---
title: "GDPR: controls supported by Noraina"
description: "Which GDPR controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit."
url: https://www.noraina.cloud/compliance/gdpr/
language: en
---
# GDPR: controls supported by Noraina

Any organisation processing personal data of people in the EU.

> Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

## GDPR (EU) 2016/679

EU regulation on the protection of personal data. References are articles of the regulation.

4 controls supported.

### Efficient Cloud Instances with replication

- Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability)
- How we help: Keeps systems that process personal data available and restorable after an incident in the primary site.
- Evidence you get: Recovery test reports for your Article 32 documentation.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: 32.1.a (Pseudonymisation and encryption); 32.1.c (Timely restoration of availability)
- How we help: Encrypted backups that let you restore access to personal data in a timely manner.
- Evidence you get: Encryption and restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: 32.1.b (Confidentiality); 32.1.c (Timely restoration of availability)
- How we help: Automatic failover, and on the Enterprise plan a second authoritative DNS network, help keep services that process personal data available, and restore access quickly when a primary service fails.
- Evidence you get: NS delegation showing both networks (Enterprise), failover configuration and event history.
- Status: Mapping under review

### Complete edge logging

- Control: art.33 (Breach notification)
- How we help: Lets you establish what happened, and to which data, within the 72-hour notification window.
- Evidence you get: Log retention configuration, investigation runbook.
- Status: Mapping under review

### Application and DDoS protection

- Control: 32.1.b (Confidentiality)
- How we help: Keeps applications that process personal data available and protected against attack.
- Evidence you get: Threat reports for your Article 32 documentation.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: 32.1.b (Confidentiality)
- How we help: Only authorised people reach personal data, and DLP blocks it from leaving through unapproved channels.
- Evidence you get: Access policy export, DLP incident reports.
- Status: Mapping under review


We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/gdpr/#assessment
