# How does Cyber Crucible support data protection requirements in Ireland?

**Short answer:** In Ireland, Cyber Crucible supports an organization's obligations under the GDPR and the Data Protection Act 2018 (enforced by the Data Protection Commission) by collecting no customer content, credentials, or keys and processing on the endpoint. Ireland is the lead supervisory authority for many multinationals, which raises the bar for vendor scrutiny; the minimal data footprint keeps the vendor side low-risk.

## How it aligns

- **GDPR + DPA 2018.** Data minimization, encryption, and access control support the Irish baseline; a data processing agreement is available.
- **Data residency.** On-premises deployment keeps personal data in Ireland where required.
- **Cybersecurity regime.** Ireland's NIS2 transposition was still being finalized as of 2026; Cyber Crucible supports covered entities' measures under the framework as adopted.

## The honest boundary

The Data Protection Commission is a prominent lead authority in the EU; compliance is the organization's. Cyber Crucible holds no Irish certification and supports these duties. Documentation is available on request.