Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What are the signs that encryption is not…
Cyber Security

What are the signs that encryption is not enough to protect transferred personal data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Cyber Security

A key sign is when the provider hosting the encrypted data can also restore it to plain text. Another warning sign is when the transfer relies on contractual clauses and encryption at rest, but the recipient can still access the data or is subject to disclosure obligations. In those cases, encryption exists technically, but it may not provide meaningful legal or operational protection.

When encryption stops being a meaningful protection test

Encryption is only one layer of protection. For transferred personal data, the more important question is whether the recipient, hosting provider, or any intermediary can still turn the data back into readable form or access it under ordinary business or legal conditions. If they can, encryption may reduce exposure in transit, but it may not change the real access risk.

That distinction matters because the security value of encryption depends on who controls the keys, where decryption happens, and whether the data remains usable by parties that should not lawfully or operationally have that level of access. If plain text can be restored in the normal course of service delivery, the transfer still carries meaningful exposure.

In practice, weak assurance shows up when encryption is paired with arrangements that leave the recipient able to access the underlying content, such as standard hosting, onward disclosure rights, broad support access, or data handling obligations that can still compel disclosure. In those cases, the encryption is real, but the protection claim may be overstated.

What the warning signs look like in a transfer assessment

A strong warning sign is any setup where encryption-at-rest, transit encryption, or even contractual commitments are treated as the main safeguard while the recipient still has technical or legal paths to the underlying personal data. The issue is not whether encryption exists, but whether the transfer effectively limits access, or merely changes the storage format.

Another sign is when the protected data can be restored by the same provider that stores it, or by a processor and its subprocessors, without a separate trust boundary. That usually means the sender has not reduced the set of parties able to see the data in plain text; they have only altered how the data is handled on the way there.

For sensitive personal data, especially where processing obligations or compelled disclosure are realistic, encryption should be evaluated against the full transfer chain. If the recipient’s operational model still permits inspection, support access, replication, or legal disclosure in readable form, encryption may not satisfy the intended protection outcome.

Encryption protects confidentiality best when the party receiving the data cannot readily decrypt it, and when key control, access pathways, and disclosure conditions are tightly limited. If the recipient can still access the data in usable form, the transfer may remain exposed even if the bytes on disk are encrypted.

This is especially important when organisations assume that a contractual clause or an encryption statement is enough to justify a transfer. A clause can allocate responsibility, but it does not by itself prevent access, reduce recoverability, or stop an authority or operator from obtaining plain text where the system design allows it.

That is why a “protected” transfer should be judged by the actual control outcome: who can read the data, who can compel access, and whether the encryption meaningfully narrows exposure compared with a plain transfer. If those answers do not improve, encryption is a technical feature, not a substantive safeguard.

Risk and Threat Considerations

When transferred personal data remains recoverable by the host or recipient, the main risk is false assurance. Organisations may believe they have reduced exposure while the practical access surface, including support personnel, subprocessors, or disclosure obligations, still allows plain-text use or release.

Failure mechanism: Encryption is implemented without a sufficiently separated trust boundary, so the data can still be decrypted, restored, or disclosed in readable form by parties that handle the transfer.

Impact: Personal data may remain exposed to operational access, compelled disclosure, or downstream misuse, and the transfer may fail to provide the level of protection the organisation assumed it had achieved.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

GDPR provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
GDPRArt.32 — Security of processingEncryption and access control are central to assessing transfer security for personal data.
Art.25 — Data protection by design and by defaultTransfer design must limit plain-text access, not just add encryption after the fact.
Art.5 — Principles relating to processing of personal dataThe answer turns on whether the transfer actually limits exposure and disclosure in practice.
Recommendation — Assess whether encryption meaningfully reduces access and disclosure risk under Art.32. Design transfers so only necessary parties can access personal data in usable form. Verify that transfer controls match the stated purpose, minimisation, and confidentiality principles.

Practitioner Guidance

What to verify: Confirm who holds the keys, where decryption occurs, and whether the recipient or hosting provider can access plain text during normal operations, support, backup restore, or legal disclosure. If any of those paths exist, treat encryption as only partial protection.

Decision rule: If the transfer still permits the recipient to read, restore, or disclose the data in usable form, escalate to a data-transfer assessment based on actual access conditions rather than the presence of encryption alone.

Practitioner takeaway: The key question is not whether data is encrypted, but whether encryption changes who can actually obtain or disclose the personal data in plain text.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org