惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
Last Week in AI
Last Week in AI
Blog — PlanetScale
Blog — PlanetScale
V
Visual Studio Blog
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
博客园 - Franky
IT之家
IT之家
博客园 - 叶小钗
Engineering at Meta
Engineering at Meta
The GitHub Blog
The GitHub Blog
雷峰网
雷峰网
腾讯CDC
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
人人都是产品经理
人人都是产品经理
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
博客园_首页
G
Google Developers Blog

Nextcloud

Collabora: Landlock adds a third, tougher sandbox tier - Nextcloud September maintenance updates before Nextcloud Hub 26 Summer, EOL for Nextcloud Hub 26 Autumn - Nextcloud Workshops at the Nextcloud Community Conference 2026 - Nextcloud How to set up UnifiedPush on Android for Nextcloud Talk - Nextcloud Anna Larch on community management and DevRel in the age of AI PRs - Nextcloud Nextcloud Hub: The European alternative to Microsoft 365 and Google Workspace - Nextcloud Nextcloud earns ANSSI CSPN and BSI IT-Grundschutz certifications - Nextcloud Academy of Civic Organizations builds a secure workspace | Nextcloud August maintenance updates for Nextcloud Hub - Nextcloud Join the Nextcloud development sprints: a week of hands-on collaboration - Nextcloud How to volunteer at the Nextcloud Community Conference 2026 - Nextcloud Prof. Dr. Johanna Pirker on AI, open source, and sovereignty - Nextcloud Do I belong at the Nextcloud Community Conference 2026? - Nextcloud July maintenance updates: Nextcloud Hub 25 Autumn, 26 Winter & 26 Spring - Nextcloud Nextcloud Office: deciding between Euro-Office, Collabora, and Thinkfree Office - Nextcloud Nextcloud Community Awards 2026 Building a sovereign AI stack: What it actually takes - Nextcloud Nextcloud AIO introduces automatic domain and DNS setup - Nextcloud Nextcloud ISV Partner Program: connecting app developers with enterprises How to install Euro-Office in Nextcloud June maintenance updates for Nextcloud Hub 25 Autumn, 26 Winter & 26 Spring - Nextcloud Nextcloud Summit 2026: Celebrating the people and companies who made it happen - Nextcloud Nextcloud Deck: the kanban board & Gantt chart app for teams - Nextcloud Bringing digital sovereignty to university IT: Interview with Michael Redinger, University of Innsbruck - Nextcloud Your Guide to Nextcloud All-in-One on Windows 10 & 11 - Nextcloud How to install the Nextcloud All-in-One on Linux - Nextcloud Nextcloud Summit 2026: Digital sovereignty comes of age Nextcloud Awards 2026: celebrating ISKA Nürnberg and FREIRAD Nextcloud Hub 26 Spring: Built together, designed for the future Out-of-band updates for Nextcloud Hub 25 Autumn & 26 Winter
Nextcloud passes DPIA by SURF & Privacy Company - Nextcloud
Kevin Herschbach · 2026-08-11 · via Nextcloud

Nextcloud - Hub 26 Summer launches live!

Hub 26 Summer launches live!

Join us for the livestream and be among the first to discover
what’s new in Nextcloud.

September 16 @ 3 PM CEST / 9 AM EDT

Watch live on YouTube or PeerTube

Set a reminder

Most software vendors describe their approach to data protection in similar terms: privacy by design, security built in from the start, data protection taken seriously. These phrases appear across nearly every vendor’s marketing material, largely because they cost nothing to state and are rarely independently verified. For buyers, it’s difficult to distinguish vendors with genuinely defensible practices from those that merely present themselves convincingly.

With Nextcloud, that distinction was recently put to the test by an independent party.

On July 16, 2026, the Dutch education and research IT cooperative SURF and the privacy and data-protection consultancy Privacy Company published the results of a joint Data Protection Impact Assessment (DPIA) for self-hosted Nextcloud Enterprise.

A DPIA is a formal, structured evaluation process, often required or recommended under GDPR for higher-risk data processing, carried out by an independent party rather than the vendor itself. It’s a level of scrutiny that procurement and legal teams tend to take very seriously.

The DPIA initially identified 15 data protection risks, for which Nextcloud promptly implemented mitigations. SURF then negotiated an amended Data Processing Agreement (DPA), reclassifying all 15 risks as resolved or low.

No access to customer’s content data

The identified risks were located in four areas: admin and commercial contact data, support data, optional diagnostic data that administrators can choose to share, and website data. Notably, no risks were found for content data (the files customers store on Nextcloud) because we have no access to this data, even when providing support.

This lack of access to content data isn’t a contractual promise but a result of how the software is built. By default, we process only minimal personal data, generally limited to contact details for administrators or procurement contacts. The company also holds CSPN certification from ANSSI, France’s national cybersecurity agency, which independently verified its secure storage, authentication, access control, and secure communications.

For users of Nextcloud Office, the DPIA makes a distinction between the available office suites. It points out that for customers who use Collabora Online, support tickets could be handled by staff in the UK, whereas Euro-Office can be used with fully EU-exclusive data processing.

SURF secured an amended DPA limiting Nextcloud’s role as processor to four specific purposes, with seven additional “further processing” purposes where Nextcloud may act as controller. It also obtained a hard guarantee that Nextcloud will never disclose personal data to authorities outside the EU, along with its own audit rights to verify ongoing compliance, limited data retention periods, and minimal cookie use. SURF negotiated these terms specifically for the Dutch education and research sector.

Implications for enterprise buyers

The responsibility to ensure data privacy doesn’t end with the vendor. Customers are expected to minimize what their administrators choose to share through diagnostic settings and implement security measures to avoid falling into a “high risk” category on their own end.

For a market where most vendors’ privacy claims go untested, the DPIA gives Nextcloud a documented account from an independent party, including what it found and what changed as a result. This doesn’t replace an organization’s own due diligence, but it gives both existing and prospective customers a concrete starting point for their evaluation.

The full DPIA is publicly available through SURF’s Vendor Compliance page. If you’re assessing Nextcloud Enterprise for your own organization, you can request a free trial or contact us for a quote tailored to your needs. We’ll talk through what a deployment would look like and which data residency and hosting configuration fits your needs.