← Blog
Compliance8 min read

HIPAA vs GDPR: what encrypted tools must support

Two regimes, different logic, overlapping technical demands. What client-side encryption satisfies, what it complicates, and where a tool cannot help you.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Different logics HIPAA regulates specific actors handling protected health information in the United States, through defined administrative, physical and technical safeguards plus contracts with business associates. The GDPR regulates the processing of any personal data of people in the EU, through principles — lawfulness, minimisation, purpose limitation, security, accountability — plus data-subject rights.

Where they converge technically Both push toward the same controls: strong access control tied to individual identities, logging of access, integrity protection, encryption of data in transit and at rest, minimisation of what is collected and retained, deletion when the purpose ends, and documented arrangements with vendors.

What client-side encryption satisfies well - **Access control** becomes cryptographic rather than administrative. - **Audit controls / accountability** are served by an append-only trail of grants, revocations, shares and access events. - **Integrity** is provided by authenticated encryption, which fails closed on tampering. - **Security of processing** improves structurally: a provider breach yields ciphertext. - **Sub-processor risk** shrinks, because storage and infrastructure vendors hold nothing readable.

What it complicates, honestly - **Provider-side retention of readable archives** is impossible. If a regime or policy requires it, end-to-end encryption is incompatible, not merely inconvenient. - **Data-subject access requests** must be served by you from your devices; the provider cannot assemble the content for you. - **Right to erasure** is satisfied by deleting ciphertext and destroying keys, which you should document as your method. - **Recovery** depends on your custody of an offline kit; there is no vendor reset.

What no tool can do for you Neither regime is satisfied by software. You still need a risk analysis, a record of processing, staff training, breach procedures, retention schedules, and agreements with each vendor. A tool that claims to deliver compliance is describing marketing; a tool that documents precisely what it does and does not provide is giving you material for your own documentation.

Our own position, stated plainly We do not hold SOC 2 or ISO 27001 certification today and we do not sign Business Associate Agreements today. We publish this rather than implying otherwise, and our compliance page tracks the current state. Where a signed BAA or a certification is a hard requirement, that requirement should decide your shortlist.

A useful exercise For each system holding regulated data, write down three things: can the vendor read it, what agreement do you have with them, and how would you evidence access if asked. Most organisations discover the gap is documentation, not encryption.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload