GDPR check

Is Nextcloud GDPR compliant? What universities should check

Nextcloud is the open-source file and collaboration platform many European universities and research networks run on their own servers. Because the institution, or a hosting partner it chooses, operates it, the GDPR questions look different from those for US cloud services. This page sets out what Nextcloud documents and what that means for a university.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Nextcloud is open-source software developed by Nextcloud GmbH in Germany. Most universities run it on their own servers or through a hosting partner, so the institution decides where data lives, who administers it and which apps are enabled. Nextcloud GmbH says it has no access to customer data in a self-hosted deployment and that no processor agreement with it is therefore needed. That removes the US transfer questions that dominate other storage checks, but it moves the security, patching, backup and configuration work to the university or its host. Enterprise subscriptions add support and early security patches. Sunet Drive, run by the Swedish research and education network Sunet, is built on Nextcloud.

What Nextcloud documents publicly

The table summarises Nextcloud's legal notice, enterprise and GDPR pages, administrator manual and push notification documentation, plus Sunet's description of Sunet Drive, read on 7 October 2026. It concerns Nextcloud Hub as self-hosted or partner-hosted software.

TopicWhat the vendor statesSource
CompanyDocumented Nextcloud GmbH, Hauptmannsreute 44a, 70192 Stuttgart, Germany; commercial register HRB 227086 (Amtsgericht München); managing director Frank Karlitschek.Legal notice [1]
Licence and hosting modelDocumented Nextcloud describes itself as self-hosted open-source software, deployed on the customer's own infrastructure or by hosting partners. Enterprise subscriptions add direct support from Nextcloud engineers, SLAs up to 24/7, early security patches and notifications, and long-term support for stable releases.Nextcloud Enterprise [2]
Processor role and DPADocumented Nextcloud states that "Nextcloud GmbH does not have any access to customer data, removing the need for a data processor or controller agreement" for self-hosted deployments. It offers a GDPR compliance kit with a checklist and an administrator manual.GDPR page [3]
Where data is storedCustomer-controlled Data stays on the servers the institution or its host runs. Nextcloud GmbH does not centrally host customer data in this model.[2], [3]
Sharing controlsDocumented Administrators can allow or block sharing by link and email, enforce passwords on public links, set and enforce maximum expiry for link shares, restrict users to sharing within their groups and exclude groups from sharing. Federated sharing with other Nextcloud servers is a separate setting.Admin manual: file sharing [4]
EncryptionConfiguration-dependent Server-side encryption is off by default, mainly protects files on external storage, and in the default master key mode lets administrators decrypt files. End-to-end encryption is performed by desktop and mobile clients, so server administrators cannot decrypt those files.Admin manual: encryption [5]
Connections to Nextcloud GmbHDocumented Mobile push notifications go through the Nextcloud Push Proxy, a hosted service from Nextcloud, encrypted with the device's public key so only the device can read them. Enterprise customers with branding support can run their own push proxy.Push notifications [6]
AI featuresDocumented Local apps for large language models, translation, speech-to-text, text-to-speech, image generation and OCR run on the institution's servers. Optional integrations connect to external services such as OpenAI and IBM watsonx.ai.Admin manual: AI [7]
Security certificationsNot found A current ISO 27001 certificate for Nextcloud GmbH: not found in public documentation (checked 7 October 2026). For a self-hosted instance, the certifications that matter are those of the university's own data centre or hosting partner.[2], [3]

In Sweden, Sunet, the national research and education network, runs Sunet Drive for higher education. Sunet describes it as combining Nextcloud with Sunet's own S3 storage in a private cloud, with access via SWAMID and full organisational control of stored data for institutions that sign an agreement with Sunet [8]. It is a good illustration of the model: the software comes from Nextcloud, while the operator and the contract are Swedish and academic.

What this means for a university

Validemic's analysis

The university is the operator. With a US cloud service, much of the assessment is about the vendor's contract and transfers. With self-hosted Nextcloud, there is no third-party processor for the core service, so the assessment turns inward: who administers the servers, how quickly security patches are applied, where backups go, how logs are kept, and who can read files. Article 32 GDPR on security of processing [9] applies directly to the university's own operation. An enterprise subscription with early security patches is one way to reduce the patching risk.

Hosted is not the same as self-hosted. When a partner runs the instance, that partner is a processor and needs a DPA, with its own subprocessors and locations. Sunet Drive is an example of a sector-run service; a commercial host is another. Saying a service "runs on Nextcloud" tells you little about data protection until you know who runs your instance and under which contract.

Research data and links. For special category data under Article 9 GDPR [9], the controls to look at first are enforced passwords and expiry on public links, restricting sharing to groups for sensitive projects, and the federated sharing setting, which lets users share with accounts on other Nextcloud servers outside your control [4]. Federation is very useful for multi-university projects, and it is also a path by which data leaves your instance.

Encryption choice. Server-side encryption in master key mode does not protect files from your own administrators [5]. For data where even internal IT access must be excluded, end-to-end encryption is the relevant option. Because the server then only holds data it cannot decrypt, expect server-side features to work less well for those folders, and test the workflow with the research group before committing.

Small data flows still count. The hosted push proxy [6] and any external AI integration [7] are points where data leaves your servers. They are easy to overlook in a records of processing entry because the core service is on-premises.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to settle before approving a Nextcloud service

  1. Who operates our instance: our own IT, a sector service such as Sunet Drive, or a commercial host? If external, do we have a DPA with it?
  2. Do we have an enterprise subscription, and how fast are security updates applied in practice?
  3. Are public links allowed? If so, are passwords and a maximum expiry enforced?
  4. Is federated sharing enabled, and with which servers?
  5. Which encryption mode do we use, and do sensitive projects need end-to-end encryption?
  6. Do mobile clients use Nextcloud's hosted push proxy, and is that recorded in our records of processing?
  7. Which AI apps are installed, and do any send content to external providers?
  8. Where are backups stored, who can restore them, and how long are they kept?

The EU AI Act angle

Nextcloud's AI apps (text generation, translation, transcription) are general-purpose tools, not the education uses listed as high-risk in Annex III of the AI Act [10]. A university that installs them on its own servers is still a deployer, and Article 4, as amended by Regulation (EU) 2026/1744, requires deployers to take measures to support the AI literacy of staff using AI systems [11]. Nextcloud's documentation includes an Ethical AI rating for its apps and a section on AI Act compliance [7]. High-risk obligations for Annex III systems apply from 2 December 2027 [12].

Sources

  1. Nextcloud legal notice, retrieved 7 October 2026
  2. Nextcloud Enterprise, retrieved 7 October 2026
  3. Nextcloud and the GDPR, retrieved 7 October 2026
  4. File sharing configuration, Nextcloud Administration Manual (latest), retrieved 7 October 2026
  5. Encryption configuration, Nextcloud Administration Manual (latest), retrieved 7 October 2026
  6. Nextcloud's push notifications for iOS and Android, Nextcloud blog, 24 October 2023, retrieved 7 October 2026
  7. Artificial Intelligence, Nextcloud Administration Manual (latest), retrieved 7 October 2026
  8. Sunet Drive, Sunet (in Swedish), retrieved 7 October 2026
  9. Regulation (EU) 2016/679 (GDPR), Articles 9 and 32, text read from the Publications Office copy, retrieved 7 October 2026
  10. AI Act Annex III, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 4: AI literacy, AI Act Service Desk (as amended by Regulation (EU) 2026/1744), retrieved 7 October 2026
  12. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Nextcloud's legal notice, enterprise and GDPR pages, the administrator manual sections on sharing, encryption and AI, Nextcloud's push notification documentation, Sunet's Sunet Drive page and the relevant EU legal texts on 7 October 2026. Statements about Nextcloud and Sunet come from those pages; our own interpretation is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular Nextcloud deployment complies with the GDPR. If you spot an error, please contact us and we will correct it.

Frequently asked questions

Is Nextcloud GDPR compliant?

No software is GDPR compliant on its own, and with Nextcloud this is especially clear: when a university hosts it, the university runs the processing and carries the obligations. Nextcloud GmbH says it has no access to customer data in a self-hosted setup and provides a GDPR compliance kit and features such as data export, retention rules and audit logging. Compliance depends on how the instance is hosted, configured and governed.

Does a university need a DPA with Nextcloud GmbH?

Nextcloud says that, because Nextcloud GmbH has no access to customer data in a self-hosted deployment, no data processor or controller agreement is needed with it. A DPA is needed with any hosting provider that runs the instance on the university's behalf, and the university should check whether optional services, such as the hosted push notification proxy or support access, involve Nextcloud GmbH processing any personal data.

Does Nextcloud encrypt files?

Server-side encryption is off by default and is mainly meant for files on external storage; in the default master key mode, administrators can decrypt files. Nextcloud's end-to-end encryption is performed by the desktop and mobile clients, so the server administrator cannot decrypt those files. Each has trade-offs that a university should weigh for sensitive research data.

Is Sunet Drive built on Nextcloud?

Yes. Sunet, the Swedish research and education network, describes Sunet Drive as combining Nextcloud with Sunet's S3 storage in a private cloud, with login through SWAMID and full organisational control over stored data. It is available to organisations that sign an agreement with Sunet.

Can Nextcloud AI features run without sending data to a third party?

Yes, if configured that way. Nextcloud documents local apps for large language models, translation, speech-to-text and other tasks that run on the institution's own servers, as well as optional integrations with external providers such as OpenAI. Which data leaves the server depends on which apps an administrator installs.