एन्क्रिप्शन कम्प्लायंस आवश्यकताएं: GDPR, HIPAA और अधिक
GDPR, HIPAA, SOC 2 की एन्क्रिप्शन कम्प्लायंस आवश्यकताओं को समझें। सुनिश्चित करें कि आपके ट्रांसफर कानूनी मानकों को पूरा करते हैं।
फाइल ट्रांसफर के लिए एन्क्रिप्शन compliance पाँच regulations और दो truths पर आती है। GDPR Article 32 personal data के लिए "जहाँ appropriate" एन्क्रिप्शन demand करता है। HIPAA 164.312(a)(2)(iv) और (e)(2)(ii) access control और transmission security address करते हैं। PCI DSS 4.0 Requirement 4 transit में strong cryptography mandate करता है। SOC 2 Common Criteria 6.7 confidential data के transmission को cover करता है। भारत का DPDP Act 2023 personal data की protection और accountability require करता है। दो truths: transit में TLS floor है, ceiling नहीं; सर्वर पर at-rest encryption help नहीं करती अगर provider keys hold करे।
GDPR Article 32 और "Appropriate" Standard
Article 32(1)(a) explicitly encryption को एक technical measure के रूप में list करता है "risk के appropriate level की security" ensure करने के लिए। Recital 83 clarify करता है कि appropriateness state of the art, cost, processing की nature, और risk consider करती है। 2026 practice में, appropriate का मतलब है transit में AES-256-GCM या ChaCha20-Poly1305, plus client-side encryption जब data में Article 9 के special categories (health, biometrics, political views) शामिल हों। EDPB के 2024 Guidelines on Data Transfers to Third Countries end-to-end encryption को supplementary measure मानते हैं जो post-Schrems II non-adequate countries को transfers legitimize कर सकती है।
HIPAA Security Rule और Addressable Standard
HIPAA की एन्क्रिप्शन requirements technically "addressable" हैं न कि "required," जो लोगों को fool करता है। 45 CFR 164.312(a)(2)(iv) और 164.312(e)(2)(ii) कहते हैं कि आपको encryption implement करनी होगी या document करना होगा कि यह reasonable क्यों नहीं है। OCR का 2024 guidance direct है: "addressable का मतलब optional नहीं है।" De facto standard है NIST FIPS 140-3 validated cryptography, जो practice में मतलब है at-rest के लिए AES-256 और in-transit के लिए TLS 1.2+। PHI (DICOM studies, HL7 messages, CCDA documents) handle करने वाली transfer service को BAA offer करना होगा और 164.308(a)(4) के अनुसार access controls demonstrate करने होंगे।
PCI DSS 4.0 पर Cryptographic Strength
Requirement 4.2.1 (March 31, 2025 से effective) open networks पर transmission के दौरान strong cryptography mandate करता है। Strong मतलब TLS 1.2 minimum, 1.3 recommended, approved cipher suites (no RC4, no 3DES, no export-grade) के साथ। Requirement 3.5 key management cover करता है: keys encrypted data से separately stored होनी चाहिए, defined policy के अनुसार rotated, और ज़रूरत न रहने पर destroyed। Requirement 12.3.3 cryptographic cipher suites और protocols का documented inventory demand करता है।
Transmission के लिए SOC 2 Common Criteria
CC6.7 require करता है "the entity restricts the transmission, movement, and removal of information to authorized internal and external users।" Audit practice में, auditors evidence माँगते हैं: TLS configuration (Qualys SSL Labs run करें, A+ expect करें), 12-month retention के साथ access logging, encryption key management policy, और incident response runbook। CC7.2 detection cover करता है; एक file transfer audit trail यह satisfy करती है। Type II reports six-month observation require करते हैं, इसलिए mid-audit adopt किया गया file transfer tool अगले cycle तक count नहीं हो सकता।
CCPA, CPRA, और Encryption Safe Harbor
California Civil Code 1798.150(a) "nonencrypted और nonredacted personal information" के breaches के लिए private right of action create करता है। Translation: अगर breached data उन keys के साथ encrypted था जो attacker को नहीं मिले, आप $100-$750 per consumer per incident के statutory damages से protected हैं। इसने California-serving businesses के लिए strong encryption financially compelling बनाया है। Attorney general की 2024 enforcement actions against Sephora और DoorDash ने at-rest encryption failures cite किए; HSM-protected keys से databases encrypted होतीं तो किसी को भी statutory damages नहीं देने होते।
State-Level Breach Notification और "Encrypted" का मतलब
All 50 US states में अब breach notification laws हैं, और ज़्यादातर encryption carve-out include करते हैं — लेकिन definition vary करती है। New York Shield Act "encryption that renders data unreadable or unusable" require करता है। Illinois PIPA (815 ILCS 530) encryption require करता है "rendering the information unreadable or indecipherable।" Massachusetts 201 CMR 17.00 specify करता है "the transformation of data through the use of an algorithmic process।" Common thread: AES-128 या stronger, keys attacker के accessible नहीं। एक file transfer service जो same server पर ciphertext और keys दोनों hold करती है qualify नहीं करती।
Post-Schrems II Cross-Border Transfer Requirements
EU से US, India, या किसी भी जगह जहाँ adequacy decision नहीं है फाइलें move करने के लिए CJEU के Schrems II ruling (C-311/18) के अनुसार supplementary measures require होते हैं। End-to-end encryption जहाँ transfer service plaintext access नहीं कर सकती gold-standard supplementary measure है, EDPB Recommendations 01/2020 के अनुसार। यह legal analysis shift करती है: client-side encryption के साथ, आपकी US-based S3 bucket ऐसा ciphertext hold करती है जिसे provider read नहीं कर सकता, इसलिए FISA 702 disclosure requests से कुछ useful नहीं मिलता।
DPDP Act 2023: India-Specific Landscape
Digital Personal Data Protection Act 2023 Indian organizations के लिए accountability के नए standards establish करता है। Act के तहत, data fiduciaries (वे organizations जो personal data process करते हैं) को appropriate technical measures — encryption सहित — के ज़रिए personal data protect करना होगा। Cross-border transfers के लिए, Act उन countries को transfers allow करता है जो Central Government notify करे। Client-side encryption यह ensure करती है कि भले ही data foreign servers पर stored हो, fiduciary इसे read नहीं कर सकता — यह DPDP compliance के लिए एक defensible technical position है।
जानने लायक Industry-Specific Additions
FINRA Rule 4511 broker-dealers को electronic records छह साल के लिए non-rewriteable, non-erasable format में preserve करने require करता है — WORM storage with encryption satisfy करती है। FERPA (20 USC 1232g) student records cover करता है; explicit encryption mandate नहीं है, लेकिन Department of Education का 2023 guidance इसे "directory information that is kept confidential" के लिए required मानता है। ITAR और EAR (export control) US-person-only access के बिना munitions पर technical data transmit करने prohibit करते हैं।
Documented Compliance की ओर
Auditors आपको perfect security पर score नहीं करते; वे documented reasonable security पर करते हैं। Cryptographic inventory रखें (algorithms, key sizes, rotation schedules), file transfers trust boundaries कहाँ cross करते हैं उसका data flow diagram, और file transfer provider की certifications (ISO 27001, SOC 2, HIPAA BAA availability) cover करने वाला vendor assessment। सालाना re-review करें। जब breach होगी — और होगी — यह documentation $50,000 fine और $5,000,000 के बीच का फ़र्क है।
hexatransfer.com पर आज़माएं — मुफ्त, बिना अकाउंट, 10 GB तक।
एंड-टू-एंड एन्क्रिप्शन के साथ बड़ी फ़ाइलें सुरक्षित रूप से भेजें
एंड-टू-एंड एन्क्रिप्शन के साथ 10 GB तक की फ़ाइलें मुफ़्त में ट्रांसफ़र करें। अकाउंट की आवश्यकता नहीं। अपलोड से पहले आपकी फ़ाइलें ब्राउज़र में एन्क्रिप्ट की जाती हैं — कोई और उन्हें पढ़ नहीं सकता।
फ़ाइल भेजें