Skip to main content

Privacy by Design

GDPR-compliant authentication with privacy by design

Passwordless login with data minimization, consent management, a DPA on every plan, US, EU and Asia-Pacific data residency - and optional MojoShield Zero-Store on Enterprise to keep PII off our servers.

What GDPR requires for authentication

Key GDPR articles that directly impact how authentication systems must be designed and operated.

Data Minimization

Article 5(1)(c)

Personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Authentication systems must not collect more data than needed.

Privacy by Design

Article 25

Data protection must be integrated into processing activities and business practices from the design stage - not bolted on as an afterthought.

Security of Processing

Article 32

Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, pseudonymization, and regular testing.

Consent

Article 7

Where processing is based on consent, the controller must be able to demonstrate that the data subject has consented. Consent must be freely given, specific, informed, and unambiguous.

Data Subject Rights

Articles 15-20

Data subjects have the right to access, rectify, erase, restrict processing, receive their data in portable format, and object to processing of their personal data.

MojoShield Zero-Store - keep PII off auth servers (Enterprise)

The most effective way to protect personal data is to not store it. MojoShield Zero-Store is an opt-in Enterprise capability, activated per project, that keeps PII off MojoAuth servers.

What a Zero-Store project does not store

  • No password hashes for users on passwordless methods
  • No PII in credential databases
  • No persistent user profiles
  • No sensitive personal data at rest

Why this matters for GDPR

  • Data minimization is built into the architecture
  • Right to erasure is simplified - less data to erase
  • Data breach risk is dramatically reduced
  • DPIA scope is minimized

GDPR requirements mapped to MojoAuth

How each GDPR requirement is addressed by MojoAuth capabilities.

Data Minimization

Article 5(1)(c)

  • Optional MojoShield Zero-Store (Enterprise) keeps PII off MojoAuth servers
  • Only essential data processed during authentication
  • No persistent storage of personal data beyond what is needed

Consent

Article 7

  • Configurable consent flows during authentication
  • Timestamped audit trail for all consent records
  • Consent withdrawal support via API

Right to Access / Erasure

Articles 15-17

  • API endpoints for data export (data portability)
  • API endpoints for complete data deletion
  • Less data to export or delete - even less with MojoShield Zero-Store

Security of Processing

Article 32

  • End-to-end encryption with TLS 1.3
  • Multi-factor authentication and bot detection
  • Regular security testing and vulnerability assessments

Data Protection Impact Assessment

Article 35

  • DPIA scope reduced by data minimization (and further by MojoShield Zero-Store)
  • No high-risk processing of authentication credentials
  • Documentation and templates available for DPIA completion

Data Processing Agreement

Article 28

  • DPA available for all plans
  • Sub-processor transparency and notifications
  • Breach notification within 72 hours as required

EU data considerations

Serve EU users with confidence - data residency options and full sub-processor transparency.

Data residency options

MojoAuth offers US, EU and Asia-Pacific data residency. Choose EU residency to keep authentication data within the European Economic Area.

  • EU-based infrastructure available
  • Standard Contractual Clauses (SCCs) for data transfers
  • US, EU and Asia-Pacific data residency

Sub-processor transparency

GDPR Article 28 requires transparency about sub-processors. MojoAuth maintains a public list of sub-processors and notifies customers of any changes.

  • Public sub-processor list maintained
  • Advance notification of sub-processor changes
  • Right to object to new sub-processors

Frequently Asked Questions

Common questions about GDPR-compliant authentication

Schedule a GDPR compliance review

See how MojoAuth supports GDPR with data minimization, EU data residency and optional MojoShield Zero-Store.

Call +1-844-321-AUTH