GDPR doesn't stop at your privacy policy – it lives in your inbox

iconSebastián Glonek
icon4 min read
iconSeptember 18, 2026
Article hero image
Your inbox is your biggest GDPR surface. What the regulation asks of email and collaboration providers — and how to check yours measures up.

Ask a company where its personal data is, and most will point at a CRM or a database. Then check the inbox: CVs from applicants, contracts, customer complaints, employee requests, medical certificates sent to HR. For most organizations, email is the largest uncounted collection of personal data they have — and the one with the least governance.

What GDPR actually asks of your email setup

Strip the legal language and the regulation lands on mail infrastructure in five practical places:

Residency. Personal data of EU residents needs to stay under EU jurisdiction — or move under strict transfer mechanisms. "Where is our email data, physically?" is a GDPR question, and "somewhere in the cloud" is not an answer.

Erasure. When someone exercises the right to be forgotten, their data in your mailboxes, archives and backups is in scope. Deleting a user and hoping is not a process.

Access requests. When someone asks what data you hold on them, email is where half of it lives. You need to be able to search, find and export it.

Processor accountability. Your email provider processes personal data for you. You need a data processing agreement, clarity on sub-processors, and confidence in their security measures.

Security appropriate to the risk. Encryption, access control, authentication — GDPR's article 32 in admin terms.

How IceWarp helps you meet GDPR requirements

You choose where the data lives. Run IceWarp in our European data centers — with EU-hosted data staying permanently in the EEA — or self-host on your own infrastructure, where personal data never leaves your building at all.

A concrete setup checklist, not just promises. On our GDPR page we publish the actual configuration steps we recommend: SmartAttach DLP to stop sensitive attachments leaving, archiving for retention policies, two-factor authentication, S/MIME message signing, dedicated service accounts, and full audit logs. It's a checklist you can work through, not a whitepaper you can frame.

One platform, one processing relationship. Every extra SaaS tool in your communication stack is another processor to assess, another DPA to sign, another sub-processor list to read. Consolidation is a GDPR strategy, not just an IT preference.

Certified processes behind the platform. IceWarp holds ISO/IEC 27001 certification and an independent SOC 2 Type II audit report — documentation you can reference in your own accountability records.

A DPO who answers. Questions about how we process data? Our data protection officer is reachable at dpo@icewarp.com.

There is no auto-compliance

No software makes you "GDPR compliant" — compliance is a property of your organization's processes, and any vendor claiming their product delivers it is selling you a shortcut that doesn't exist. What a platform can do is give you the controls, the residency, the documentation and the audit trail that your compliance work builds on. That's what we built.

See the full checklist

Our GDPR page includes the complete recommended setup, the DPA details and the DPO contact — everything in one place.

FAQ

Where is our email data stored with IceWarp? You choose, upon registration you can select the data-center location You want. IceWarp stores your data only in the datacenter you choose, ensuring full compliance with your legal requirements. Our European data centers in the Czech Republic, Germany and Italy keep EU-hosted data permanently in the EEA, or self-host on your own servers and keep data on your own infrastructure entirely.

Can we fully delete a user's data on request? Yes. Administrators control mailboxes, archives and retention policies, so erasure requests can be executed and evidenced. Self-hosted deployments give you control down to the storage layer.

Do we need a data processing agreement with IceWarp? For cloud deployments, yes — and we provide one. It covers our role as processor, our security measures and our sub-processors, as GDPR requires. Self-hosted deployments keep processing on your infrastructure.

How do we handle a data-access request? IceWarp's search and export capabilities let administrators locate and export a person's data across mailboxes and archives — turning a subject-access request from a scavenger hunt into an afternoon task.

Is cloud or self-hosted better for GDPR? Both can support your compliance work. EU cloud keeps data permanently in the EEA with certified data-center infrastructure while self-hosted adds complete physical control. The deciding factor is usually your organization's risk model and IT capacity, not the regulation itself.