Can a European Zotero user be assured of not breaching the GDPR via Zotero cloud services?
Following the GDPR (General Data Protection Regulation) (https://en.wikipedia.org/wiki/General_Data_Protection_Regulation), a European (EU) individual user must assure that their use of Zotero cloud services does not put their research materials outside of the European Economic Area (EEA), without assuring how and when these data are being used, disposed, disclosed, processed. Can Zotero.Org offer any certainty to UK and EU users that their information saved to its cloud services is not transferred outside of the EEA? If these Zotero cloud servers are located outside of the EEA then it seems there is the possibility of users and their sponsoring organizations permitting the use of such services (e.g. universities) being in breach of new stricter Data Protection Legislation. Please clear this up for us.
1) Because Zotero complies with GDPR stipulations with regards to your own personal data and
2) Because literature and notes about it does not constitute personal data by any definition.
If you want to store sensitive reserach data such as identified interview transcripts in Zotero, that's probably illegal under GDPR, though.
Edit: Or I guess the Adequacy Decision for the US is limited to the Privacy Shield framework? I don't really know anything about that or its relation to GDPR. In any case, Zotero obviously has a huge number of European users, and we've made sure we're in compliance with GDPR to the best of our knowledge. You can read about more about our policies in our privacy policy.
https://kib.ki.se/en/zotero
Faculty and students at KI have been using Zotero almost exclusively for many years as the bib manager of choice.
Zotero is also used by many students and faculty at Ersamus in the Netherlands even though the university has licenses for EndNote and RefWorks.
https://libguides.eur.nl/informationskillscitinginformation/referencemanager
There is no mention anywhere about the Zotero sync itself being a potential violator of GDPR. Zotero users I know use Zotero's own sync system. I don't know about using Zotero to sync to other back-up services. If you intend to use Zotero for cataloging trade secret documents or individual financial or medical documents with personal identifiers that is a different question altogether. GDPR privacy protections will require specialty software for that.
I'd encourage you to read through our privacy policy if you have any doubts about this. Privacy is a reason to use Zotero, not a reason not to.
Are there any plans to update the privacy policy and offer data processing agreements? Did that topic never come up with institutional customers?
Of course, I'm only talking about Zotero Sync, the offline client is not affected by these privacy issues.
This makes the Zotero dataserver and especially a deployable option like ZotPrime really interesting. It is a pity that there is so few documentation and that the Zotero desktop client seemingly must be modified to accept home-brewed sync servers for groups as well.