Nextcloud on Virtualmin for Associations: Setting Up GDPR-Compliant End-to-End Encryption and Server-Side Encryption
Learn how to set up Nextcloud on Virtualmin for your association in a GDPR-compliant way and protect sensitive association documents with end-to-end and server-side encryption – even if the server is compromised or you change hosting providers.
Why associations should rely on GDPR-compliant encryption
Associations often manage highly sensitive data: member lists, financial records, minutes, or personal data of volunteers. The GDPR requires that personal data be adequately protected – in particular through encryption. A compromised server or a change of hosting provider must not result in unauthorized persons gaining access to this data. With end-to-end encryption (E2EE) and server-side encryption (SSE), Nextcloud offers exactly the right tools. In this article, we will show you how to set up Nextcloud on Virtualmin for your association and correctly configure both encryption methods.
Requirements: Virtualmin, Nextcloud, and the right infrastructure
Before you start with encryption, you need a solid foundation. We recommend a virtual server or web hosting plan that offers sufficient resources. For associations, a VPS with at least 2 GB RAM and sufficient storage is often enough. On the server, you install Virtualmin to conveniently manage domains and services. For Nextcloud, you create a separate subdomain, e.g. cloud.dein-verein.de. You can register a domain directly with us.
After installing Virtualmin and Nextcloud (ideally via the installation script), you should ensure that PHP, MySQL/MariaDB, and a web server (Apache or Nginx) are running correctly. Enable HTTPS with a Let's Encrypt certificate so that the connection between client and server is encrypted.
Step 1: Install Nextcloud on Virtualmin
Log in to Virtualmin and create a new virtual server for your cloud domain. Allocate sufficient resources and install PHP 8.1 or newer. Then download the current Nextcloud version and unpack it in the public directory. Set up a database and run the web installer. Assign a strong admin password and enable two-factor authentication for all administrators.
Enable end-to-end encryption (E2EE) in Nextcloud
End-to-end encryption ensures that data is encrypted on the client itself and that the server (or hosting provider) can never access it in plain text. This is ideal for sensitive association documents. Here is how to enable E2EE:
- Log in to Nextcloud as an administrator and go to Apps.
- Search for End-to-End Encryption and enable the app.
- Navigate to Settings > Security and enable end-to-end encryption.
- Each member must use the Nextcloud desktop or mobile app to create encrypted folders. The passphrase is stored only on the devices.
Important: With E2EE, the server cannot offer password recovery. Store the passphrase securely, e.g. in a password manager. For associations, this means: even if the server is hacked, the data remains unreadable.
Set up server-side encryption (SSE)
Server-side encryption protects data at rest, i.e. on the server's hard drive. It makes sense for all files that are not end-to-end encrypted and provides a certain level of protection against theft or improper disposal of hard drives. Here is how to set up SSE:
- Install the Default Encryption Module app (if not preinstalled).
- Enable it under Apps > Security.
- Run the following command on the command line to enable encryption mode:
occ encryption:enable. - Generate a strong password and store it securely:
occ encryption:generate-key. - Encrypt all existing files:
occ encryption:encrypt-all.
Note that SSE only works with a valid key. If you lose it, the data is irretrievably lost. For associations, it is advisable to print out the key and keep it in a safe.
Combination of E2EE and SSE
You can combine both methods: use E2EE for particularly sensitive folders (e.g. personnel files) and SSE for all other data. This gives you multi-layered protection. When changing hosting providers, you can simply migrate the encrypted data – without the new provider seeing plain text.
GDPR compliance and organizational measures
Technical encryption is an important building block, but the GDPR also requires organizational measures. These include:
- Maintaining a record of processing activities.
- Concluding data processing agreements (DPAs) with the hosting provider. DezHost offers corresponding contracts.
- Regular training of association members in handling sensitive data.
- Assigning access rights according to the principle of least privilege.
- Regular backups – encrypted, of course.
With Nextcloud on Virtualmin and the encryption methods described, you are on the safe side. Even if the server is compromised or you change hosting providers, the association documents remain protected.
Conclusion: Security for association data
Setting up Nextcloud on Virtualmin with end-to-end and server-side encryption is not rocket science. With the right instructions and a reliable hosting partner like DezHost, you can significantly improve your association's GDPR compliance. Start securing your sensitive association documents today!
