PDFA-BLOG-004
Filed on
Sovereignty

GDPR: where are your documents, really?

"GDPR compliant" is written everywhere. But the real question is more concrete: where are your files physically stored, and who can reach them? A few points to see clearly.

01Location counts

A service can be "GDPR compliant" and still host your data outside Europe, or depend on a provider subject to extraterritorial laws (the American Cloud Act, for instance), which can allow access to data whatever the place of storage.

02The questions to put to your cloud

  • Where are the servers? (the country, named, not a "region")
  • Is there a transfer outside the EU, even a temporary one?
  • Who are the technical processors, and where are they?
  • Is the provider subject to an extraterritorial law?
  • Can you export and delete your data freely?

03Why "in France, in the EU" matters

Keeping data in the European Union reduces exposure to extraterritorial access and simplifies compliance (no transfer mechanism to justify). For sensitive data such as deeds, medical files or members' records, it is a matter of prudence.

04What PDF Archive does

Servers in France, your documents do not leave the EU (our few technical processors, for payment and for sending email, never have access to their content), encryption on upload, free export, and a list of what we never do (no advertising, no reselling, no advertising profiling). That is the basis of our promise on sovereignty.

An informative article; it does not replace the opinion of a data protection officer.

What your files say without you

A PDF carries the name of its author, the software that produced it and its dates. That can be read, and corrected. And a file encrypted before it goes out no longer depends on what the intermediary does.

© 2026 PDF ARCHIVE · e.i. Valentin Beck · 67200 Strasbourg · hosted in France