GDPR Compliance Mapping
Version: 1.0 Last Updated: September 2026
1. Introduction
This document describes how Nova IAM supports compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) for organizations that process personal data of EU residents.
2. Roles and Responsibilities
| GDPR Role | Entity | Responsibility |
|---|---|---|
| Data Controller | Customer organization | Determines purposes and means of processing identity data |
| Data Processor | Nova IAM (when hosted) | Processes data on behalf of the controller per instructions |
| Data Subjects | End users managed in Nova IAM | Individuals whose identity data is processed |
Note: For self-hosted deployments, the customer organization acts as both controller and processor. Nova IAM provides the software tool only.
3. Lawful Basis for Processing
Nova IAM processes personal data under the following lawful bases:
| Data Category | Lawful Basis | Justification |
|---|---|---|
| Employee identity data | Art. 6(1)(b) — Contract | Necessary for employment relationship and IT access |
| Access/authorization data | Art. 6(1)(f) — Legitimate interest | Security and access control is a legitimate business need |
| Audit log data | Art. 6(1)(c) — Legal obligation | Required for compliance with security regulations |
| AI analysis data | Art. 6(1)(a) — Consent | Opt-in feature, disabled by default |
4. GDPR Article Compliance Matrix
Chapter III — Rights of the Data Subject
| Article | Right | Nova IAM Support |
|---|---|---|
| Art. 13-14 | Information | User profiles display all stored personal data transparently |
| Art. 15 | Access | Full user data accessible via UI and API (GET /api/users/{id}) |
| Art. 16 | Rectification | User data editable via UI and API (PUT /api/users/{id}) |
| Art. 17 | Erasure | Users can be deleted and purged from the recycle bin, manually or automatically after a configurable period (default 90 days). Audit log entries keep actor and target names as written at the time of the event; anonymisation of historical audit entries is not yet supported |
| Art. 18 | Restriction | User accounts can be deactivated (status: inactive) without deletion |
| Art. 20 | Portability | User data exportable in JSON format via API |
| Art. 21 | Objection | AI features are off by default. Excluding individual users from AI analysis is not supported |
| Art. 22 | Automated decisions | The AI does not decide on its own; it acts only on behalf of and with the permissions of the signed-in user. Around 100 critical actions (e.g. delete, revoke) require a confirmation with preview, and changes made via the AI chat are logged with the origin "AI chat". Whether Art. 22 applies to a processing operation is assessed by the controller |
Chapter IV — Controller and Processor
| Article | Requirement | Nova IAM Support |
|---|---|---|
| Art. 25 | Data protection by design | Minimum data collection, parameterized queries, hashed passwords |
| Art. 28 | Processor obligations | Key DPA terms in section 6; a DPA is concluded where we process data on the customer's behalf |
| Art. 30 | Records of processing | The record of processing activities is kept by the controller; the audit log documents changes to accounts, roles and requests |
| Art. 32 | Security of processing | Encryption in transit (TLS), hashed credentials, access controls |
| Art. 33 | Breach notification | 72-hour notification process (see Incident Response Plan) |
| Art. 35 | DPIA | Inputs for the customer's DPIA, see section 8 |
5. Data Protection by Design (Art. 25)
Nova IAM implements the following privacy-by-design principles:
Data Minimization
- Only data necessary for IAM operations is collected
- No tracking, analytics, or advertising data
- Optional fields (phone, location, title) can be left empty
Purpose Limitation
- Data is processed exclusively for identity and access management
- AI features are isolated and opt-in
- No data sharing with third parties beyond configured backend systems and, if enabled, the cloud AI provider
Storage Limitation
- User data can be deleted when no longer needed; deleted users are purged from the recycle bin manually or automatically after a configurable period (default 90 days)
- Audit log entries keep actor and target names as written at the time of the event; anonymisation of historical audit entries is not yet supported
- Audit log retention is managed at database level by the customer
Integrity and Confidentiality
- Passwords hashed with memory-hard algorithm (scrypt)
- All API access authenticated
- Database queries parameterized against injection
- TLS encryption for all external communications
6. Data Processing Agreement (Art. 28)
Where Nova IAM processes personal data on behalf of the customer (for example in a hosted variant), a DPA is concluded. It covers:
- Subject matter and duration — IAM data processing for the contract term
- Nature and purpose — Identity management, access control, compliance
- Type of personal data — Employee identity, access, and audit data
- Categories of data subjects — Employees and contractors of the controller
- Processor obligations:
- Process only on documented controller instructions
- Ensure personnel confidentiality
- Implement appropriate security measures
- Assist with data subject rights requests
- Delete or return data on contract termination
- Make available audit and inspection information
- Sub-processors — Listed and updated with prior notice
- International transfers — Only with adequate safeguards (SCCs if applicable)
7. International Data Transfers
Self-Hosted Deployments
- No data transfers: all data remains on customer infrastructure, unless cloud AI is enabled (see below)
- Customer controls data residency and jurisdiction
Cloud AI Features (Optional)
When cloud AI is enabled, user access data may be transmitted to:
- Anthropic (Claude) — US-based, see Anthropic's DPA
- OpenAI — US-based, see OpenAI's DPA
Customers requiring EU data residency should use the Local AI (Ollama) option, which processes all data on-premises.
8. Data Protection Impact Assessment (Art. 35)
A DPIA should be conducted when Nova IAM is used for:
- Large-scale processing of employee access data
- Systematic monitoring of access patterns (AI analysis features)
- Cross-border data transfers (cloud AI features)
Nova IAM provides the following inputs for customer DPIAs:
- This GDPR compliance document
- Architecture Security Overview
- Data Protection Policy
- Audit Trail Documentation
- Incident Response Plan