt;h2 id=&#34;a-direct-legal-collision&#34;&gt;A direct legal collision&lt;/h2&gt;
&lt;p&gt;The problem is immediate: the CLOUD Act requires disclosure based on the control exercised by the parent company, without a proportionality requirement comparable to that demanded by European law. The Data Act, conversely, conditions recognition of such a request on the existence of an international agreement or specific procedural safeguards. A US company operating in Europe, ordered by an American authority to hand over data hosted within the Union, thus finds itself caught between two contradictory legal obligations: comply with the American mandate and violate Union law, or respect the Data Act and face the consequences of refusal in the United States.&lt;/p&gt;
&lt;p&gt;This tension is not theoretical. It has already been documented by the Court of Justice of the European Union (CJEU) in two landmark rulings, &lt;strong&gt;Schrems I&lt;/strong&gt; (2015) and &lt;strong&gt;Schrems II&lt;/strong&gt; (2020). In the Schrems II judgment, the CJEU held that American surveillance conducted under &lt;strong&gt;Section 702 of FISA&lt;/strong&gt; (&lt;em&gt;Foreign Intelligence Surveillance Act&lt;/em&gt;) and &lt;strong&gt;Executive Order 12333&lt;/strong&gt; does not respect the minimum safeguards required by Union law under the principle of proportionality, and therefore cannot be regarded as limited to what is strictly necessary. The Court also noted the absence of an effective judicial remedy for Union data subjects, in violation of Article 47 of the Charter of Fundamental Rights. This ruling invalidated the Privacy Shield framework, which had until then governed data transfers between the EU and the United States.&lt;/p&gt;
&lt;h2 id=&#34;the-structural-risk-harvest-now-decrypt-later&#34;&gt;The structural risk: Harvest Now, Decrypt Later&lt;/h2&gt;
&lt;p&gt;Beyond the jurisdictional conflict, a more insidious threat looms over data hosted in infrastructures subject to US law: the so-called &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;&lt;strong&gt;Harvest Now, Decrypt Later&lt;/strong&gt;&lt;/a&gt;
 (HNDL) strategy. The principle involves an intelligence service or hostile state actor intercepting and storing encrypted data today, in anticipation of sufficient quantum computing capabilities to decrypt it in the future.&lt;/p&gt;
&lt;p&gt;This strategy transforms any prolonged dependence on American cloud infrastructure into a deferred security liability: what is confidential today may become readable in ten or fifteen years, without any further action required on the part of the attacker — only time and patience.&lt;/p&gt;
&lt;h2 id=&#34;why-only-technical-impossibility-constitutes-a-genuine-guarantee&#34;&gt;Why only technical impossibility constitutes a genuine guarantee&lt;/h2&gt;
&lt;p&gt;Legal analysis converges on a finding shared by many compliance experts: however solid the Data Act&amp;rsquo;s legal framework may be, it remains a text that geopolitical power dynamics and diplomatic pressures can circumvent, delay, or reinterpret. The only protection that depends on no future negotiation is &lt;strong&gt;technical impossibility of enforcement&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;zero knowledge&lt;/strong&gt; architecture, in which the service provider never holds possession or custody of the decryption keys, renders a legal demand materially inoperable. One cannot be compelled to hand over what one never possesses.&lt;/p&gt;
&lt;p&gt;This is the logic that underpins ecosystems such as &lt;strong&gt;Arpokrat&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Jurisdictional neutralisation&lt;/strong&gt;: the infrastructure is hosted in Switzerland, under the Swiss Federal Act on Data Protection (FADP/LPD), outside the direct scope of the CLOUD Act&amp;rsquo;s extraterritoriality&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No custody&lt;/strong&gt;: the zero knowledge architecture deprives the service provider of any ability to hand over keys or content it never holds&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduced identity footprint&lt;/strong&gt;: by eliminating the requirement to register with a phone number or email address — identifiers that FISA Section 702-based surveillance can easily track — the user ceases to be an identifiable subscriber and becomes an anonymous cryptographic key&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-chain-of-custody-does-not-stop-at-message-encryption&#34;&gt;The chain of custody does not stop at message encryption&lt;/h2&gt;
&lt;p&gt;A point often underestimated in compliance analyses: encrypting the content of a communication is not enough if the underlying operating system — whether Android or iOS — continues to capture metadata or kernel-level telemetry destined for servers under US jurisdiction. Protecting confidentiality requires a complete closure of the chain of custody, from content all the way down to the hardware infrastructure itself.&lt;/p&gt;
&lt;p&gt;This is why digital sovereignty also requires reflection on the operating system in use, not just on messaging applications. De-Googled systems, in which modules such as Bluetooth or GNSS geolocation can be disabled directly at the kernel level, eliminate physical attack vectors that no application-layer encryption can compensate for.&lt;/p&gt;
&lt;h2 id=&#34;post-quantum-cryptography-an-already-engaged-horizon&#34;&gt;Post-quantum cryptography: an already-engaged horizon&lt;/h2&gt;
&lt;p&gt;In the face of the threat posed by the HNDL strategy, adopting post-quantum cryptography (PQC) standards becomes a necessity for anyone wishing to guarantee the confidentiality of sensitive data over the long term — whether that involves trade secrets, professional correspondence, or health data. Encryption considered robust today under classical standards does not guarantee that it will withstand the quantum computing capabilities expected within the next fifteen years.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The conflict between the Data Act and the CLOUD Act illustrates a broader reality: digital sovereignty can no longer be built on legislation alone, however solid that legislation may be. It requires closing the chain of custody at every level — from the encryption protocol to the hosting jurisdiction, and including the operating system itself. It is this layered approach, rather than trust placed in a single regulatory framework, that defines genuine digital sovereignty by design today.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The End of Privacy? Backdoors, the Online Safety Act, and the Response of Sovereign Ecosystems</title>
      <link>https://arpokrat.com/blog/ipa-osa-backdoors/</link>
      <pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/ipa-osa-backdoors/</guid>
      <description>&lt;p&gt;London has become the epicenter of a global battle for the future of digital privacy. With the adoption of the &lt;em&gt;Online Safety Act&lt;/em&gt; 2023 (OSA) and recent proposals to revise the &lt;em&gt;Investigatory Powers Act&lt;/em&gt; (IPA) — dubbed the &amp;ldquo;Snoopers&amp;rsquo; Charter&amp;rdquo; by its critics —, the British government is claiming the right to impose surveillance obligations at the very heart of private communications. The breaking point is the power granted to the regulator OFCOM to require platforms to deploy &amp;ldquo;accredited technology&amp;rdquo; to detect child sexual exploitation and abuse (CSEA) material or terrorism, including within &lt;a href=&#34;https://arpokrat.com/messenger&#34;&gt;end-to-end encrypted communications&lt;/a&gt;
.&lt;/p&gt;
&lt;p&gt;For major digital platforms, Westminster&amp;rsquo;s message is unambiguous: either they facilitate state access to their infrastructures, or they face fines of up to 10% of their global revenue. The response was immediate: services like Signal and WhatsApp publicly threatened to withdraw from the UK market, refusing to compromise the security of their users to satisfy a single jurisdiction. The technical argument is hard to dispute: there is no master key reserved solely for legitimate actors. An open door for law enforcement is, by design, an open door for cybercriminals and foreign intelligence services.&lt;/p&gt;
&lt;h2 id=&#34;the-business-model-of-major-platforms-a-structural-obstacle-to-zero-knowledge&#34;&gt;The business model of major platforms: a structural obstacle to Zero-Knowledge&lt;/h2&gt;
&lt;p&gt;The resistance of major platforms to adopting Zero-Knowledge encryption is not explained by technical inability, but by a fundamental economic incompatibility. Companies like Alphabet and Meta rely on monetization models based on the systematic collection of behavioral data. This model is, incidentally, implicitly recognized by the European Union&amp;rsquo;s Digital Markets Act (DMA), which classifies these &amp;ldquo;gatekeepers&amp;rdquo; as entities whose dominant position is precisely fueled by the accumulation of data on an unparalleled scale. For these actors, adopting a Zero-Knowledge architecture would mean depriving their advertising systems of the continuous identification of users that constitutes its fuel. It is therefore not a technical choice, but a trade-off between user privacy and the viability of their business model.&lt;/p&gt;
&lt;h2 id=&#34;the-strategic-risk-the-harvest-now-decrypt-later-threat&#34;&gt;The strategic risk: the &amp;ldquo;Harvest Now, Decrypt Later&amp;rdquo; threat&lt;/h2&gt;
&lt;p&gt;Beyond the debate on privacy, the weakening of encryption raises a national security issue of a completely different scope. The strategy known as &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;&lt;em&gt;Harvest Now, Decrypt Later&lt;/em&gt; (HNDL)&lt;/a&gt;
 involves state adversaries intercepting and storing massive volumes of encrypted communications today, in anticipation of future quantum decryption capabilities. By weakening current encryption standards, the British legislative framework objectively facilitates this type of operations against government, diplomatic, or industrial communications.&lt;/p&gt;
&lt;p&gt;It is precisely in this context of a trust deficit that ecosystems like Arpokrat&amp;rsquo;s acquire operational relevance. By operating under the regime of the Swiss Federal Act on Data Protection (FADP), with an architecture that collects no civil identifiers, Arpokrat offers a technical break from infrastructures subject to British jurisdiction — guaranteeing that the system remains deaf to the injunctions foreseen by the OSA.&lt;/p&gt;
&lt;h2 id=&#34;the-conflict-of-norms-osa-and-ipa-against-european-law&#34;&gt;The conflict of norms: OSA and IPA against European law&lt;/h2&gt;
&lt;p&gt;The legal analysis of the new British state prerogatives reveals a direct collision with the foundations of European law regarding data protection and the confidentiality of communications.&lt;/p&gt;
&lt;h3 id=&#34;osa-against-the-prohibition-of-generalized-surveillance&#34;&gt;OSA against the prohibition of generalized surveillance&lt;/h3&gt;
&lt;p&gt;Article 121 of the OSA introduces the possibility for OFCOM to issue notices forcing platforms to implement client-side scanning. This measure directly contravenes the principle, derived from European law and included in the jurisprudence of the CJEU, prohibiting general surveillance obligations. By imposing a &amp;ldquo;vulnerability by design&amp;rdquo;, it also places companies in a double bind situation: by weakening their security to comply with a state mandate, they fail in their obligation to guarantee a level of security appropriate to the processing, as enshrined in Article 32 of the GDPR.&lt;/p&gt;
&lt;h3 id=&#34;the-eprivacy-directive-and-the-confidentiality-of-communications&#34;&gt;The ePrivacy Directive and the confidentiality of communications&lt;/h3&gt;
&lt;p&gt;The scanning of private messages is in direct contradiction with Article 5, paragraph 1, of Directive 2002/58/EC (&lt;em&gt;ePrivacy&lt;/em&gt;), which obliges Member States to guarantee the confidentiality of electronic communications and prohibits any form of interception or surveillance without the explicit consent of the users concerned.&lt;/p&gt;
&lt;h3 id=&#34;technical-capability-notices-and-blocking-security-updates&#34;&gt;&lt;em&gt;Technical Capability Notices&lt;/em&gt; and blocking security updates&lt;/h3&gt;
&lt;p&gt;Under the IPA 2016 regime, the British government now intends to use &lt;em&gt;Technical Capability Notices&lt;/em&gt; (TCN) to block security updates before they are deployed. This mechanism creates an unsolvable conflict with the obligation, set by Article 32 of the GDPR, to ensure the continuous security of processing systems — an obligation that precisely requires the ability to apply patches without delay or external interference.&lt;/p&gt;
&lt;h2 id=&#34;compliance-risks-for-companies-operating-in-europe&#34;&gt;Compliance risks for companies operating in Europe&lt;/h2&gt;
&lt;p&gt;The revisions to the IPA aim to force companies to notify the British government of any technical modification affecting security, prior to its implementation, thereby granting it a veto right over product development. This interference creates considerable legal insecurity for suppliers operating in the European market: British adequacy to European law — already fragile — could be called into question if the UK no longer guarantees protection substantially equivalent to that of the GDPR. Data transfers to the UK under this new framework would therefore likely expose companies to sanctions under the GDPR.&lt;/p&gt;
&lt;h2 id=&#34;defense-through-technical-impossibility-the-zero-knowledge-principle-as-a-legal-shield&#34;&gt;Defense through technical impossibility: the Zero-Knowledge principle as a legal shield&lt;/h2&gt;
&lt;p&gt;International jurisprudence, consolidated by the &lt;em&gt;Schrems I&lt;/em&gt; and &lt;em&gt;Schrems II&lt;/em&gt; rulings of the CJEU, has established a defining principle: the only robust safeguard against disproportionate surveillance is the technical impossibility of accessing it. Zero-Knowledge architectures apply this principle in three layers of protection:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Absence of custody:&lt;/strong&gt; since the platform does not hold the decryption keys, any injunction to scan messages is technically inoperative;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sovereignty of the operating system:&lt;/strong&gt; the control of &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;ArpokratOS&lt;/a&gt;
 eliminates telemetry that feeds intelligence collection at the device level;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Swiss jurisdictional anchoring:&lt;/strong&gt; by hosting its infrastructure in Switzerland, Arpokrat operates under a legal regime requiring individualized and reasoned mutual legal assistance requests, neutralizing the automated execution of mass scans foreseen by the OSA.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;The provisions of the OSA and the revisions of the IPA are not only a threat to the privacy of individuals: they represent a breach of legal certainty for all European data passing through infrastructures subject to British jurisdiction. By legitimizing the weakening of encryption in the name of public safety, London paradoxically exposes its allies and trading partners to risks of industrial and state espionage that Zero-Knowledge architectures are precisely designed to prevent.&lt;/p&gt;
&lt;p&gt;The integrity of professional and institutional communications now requires a structural response: the migration towards decentralized ecosystems guaranteeing digital sovereignty, from the code level up to the jurisdictional anchoring.&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>