Most software vendors describe their approach to data protection in similar terms: privacy by design, security built in from the start, data protection taken seriously. These phrases appear across nearly every vendor’s marketing material, largely because they cost nothing to state and are rarely independently verified. For buyers, it’s difficult to distinguish vendors with genuinely defensible practices from those that merely present themselves convincingly.
With Nextcloud, that distinction was recently put to the test by an independent party.
On July 16, 2026, the Dutch education and research IT cooperative SURF and the privacy and data-protection consultancy Privacy Company published the results of a joint Data Protection Impact Assessment (DPIA) for self-hosted Nextcloud Enterprise.
A DPIA is a formal, structured evaluation process, often required or recommended under GDPR for higher-risk data processing, carried out by an independent party rather than the vendor itself. It’s a level of scrutiny that procurement and legal teams tend to take very seriously.
The DPIA initially identified 15 data protection risks, for which Nextcloud promptly implemented mitigations. SURF then negotiated an amended Data Processing Agreement (DPA), reclassifying all 15 risks as resolved or low.
No access to customer’s content data
The identified risks were located in four areas: admin and commercial contact data, support data, optional diagnostic data that administrators can choose to share, and website data. Notably, no risks were found for content data (the files customers store on Nextcloud) because we have no access to this data, even when providing support.
This lack of access to content data isn’t a contractual promise but a result of how the software is built. By default, we process only minimal personal data, generally limited to contact details for administrators or procurement contacts. The company also holds CSPN certification from ANSSI, France’s national cybersecurity agency, which independently verified its secure storage, authentication, access control, and secure communications.
For users of Nextcloud Office, the DPIA makes a distinction between the available office suites. It points out that for customers who use Collabora Online, support tickets could be handled by staff in the UK, whereas Euro-Office can be used with fully EU-exclusive data processing.
SURF secured an amended DPA limiting Nextcloud’s role as processor to four specific purposes, with seven additional « further processing » purposes where Nextcloud may act as controller. It also obtained a hard guarantee that Nextcloud will never disclose personal data to authorities outside the EU, along with its own audit rights to verify ongoing compliance, limited data retention periods, and minimal cookie use. SURF negotiated these terms specifically for the Dutch education and research sector.
Implications for enterprise buyers
The responsibility to ensure data privacy doesn’t end with the vendor. Customers are expected to minimize what their administrators choose to share through diagnostic settings and implement security measures to avoid falling into a « high risk » category on their own end.
For a market where most vendors’ privacy claims go untested, the DPIA gives Nextcloud a documented account from an independent party, including what it found and what changed as a result. This doesn’t replace an organization’s own due diligence, but it gives both existing and prospective customers a concrete starting point for their evaluation.
The full DPIA is publicly available through SURF’s Vendor Compliance page. If you’re assessing Nextcloud Enterprise for your own organization, you can request a free trial or contact us for a quote tailored to your needs. We’ll talk through what a deployment would look like and which data residency and hosting configuration fits your needs.