deep-dive

GDPR and CCPA Compliance: What Those Labels Actually Guarantee

Every privacy-focused storage service claims GDPR or CCPA compliance. Here's what that actually means — and what it does not — for your files and photos.

Browse the privacy claims of any cloud storage service and you’ll find a consistent set of badges: “GDPR Compliant.” “CCPA Compliant.” “Privacy First.” These labels appear on the landing pages of services across the spectrum — from genuinely privacy-protective services to advertising-funded platforms that technically meet the minimum threshold while doing things most users would object to.

The labels mean something. They also don’t mean everything. Understanding what these compliance frameworks actually require — and what they explicitly don’t require — is necessary groundwork for evaluating any service you’re considering trusting with your files and photos.


What GDPR Actually Is

The General Data Protection Regulation is EU law that has applied across European Union member states since May 2018. It sets rules for how organizations can collect, store, process, and transfer the personal data of people in the EU.

GDPR applies to any organization that processes personal data of people in the EU, regardless of where the organization itself is located. A US company with EU users is subject to GDPR. A Hong Kong company with EU users is subject to GDPR. The extraterritorial reach of GDPR is part of why it has become the de facto global standard: companies that need to comply for their EU users often apply the same practices to everyone, because running separate policies for different user bases is expensive.

What GDPR requires of services that store your photos and files:

GDPR requires that data be processed under a lawful basis — meaning the company must have a legitimate reason for processing your data that is recognized under the regulation. For cloud storage, the typical lawful basis is contractual necessity: they process your files because you asked them to store your files.

GDPR requires that personal data be processed for specified, explicit, and legitimate purposes, and not further processed in ways incompatible with those purposes. A company that stores your photos to provide storage service and then uses those photos for AI training or advertising targeting is potentially violating the purpose limitation principle — though the legal analysis depends on whether the company has disclosed this and obtained appropriate consent.

GDPR requires data minimization: collecting only what is necessary for the stated purpose. A storage service doesn’t need to analyze the content of your photos to provide storage; doing so anyway raises questions under data minimization.

GDPR grants specific rights to individuals: the right to access their data, the right to correct it, the right to erasure (the “right to be forgotten”), the right to portability (receiving a copy of your data in a usable format), and the right to object to certain processing.

GDPR requires appropriate technical and organizational security measures to protect personal data against unauthorized access, loss, or destruction. Encryption is typically part of what “appropriate technical measures” means, though GDPR doesn’t specify encryption standards.

What GDPR does not require:

GDPR does not require end-to-end encryption. A service can be GDPR compliant while having access to your file content, as long as that access is disclosed, secured, and used for stated purposes.

GDPR does not prohibit analyzing your photos or files for purposes you’ve consented to. If you agreed to terms of service that include content analysis for improving AI models, and that was disclosed, that processing may be GDPR compliant.

GDPR does not require free services to be funded by anything other than advertising. An advertising-funded cloud storage platform can be GDPR compliant — it just needs to handle the data properly and be transparent about what it does.


What CCPA Actually Is

The California Consumer Privacy Act, significantly amended by the California Privacy Rights Act (CPRA) that took effect in 2023, is California state law governing data privacy rights for California residents.

CCPA is less comprehensive than GDPR but covers the largest US consumer market and has had significant influence on data practices for companies that serve California users. Like GDPR, the extraterritorial effect is real: a company serving California users is subject to CCPA regardless of where the company is based.

What CCPA requires:

CCPA requires businesses to disclose what personal information they collect, for what purposes they collect it, and whether they sell or share it with third parties.

CCPA gives California residents the right to know, the right to delete, the right to opt out of the sale of their personal data, and the right not to be discriminated against for exercising these rights.

CCPA defines “selling” personal data broadly — a company doesn’t need to receive money for sharing data to trigger opt-out requirements. Sharing data with advertising partners in ways that allow those partners to use it for their own purposes can qualify as a “sale” under CCPA.

What CCPA does not require:

Like GDPR, CCPA doesn’t require specific encryption standards. It requires “reasonable security measures,” which is less prescriptive.

CCPA doesn’t prevent companies from using your data for their own internal purposes, including analysis and improvement of services, as long as they disclose this.

CCPA’s deletion rights come with significant exceptions. Data can be retained if it’s necessary to complete a transaction you requested, to comply with legal obligations, or for other specified purposes. A service claiming CCPA compliance can still retain your data in many circumstances even after a deletion request.


What “Compliant” Actually Signals

When a service says it’s GDPR or CCPA compliant, it’s asserting that it meets the minimum legal requirements of those frameworks. This is a meaningful floor, not a meaningful ceiling.

Meeting minimum requirements under GDPR means: you have a privacy policy that discloses what you collect and why, you have processes in place to handle data subject rights requests, you have a lawful basis for processing, and you take reasonable security measures.

It does not mean: your encryption is strong, you don’t analyze your users’ photos for AI training, you don’t sell data in any meaningful sense, or that your privacy practices would satisfy anyone who read your policy carefully.

A service can be GDPR compliant while:

  • Analyzing the content of your photos to build advertising profiles
  • Retaining your data in server backups for years after you request deletion
  • Sharing data with affiliated companies under privacy-policy-disclosed data sharing arrangements
  • Training AI models on your content, if this is disclosed in terms you agreed to

The compliance label tells you the service has thought about data protection. It doesn’t tell you much about whether the service is actually good steward of your data.


Reading the Gap Between Compliance and Practice

The gap between “compliant” and “good steward” shows up in specific places in a privacy policy. Once you know what to look for, evaluating a service’s actual privacy stance becomes more tractable.

Training AI on user content. Look for explicit language about whether your content is used to train machine learning models. This should be in the privacy policy in clear terms — not implied, not buried in a data uses section. If the policy describes “improving our services” without specifying what that improvement involves, it may include model training. Ask directly via the service’s data subject access request process if the policy is unclear.

Duration of deletion. When you delete a file, how long until it’s gone? GDPR’s right to erasure requires deletion “without undue delay” — but the definition of undue delay is vague, and the exceptions are substantial. A service that says files are permanently deleted after a specific defined window (e.g., 30 days) is making a more concrete commitment than a service that says deletion is “processed in accordance with our retention policy.”

Sharing with third parties. GDPR and CCPA both require disclosure of what’s shared with third parties and why. Read this section carefully. “We may share data with our partners and affiliates” is very different from “We never sell your data to third parties.” The first is consistent with extensive data sharing; the second limits it. The specific language matters.

Data transfers outside the EU. If you’re in the EU, data transferred to US or other non-EU servers requires specific safeguards under GDPR — either Standard Contractual Clauses, the EU-US Data Privacy Framework, or another approved mechanism. A GDPR-compliant service that transfers EU user data to the US must document which mechanism it uses. If this isn’t in the policy, it’s worth asking.

Access by service employees. GDPR requires that access to personal data be limited to what’s necessary (the principle of data access minimization). But it doesn’t prohibit all employee access. Ask specifically: can service employees access the content of my stored files? Under what conditions? This question distinguishes services where files are technically accessible to staff from services where encryption is designed to prevent that access.


What Genuinely Strong Commitments Look Like

Some services make commitments that go materially beyond minimum compliance. These are worth recognizing because they represent actual differences in privacy protection, not just marketing differentiation.

Explicit AI training prohibition. A commitment not to train AI models on user content, stated clearly in the privacy policy, is a real commitment that compliance alone doesn’t require. When it’s in the policy as a commitment rather than implied by absence, it creates an obligation the company is contractually bound to.

Concrete deletion timelines. A specific and short deletion timeline — “permanently and irreversibly erased within 30 days of deletion” — is more protective than the legally compliant but vague “deleted without undue delay.” The specificity limits room for interpretation and makes compliance easier to evaluate.

No advertising, no data sales. A service with no advertising revenue and an explicit commitment not to sell user data doesn’t have the structural incentives that make compliance-while-monetizing-your-data-anyway possible. This is a business model commitment, not just a legal commitment.

Explicit encryption standards. Stating the specific encryption standard used (AES-256 at rest, TLS 1.3 in transit) is more useful than saying “we use industry-standard encryption.” The specific commitment is verifiable and auditable in a way that vague assurances are not.

Daftei commits to AES-256 encryption at rest and TLS 1.3 in transit, explicitly never trains third-party AI on user content, never sells user data, never shows ads, and permanently and irreversibly erases data after a 30-day deletion window. The service is GDPR and CCPA compliant — but those labels are the floor, not the ceiling of what it commits to.


The Questions to Ask Any Service

When evaluating a cloud storage provider — particularly for personal photos and files you consider private — ask these specific questions and look for specific answers in the privacy policy:

  1. Does the company use my stored content to train machine learning or AI models?
  2. When I delete a file, when is it permanently and irreversibly gone?
  3. Does the company share my data with third parties? For what purposes?
  4. Can company employees access the content of my stored files?
  5. Does the company show advertising to me based on my content?
  6. What encryption is used for files at rest and in transit?
  7. If the company is acquired or goes bankrupt, what happens to my data?

A service with good answers to these questions — clear, specific, policy-backed answers, not marketing language — is a materially better steward of your data than a service that can only point to a “GDPR Compliant” badge.


Compliance Is the Starting Point

The presence of GDPR or CCPA compliance language on a service’s website is meaningful baseline information. It tells you the service has engaged with data protection requirements at a legal level. It does not tell you the service treats your data the way you’d want it to be treated if you read every document and knew every practice.

The standard for your personal photos and files — particularly the ones that are most private — should be higher than legal minimum compliance. The questions above give you a way to evaluate actual practice rather than just stated compliance.

The gap between “compliant” and “trustworthy” is exactly where most of the interesting privacy decisions live.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts