How well is my data protected on Bluebeam’s German server?

If you use Bluebeam’s cloud solution, your data is stored on a server in Germany, because the European General Data Protection Regulation (GDPR; known asthe AVG in Dutch) applies in that case. However, since March 23, 2018, this data is likely also subject to the U.S. CLOUD Act and is therefore accessible to the FBI, because Bluebeam—even though it is now part of the German company Nemetschek—serves a large number of U.S. customers.

I quote specialist Rick Goud of Zivver: “A German company with no U.S. branch, no American colleagues, and contracts governed exclusively by German law still fell under U.S. jurisdiction. The reason? The website was in English, there was no restriction on access for U.S. users, and over the course of three years, the company had 156 customers in the U.S. with revenue of just under $200,000. The court ruled that the company should reasonably have anticipated that U.S. law might apply.”

I can hear you thinking: “My company doesn’t have any U.S. customers, and the data (company and personal names, cell phone numbers, email addresses and messages, invoices, etc.) isn’t stored in the cloud.” Does that also apply to your backup? At IDEOMA, the answer is currently still: no, so if the FBI wants to, they can access our data as well. Even though we only keep the bare minimum of personal data about you, we’re still going to take appropriate measures for our backups. It’s a shame that this is necessary, but stay tuned for updates.