The GDPR Playbook
GDPR is a governance decision. So is your digital workplace.
A practical, vendor-neutral guide to what GDPR actually asks of the tools your business runs on every day — and how the infrastructure behind them either simplifies or quietly complicates your compliance.
Storing data in Europe was never the whole story. Encryption isn't compliance. "Our cloud provider handles it" isn't a strategy.
Why this playbook
Not legal theory. Not marketing. Something you can act on.
Most GDPR content is either theory you can't use or vendor spin dressed up as education. This is neither.
From first principles
What personal data actually is, what "compliant" really means, and why the regulation was written the way it was.
To daily operations
Your digital workplace is where GDPR is exercised every day — and its architecture shapes how easily you can prove you're in control.
Honest about the limits
No platform makes you compliant. What the right one does is make the controls GDPR expects far easier to implement and demonstrate.
What's inside
Six things you'll be able to do differently.
Principles
Principles, translated into operations
What "appropriate technical and organizational measures" looks like for IT, HR, security, and procurement.
9 Myths
Common myths, dismantled
From "we store data in Europe" to "we own our data" to "compliance is a one-time project."
15+ Frameworks
A global view
How GDPR compares to UK GDPR, LGPD, CPRA, PIPL, and the DPDP Act — for cross-border operations.
Schrems II
Residency vs. sovereignty
The distinction that changes how you evaluate every provider, and what Schrems II means for transfers.
Checklist
A GDPR readiness checklist
A practical evaluation framework for IT leaders, CISOs, DPOs, and procurement teams.
Levels 1–4
A maturity model
Benchmark where you are today, and see where to go next.
Who it's for
Written for the people who have to answer the hard questions.
The audience
Regulated & governance-sensitive organizations.
Decision-makers and the teams behind them:
- Government & public sector
- Healthcare & life sciences
- Finance & insurance
- Critical infrastructure operators
- IT, security, compliance & procurement leaders
The questions
When "it's in the cloud" isn't a sufficient answer.
- Who can access our data?
- Whose laws apply to our provider?
- Can foreign authorities compel access (e.g. the US CLOUD Act)?
- Who administers the environment?
- Can we migrate without lock-in?
Access the playbook
No form. No wait. Access it online.
The full playbook, free — access it, share it, use it to open the conversation.
The takeaway
Which makes the platform a compliance decision.
Email, chat, meetings, files — that's where personal data is actually processed every day, and where GDPR is met or missed. The tool your teams work in isn't a productivity choice. It's a governance one.
Which turns the real question from where is our data into how much control do we have over it — who can reach it, whose laws apply, who holds the keys.
And for most organizations, that platform is a hyperscaler suite they rent.
The hyperscaler trade-off
What you give up when collaboration is something you rent.
A hyperscaler suite is easy to buy and quick to switch on. The cost shows up later — not in the invoice, but in how little of the arrangement you actually control.
Your data sits under foreign jurisdiction
A US-headquartered provider can be compelled to disclose data under laws like the CLOUD Act — regardless of which region it's stored in.
You rent access, not the platform
It's their cloud, their tenant, their rules. No version you host, no infrastructure you choose — access is the most you can buy.
Licensing that moves without you
Per-seat prices rise, features shift between tiers, and SKUs get repackaged on a schedule you don't set and can't opt out of.
AI switched on by default
AI features arrive enabled and woven through the suite. Keeping your content out of them becomes an ongoing administrative burden, not a default.
Shared tenancy, shared fate
On multi-tenant public cloud, outages, breaches, and policy changes you had no part in still land on your organization.
Leaving is designed to be hard
Proprietary formats and deep cross-app entanglement mean the exit cost climbs the longer you stay — which is the point.
None of this makes the hyperscalers a bad choice — for many organizations they're the right one. But notice what's being handed over: jurisdiction, access, retention, auditability. Those aren't just operational conveniences — they're the exact things GDPR holds youaccountable for. Rent the platform, and you're still answerable for controls you no longer fully hold.
The alternative
Carbonio: one platform, built for secure everyday collaboration.
Everything a hyperscaler charges for as separate apps and license tiers — email, calendar, chat, video, files, mobile, admin — Carbonio carries natively, on infrastructure you control. Same trade-off as above, answered the other way.
One integrated suite
Email, calendar, chat, video meetings, files, and collaborative document editing — one platform, not a stack of separate apps and license tiers.
Deploy it your way
On-premises, private cloud, hybrid, or sovereign cloud. You decide where it runs and who operates it — not the vendor.
Control who's in charge
Multi-tenancy, role-based access control (RBAC), and administrative separation keep the right people in — and everyone else out.
Prove what happened
Full auditability, legal hold, and centralized administration help you document access, actions, and changes when accountability is on the line.
Own the full data lifecycle
Storage policies, backup and restore, retention, and secure deletion — so you define how long data lives and how it leaves.
Freedom from lock-in
Open standards and an open-core architecture — SMTP, IMAP, CalDAV, CardDAV — keep your stack interoperable and independent.
No platform makes an organization GDPR compliant — compliance always stays with you. The value of the right one is simpler: it puts the technical and organizational measures GDPR expects within reach, and keeps the questions that follow easier to answer.
Frequently asked
GDPR, sovereignty, and Carbonio — answered.
Does storing data in Europe make my organization GDPR compliant?
No. Data residency and GDPR compliance aren't the same thing. Where data is stored is only one factor — GDPR also governs how it's processed, who can access it, which third parties are involved, how long it's kept, and whether you can demonstrate accountability. You can store every byte in the EU and still be non-compliant.
Is encryption enough for GDPR compliance?
No. GDPR lists encryption as one example of an appropriate technical measure — not a guarantee of compliance. Encryption protects data, but it doesn't explain why you collected it, who can access it, or whether you should have collected it at all. It works alongside access controls, retention, logging, and governance.
What's the difference between data residency and digital sovereignty?
Data residency is where your data is physically stored. Digital sovereignty is who has legal and operational control over the data and the systems processing it — including provider jurisdiction, administrative access, encryption keys, and exposure to foreign government access laws. A US-headquartered provider can be compelled to disclose data under laws like the CLOUD Act regardless of which region it's stored in — so data can reside in Europe while legal control sits elsewhere.
Does GDPR require me to run everything on-premises or own my infrastructure?
No. GDPR is technology-neutral and never requires you to own servers or avoid cloud providers. It requires appropriate technical and organizational measures and accountability. A well-managed cloud deployment can be compliant; a poorly managed on-premises one may carry more risk. The point is control, not ownership.
Is my cloud provider responsible for GDPR compliance?
No. Responsibility can't be outsourced. Under GDPR the data controller remains accountable for selecting processors, configuring security, managing access, setting retention, and responding to data subject requests. Providers can offer tools that support compliance, but they can't make you compliant by default.
Does GDPR apply to my company if we're not based in the EU?
Often, yes. GDPR has extraterritorial reach: it applies to any organization, anywhere, that offers goods or services to individuals in the EU or monitors their behavior. Whose data you process matters more than where your company is located.
Does GDPR only apply to large enterprises?
No. GDPR applies to organizations of all sizes whenever they process personal data covered by the regulation. Whether you have 5 employees or 50,000, the core principles are identical — only the scale of implementation differs.
What makes a collaboration or email platform "GDPR-ready"?
No platform is compliant on its own. A GDPR-ready platform makes the controls easier to implement and prove — access control, strong authentication, retention policies, audit logging, secure export and deletion, and the flexibility to choose where and how it's deployed. Email matters most, since it's usually the largest store of personal data in the business.
Is Carbonio GDPR compliant?
No software is "GDPR compliant" on its own — and any vendor claiming otherwise should be treated with caution. Compliance depends on how your organization configures, governs, and operates its tools. What Carbonio does is give you the technical and organizational controls GDPR expects — access management, authentication, auditability, retention, and deployment choice — so those controls are within your reach rather than someone else's.
How does Carbonio support GDPR compliance?
Carbonio (by Zextras) helps organizations implement the measures GDPR asks for: role-based and delegated administration, multi-factor authentication, audit logging, backup and recovery, retention and secure deletion, and data export via open standards. Together these support the security (Article 32), accountability (Article 5(2)), and privacy-by-design (Article 25) expectations — while the responsibility for compliance stays with you.
Can Carbonio be deployed in Europe or on our own infrastructure?
Yes. Carbonio supports on-premises, private cloud, hybrid, and sovereign-cloud deployments. You choose where it runs, in which jurisdiction, and who operates it — so you can align data location and administrative control with your governance and residency requirements instead of adapting to a fixed provider model.
Is Carbonio a good GDPR-friendly alternative to hyperscaler platforms?
For organizations with strict governance, sovereignty, or regulatory needs, it can be. Hyperscalers are a valid choice for many businesses, but they typically fix where data is processed and who holds administrative access. Carbonio's value is flexibility: you decide the deployment model, retain administrative control, and avoid the cross-border processing and subprocessor questions that complicate accountability.
Does Carbonio help with digital sovereignty, not just data residency?
That's the core distinction. Residency is where data sits; sovereignty is who has legal and operational control over it. Carbonio doesn't remove your legal obligations, but by letting you choose the hosting location, the operator, the infrastructure provider, and the administrative model, it gives you more of the control that sits at the heart of a digital-sovereignty strategy.
Does Carbonio use open standards, and why does that matter for GDPR?
Yes — Carbonio is built on standards like SMTP, IMAP, CalDAV, and CardDAV. Open standards reduce vendor lock-in, keep migration and data export practical, and make interoperability easier. That supports GDPR's accountability and portability objectives, since you can move or hand over data without being trapped in a proprietary ecosystem.
Where to next
You've seen the trade-off. Now see the alternative in full.
Explore how Carbonio gives organizations a private, secure digital workplace they deploy and govern on their own terms — or take the playbook with you and decide in your own time.