← Back to Blog

GDPR and Post Quantum Cryptography: How Quantum Safe Encryption Supports Long-Term Compliance

GDPR and Post Quantum Cryptography: How Quantum Safe Encryption Supports Long-Term Compliance - QNSQY post-quantum encryption guide

GDPR Article 32 and PQC

GDPR Article 32 requires controllers and processors to implement "appropriate technical and organisational measures to ensure a level of security appropriate to the risk." It does not mandate specific algorithms. It does require risk-based measures that account for the state of the art and foreseeable threats. HNDL is a foreseeable threat for personal data with multi-decade sensitivity.

When GDPR Implies PQC

PQC becomes a reasonable interpretation of Article 32 when:

  1. Personal data has long confidentiality lifetime (e.g., medical, genetic, financial).
  2. Data is transmitted over channels where HNDL collection is plausible (public internet).
  3. Processing is likely to continue across the expected CRQC horizon (10-20+ years).

For such cases, deploying hybrid ML-KEM in TLS and encrypting data at rest with PQC-aware KMS is part of appropriate measures.

EDPB Guidance

The European Data Protection Board has not issued PQC-specific guidance as of April 2026. Expect guidance through 2026-2027 aligned with ETSI and ENISA PQC work.

Member State Data Protection Authorities

DPAs in Germany (BSI), France (ANSSI), Netherlands (AIVD), and others reference NIST PQC standards in their technical guidance. National security agencies in member states are increasingly PQC-aware.

Data Breach Notification

GDPR Article 33 requires 72-hour breach notification. An HNDL-based decryption of historic data could constitute a breach long after the original transmission. This is legally novel; expect DPAs to clarify.

Practical Steps for GDPR Compliance with PQC

  1. Update Records of Processing Activities (RoPA) to include PQC-related technical measures.
  2. Update Data Protection Impact Assessments (DPIA) to reference quantum threat.
  3. Include PQC in vendor Data Processing Agreements (DPAs).
  4. For data transfers under Chapter V (international), consider PQC as part of "supplementary measures."
  5. Deploy hybrid ML-KEM in public-facing TLS.

International Transfers (Schrems II)

Post-Schrems II, EU data exported to jurisdictions without adequacy decisions must be protected by supplementary measures. PQC is a credible supplementary measure against HNDL, particularly for transfers to jurisdictions with known SIGINT capabilities.

Frequently Asked Questions

Does GDPR mandate PQC?

Not specifically. GDPR Article 32 requires appropriate technical measures that account for state of the art and foreseeable risks. PQC is an increasingly reasonable interpretation for long-lived personal data.

Is HNDL a GDPR breach?

Legally novel. HNDL is future decryption of historically collected encrypted data. A breach notification obligation may arise when historic data becomes decryptable. DPA guidance is expected through 2026-2027.

Should my DPIA reference PQC?

For processing involving long-lived personal data transmitted over public networks, yes. Frame PQC as a mitigating measure against the quantum threat.

Is Signal PQXDH sufficient for GDPR?

Signal PQXDH is a strong technical measure for messaging. For a complete GDPR compliance story, pair with PQC for data at rest and documented organizational measures.

Sources

  1. GDPR Article 32
  2. ENISA PQC

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY

Originally published at quantumsequrity.com/blog/gdpr-pqc-alignment.