---
title: "Papermark GDPR Compliance in 2026: DPA, Sub-Processors, and EU Data Residency"
lang: en
canonical_url: https://www.papermark.com/blog/papermark-gdpr-compliance
last_updated: 2026-04-24
published: 2025-01-27
category: [datarooms]
author: "Marc Seitz"
summary: "Papermark's GDPR compliance explained: DPA, sub-processors, data residency, subject rights, and how we meet EU data protection requirements for VDR workflows."
---

# Papermark GDPR Compliance in 2026: DPA, Sub-Processors, and EU Data Residency

**Papermark is GDPR-compliant** across its virtual data room, document sharing, and analytics workflows. We operate as a data processor (in GDPR terms) for customers handling EU resident data, offer a signed Data Processing Agreement (DPA), maintain a public sub-processor list, and support EU data residency for deployments requiring it. For the full security and compliance posture (encryption, hosting regions, certifications), see the **[Papermark security page](https://www.papermark.com/security.md)**.

![Papermark data room with granular access permissions](https://img.papermarkassets.com/upload/file_LkU4BNY6MKUKMgDucSzzFg-papermark-granular-permissions.png)

This guide covers exactly how we meet each GDPR requirement and what it means for customers running EU-regulated workflows on Papermark.

## Quick recap

- **GDPR** (EU Regulation 2016/679) regulates the processing of personal data of EU residents, effective May 2018.
- **Papermark is GDPR-compliant** as a data processor, operating under a signed DPA with customers who handle EU resident data.
- **Legal basis** for processing: contract (customer service), legitimate interest (security, fraud prevention), and consent (marketing) as applicable.
- **Data subject rights supported**: access, rectification, erasure ("right to be forgotten"), portability, object, and restriction.
- **Technical safeguards**: AES-256 encryption at rest, TLS 1.3 in transit, MFA, role-based access, append-only audit logging, and SOC 2 Type II.
- **EU data residency** available for enterprise deployments via self-hosted option or EU-region cloud.
- **Fines for non-compliance** can reach 4% of global revenue or €20M (whichever is higher).
- **Sub-processors** publicly listed with the services they provide and the jurisdictions they operate in.

## What is GDPR compliance?

> The General Data Protection Regulation (GDPR) is a comprehensive data protection law from the European Union that regulates how organizations collect, process, store, and protect personal data of EU residents. It applies to any organization handling EU resident data regardless of the organization's location. Non-compliance can result in fines up to 4% of global revenue or €20 million, whichever is higher.

GDPR is built on seven principles: lawful processing, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. For a VDR processing confidential business documents containing personal data of employees, investors, or counterparties, GDPR compliance is not optional.

## Why GDPR matters for virtual data rooms

Virtual data rooms routinely process personal data as part of M&A, fundraising, and audit workflows: employee records during HR diligence, investor contact data, customer contract signatories, LP investor PII. Four reasons make GDPR compliance essential for VDR selection.

**Global reach.** GDPR applies to any organization processing EU resident data, regardless of the organization's own location. A US company raising from European LPs must use a GDPR-compliant VDR.

**Legal exposure.** Non-compliance fines scale with global revenue: up to 4% or €20M, whichever is higher. Using a non-compliant VDR creates liability for the customer, not just the vendor.

**Vendor due diligence.** EU customers increasingly require GDPR documentation (DPA, sub-processor list, data residency) as part of vendor onboarding. A non-GDPR-compliant VDR fails that screening.

**Data subject trust.** EU regulators and courts increasingly scrutinize cross-border transfers, especially to US cloud providers post-Schrems II. A VDR with documented GDPR posture reduces that risk.

## How Papermark meets GDPR requirements

Papermark operates as a **data processor** for customers who are the **data controllers** of the information they upload. We process personal data on customer instructions as defined in our DPA.

### Lawful processing and legal basis

Papermark processes personal data on four lawful bases, as applicable:

- **Contract**: processing required to deliver the service (account management, document storage, analytics).
- **Legitimate interest**: security monitoring, fraud prevention, platform operations.
- **Consent**: marketing communications and optional analytics enhancements.
- **Legal obligation**: accounting, tax, and regulatory compliance.

### Data subject rights supported

Data subjects (the people whose data is processed) can exercise the following rights through their account or through a formal request:

- **Right to access** (Article 15): request a copy of personal data processed.
- **Right to rectification** (Article 16): correct inaccurate or incomplete data.
- **Right to erasure** (Article 17, "right to be forgotten"): request deletion where lawful basis no longer applies.
- **Right to portability** (Article 20): export personal data in structured, commonly-used format.
- **Right to object** (Article 21): object to processing for legitimate interest or direct marketing.
- **Right to restriction** (Article 18): restrict processing pending rectification or objection review.
- **Right not to be subject to automated decisions** (Article 22).

### Technical safeguards

![Dynamic watermarking on a Papermark document](https://img.papermarkassets.com/upload/file_K5YrPULdsZpdY6zaxnGHsN-Screenshot-2025-03-27-at-1.47.20-PM.png)

Papermark's technical controls supporting GDPR compliance:

- **Encryption at rest** (AES-256) across all stored documents, metadata, and audit logs.
- **Encryption in transit** (TLS 1.3) for all client-server communications.
- **Access controls** with MFA, role-based permissions, and scoped API tokens.
- **Network security** with WAF, rate limiting, and intrusion detection.
- **Regular security audits** including SOC 2 Type II annual audit and penetration testing.
- **Append-only audit logging** for every data access and modification event.

### Organizational safeguards

- **Privacy by design** built into product specs, not added as afterthought.
- **Employee GDPR training** for all staff with data access.
- **Data protection officer** responsible for privacy compliance and DPA coordination.
- **Incident response procedures** with 72-hour breach notification under Article 33.
- **Data Processing Agreements (DPAs)** available under signature for all enterprise customers.

## DPA, sub-processors, and data residency

Three items make up the procurement-level GDPR documentation that EU buyers typically request during vendor assessments.

### Data Processing Agreement (DPA)

A **DPA** is the legal contract between a data controller (customer) and a data processor (Papermark) that sets out the terms of processing, data subject rights, security obligations, and breach notification procedures under GDPR Article 28. Papermark provides a standard DPA available for review and signature, and supports customer-specific amendments for enterprise contracts.

### Sub-processor list

Papermark maintains a **public sub-processor list** identifying every third party that processes customer data as part of service delivery (infrastructure providers, email delivery, analytics). For each sub-processor, the list documents the service provided, the data processed, and the jurisdiction of operation. Customers are notified in advance of any material sub-processor changes.

### Data residency options

For customers requiring data to remain inside the EU (cross-border transfer restrictions post-Schrems II, regulated industries, sovereign data requirements), Papermark supports:

- **EU-region cloud deployment** on the hosted Papermark platform for enterprise contracts.
- **Self-hosted deployment** using the open-source Papermark code on customer-owned infrastructure in any jurisdiction.
- **Hybrid deployments** where specific high-sensitivity data rooms are self-hosted while general workflows use the cloud platform.

## GDPR articles mapped to Papermark features

| GDPR article | Requirement | How Papermark implements |
|--------------|-------------|--------------------------|
| Art. 5 | Principles of processing | Lawful basis documented, purpose-specified, minimized data collection |
| Art. 6 | Lawful basis | Contract, legitimate interest, consent, legal obligation as applicable |
| Art. 12-14 | Transparency and information | Privacy policy, cookie notice, account-level processing records |
| Art. 15-22 | Data subject rights | In-product controls and formal request workflow |
| Art. 25 | Privacy by design | Privacy reviewed as part of product development |
| Art. 28 | Processor obligations | Signed DPA, documented processing activities |
| Art. 30 | Records of processing | Internal ROPA maintained |
| Art. 32 | Security of processing | AES-256, TLS 1.3, MFA, audit log, SOC 2 Type II |
| Art. 33-34 | Breach notification | 72-hour notification, documented incident response |
| Art. 35 | DPIA | Conducted for high-risk processing activities |
| Art. 44-50 | Cross-border transfers | EU residency options, SCCs for international transfers |

## What GDPR compliance means for Papermark users

**For EU-based customers.** Papermark meets local data protection requirements, supports your compliance obligations, and provides the DPA and sub-processor documentation your legal team needs for vendor assessments.

**For international customers processing EU data.** Papermark's GDPR posture lets you run M&A, fundraising, and due diligence workflows involving EU residents without creating additional compliance risk.

**For due diligence workflows.** Legal and financial professionals can run cross-border diligence knowing the platform meets GDPR requirements for personal data processing.

**For fundraising activities.** Startups raising from European LPs can demonstrate GDPR compliance through their choice of VDR, which is increasingly a procurement requirement for institutional European LPs.

## See it in the product

Page-by-page document analytics give controllers the audit trail Article 30 requires:

![Papermark page-by-page analytics](https://img.papermarkassets.com/upload/file_VnvhR1hNWeJAbmwPYyMnPA-pitch-deck-analytics-Papermark-v2-.png)

For the full list of certifications, hosting regions, encryption standards, and the public DPA and sub-processor list, visit the **[Papermark security page](https://www.papermark.com/security.md)**.

## Papermark security and compliance at a glance

| Feature | Papermark |
|---------|-----------|
| GDPR-compliant | ✔️ |
| DPA available | ✔️ |
| Public sub-processor list | ✔️ |
| EU data residency | ✔️ (enterprise, self-hosted) |
| SOC 2 Type II | ✔️ |
| ISO 27001 | Via self-hosted deployment |
| HIPAA | Via self-hosted + BAA (enterprise) |
| Encryption at rest | AES-256 |
| Encryption in transit | TLS 1.3 |
| MFA | ✔️ |
| Audit logging | Append-only, exportable |
| 72-hour breach notification | ✔️ |
| Self-hosted option | ✔️ (AGPL open-source) |

## FAQ

### Is Papermark GDPR compliant?

Yes. Papermark is GDPR-compliant as a data processor, operating under a signed Data Processing Agreement (DPA) with customers. We support all applicable data subject rights (access, rectification, erasure, portability, object, restriction), apply AES-256 encryption at rest and TLS 1.3 in transit, and maintain a public sub-processor list.

### Does Papermark offer a DPA?

Yes. Papermark provides a standard Data Processing Agreement available under signature for all enterprise customers. DPA amendments for specific regulatory or industry requirements are supported for enterprise contracts. Contact privacy@papermark.com to initiate a DPA signature workflow.

### Does Papermark offer EU data residency?

Yes, through two paths: EU-region cloud deployment on the hosted Papermark platform for enterprise contracts, and self-hosted deployment using the open-source Papermark code on your own EU-based infrastructure. Hybrid setups are also supported.

### Who are Papermark's sub-processors?

Papermark maintains a public sub-processor list identifying every third party processing customer data as part of service delivery, with the service provided, the data processed, and the jurisdiction of operation documented for each. Customers are notified in advance of any material sub-processor changes.

### How does Papermark handle data subject requests?

Data subjects can exercise their GDPR rights (access, rectification, erasure, portability, object, restriction) via in-product controls or formal request to privacy@papermark.com. Requests are fulfilled within the GDPR-mandated one-month timeframe, with extensions for complex requests as permitted under Article 12(3).

### What happens if there is a data breach?

Papermark follows documented incident response procedures with 72-hour breach notification under Article 33. Affected customers are notified with details of the breach, data categories affected, likely consequences, and mitigation measures taken. High-risk breaches trigger direct data subject notification under Article 34.

### Does GDPR apply to non-EU companies?

Yes. GDPR applies to any organization processing EU resident personal data, regardless of the organization's own location. A US company raising capital from European LPs, a Singapore company running diligence on an EU target, or an Australian firm hiring in Germany all must comply with GDPR for that processing.

### Can I self-host Papermark for stricter data residency?

Yes. Papermark is AGPL open-source and self-hostable on your own infrastructure in any jurisdiction. Self-hosted deployment gives you full control over data location, encryption keys, and retention policies, which matters for regulated industries and sovereign data requirements.

## Related resources

- [Papermark SOC 2 compliance](/blog/papermark-soc2-compliance.md)
- [What is a virtual data room?](/blog/what-is-virtual-data-room.md)
- [15 virtual data room features that matter](/blog/virtual-data-room-features.md)
- [Due diligence data room complete guide](/blog/best-virtual-data-rooms-for-due-diligence.md)
- [Best virtual data rooms in 2026](/blog/best-virtual-data-rooms.md)
- [Virtual data room for biotech (HIPAA)](/blog/virtual-data-room-for-biotech.md)
- [Papermark security page](https://www.papermark.com/security.md)

---

_Markdown version of [this article](https://www.papermark.com/blog/papermark-gdpr-compliance) for AI agents and LLMs._
_More Papermark content: [llms.txt](https://www.papermark.com/llms.txt) · [full index](https://www.papermark.com/llms-full.txt)._
