In brief: A GDPR-compliant digital vault in France does not have a single definition. Depending on your profession—HR, paramedical, accounting, legal—requirements range from simple encrypted partitioning to NF Z42 certification and HDS hosting. Here is a guide to help you choose, and why the sovereign WordPress path may be sufficient—or not.
The term “digital vault” has become a catch-all. Coffreo claims it, Digiposte claims it, SmartVault does too, and the latest edition of your WordPress with an online DMS plugin sometimes presents itself as one. These products do not all do the same thing, do not cover the same obligations, and do not carry the same publisher liability. To choose, you must first know what you are looking for.

Three definitions of the digital vault, three use cases
The first definition is that of evidentiary electronic archiving with enforceable value. It is governed by the NF Z42-013 standard for electronic archiving, and NF Z42-026 for evidentiary archiving. This path is intended for large document volumes requiring long-term retention: payslips, hospital patient records, and high-stakes commercial contracts. Coffreo and Digiposte follow this path. Costs are high, as is the implementation complexity.
The second definition is that of a secure client document portal. This is what HoneyBook, SuiteDash, Copilot, Clustdoc, or Client Vault do. These tools do not claim to replace an evidentiary archiving system. They solve an operational problem: receiving, validating, organizing, and storing documents that clients upload to the firm, under conditions compliant with the GDPR and professional secrecy.
The third definition is that of pure document-based EDM: Document Library Pro, Box, Dropbox Business. These tools store and share. They do not provide structured requests, enforceable timestamps, or strict business-specific partitioning. They are useful, but for a different purpose.
What GDPR requires of a French digital safe
Regardless of the path chosen, a safe that processes personal data — which is to say nearly all of them — must comply with the principles of the GDPR. Article 32 requires appropriate technical and organizational measures: encryption at rest, access control, logging, and backups. Article 28 governs subcontracting through a detailed data processing agreement. Article 5 mandates that storage periods be limited to what is strictly necessary for the purpose.
“Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing (…), the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.”
GDPR, Article 32, paragraph 1
Article 32 does not define a single technical standard. It imposes proportional reasoning: the more sensitive the data, the more robust the measures must be. For standard accounting or commercial data, encryption at rest on a properly administered French server may suffice. For health or criminal data, much more is required.
When NF Z42 is truly required, and when it is not necessary
NF Z42-013 and Z42-026 are standards for electronic archiving. They outline the conditions for a digital document to be admissible as long-term evidence in critical contexts: labor disputes regarding payroll slips older than five years, tax challenges concerning documents kept beyond the legal period, or medical records subject to a ten-year retention period.
For these uses, Coffreo and Digiposte are the French players covering the complete chain. For more daily uses—collecting client documents, private client portals, validation, and GDPR-compliant storage—NF Z42 is not required by law. Confusing it with GDPR compliance is a frequent error.
In practical terms: if you are a law firm wanting a client portal to collect case files, NF Z42 is not your obligation. GDPR, the RIN, and Article 66-5 are. If you are an HR department managing payroll for five thousand employees, you are in the segment where NF Z42 makes sense. Both worlds coexist.
HDS: the specific case of health data
Health data hosting is governed by a specific framework, supervised by the Agence du Numérique en Santé. The HDS framework imposes reinforced technical and organizational requirements regarding physical security, availability, traceability, and confidentiality. HDS certification is granted to hosts, not to software publishers—this is a fundamental distinction.
Specifically: if you process health data — patient records, prescriptions, therapeutic follow-ups — you must host them with an HDS-certified hosting provider. OVHcloud Healthcare and Outscale are the two main French players covering this scope. The software you use on top of it does not need specific HDS certification: what matters is the hosting environment.
Comparison of the three main paths in France 2026
First path: a French SaaS certified NF Z42 — Coffreo, Digiposte. Advantages: strong compliance for evidential archiving, French jurisdiction, solid HR professional ecosystem. Limitations: high cost, integration complexity, poorly suited for small firms, irrelevant for a classic client portal.
Second path: an American SaaS — TaxDome, SmartVault, Box, Dropbox. Advantages: rich integrations, mature ecosystems, rapid adoption. Limitations: American jurisdiction, exposure to the CLOUD Act, operational dependency, increasing recurring costs, strong vendor lock-in.
Third path: a sovereign WordPress plugin hosted with a French provider — Client Vault, or a custom development. Advantages: full ownership, chosen hosting, independence from a vendor, GDPR by design compliance, controllable total cost. Limitations: requires WordPress expertise, not adapted to NF Z42 or HDS uses without specific integration with an HDS-certified provider.
The selection grid by use case
You manage an HR department with several hundred pay slips per month. The NF Z42 SaaS approach is consistent. Coffreo or Digiposte. Investment justified by the volume of documents and the criticality of long-term storage.
You are a paramedical professional and receive patient records. The WordPress approach on HDS hosting — OVHcloud Healthcare or Outscale — is consistent. A WordPress vault plugin on top for structured collection. No need for NF Z42 for this use case.
You are a law firm, accounting firm, broker, or architect. The sovereign WordPress approach on standard French hosting is consistent. Coffreo is not necessary. TaxDome or Clio exposes you to the CLOUD Act without any additional benefit.
You are a freelancer, photographer, coach, or web agency. The sovereign WordPress approach is the most suitable. Bonsai, HoneyBook, or Plutio provide a more polished experience but outsource your client data.
How Client Vault positions itself in this grid
Client Vault is on the third path: WordPress plugin, installation on the host of your choice, full ownership of data. It covers client portal and document collection uses for profiles that do not require NF Z42 or HDS. For paramedical professionals, Client Vault can be installed on HDS hosting, making the setup compliant with health requirements without needing specific editorial certification.
For WordPress agencies that equip professionals: this is precisely the grid you present to your clients. For the average law firm, Client Vault on OVH or Infomaniak is sufficient. For the physical therapist who wants to host patient records, you should guide them toward OVHcloud Healthcare. For the HR department that wants to archive ten thousand payslips per month, you should guide them toward Coffreo or Digiposte. The agency’s role is precisely this technical intermediation.

Honest limitations
Client Vault is not NF Z42 certified and will not be in the near future. This certification is aimed at a different market and imposes architectural constraints that are not aligned with the client portal segment. For long-term evidentiary archiving use cases and high volumes, the path remains Coffreo, Digiposte, or a custom development.
Client Vault also requires WordPress expertise. If you are on your own, without a trusted WP agency, and site maintenance feels like a burden, the sovereign path becomes an effort. Recognizing this limit is how you maintain credibility.
Let’s get to know each other
If you are hesitating between the three paths for your firm or on behalf of a client, let’s discuss it via video call. Twenty to thirty minutes to understand your use case, your document volume, your regulatory constraints, and to guide you toward the path that suits you. If it is not Client Vault, I will say so as well.
Frequently asked questions
What is a GDPR-compliant digital vault?
A GDPR-compliant digital vault is a system that covers the requirements of articles 5, 28, and 32: encryption at rest, access control, traceability, subcontracting frameworks, and retention period limitations. The term covers several realities depending on professional usage.
Is NF Z42 certification mandatory?
No. NF Z42 governs long-term evidentiary archiving. It is necessary for uses requiring high legal value archiving (large-volume HR, hospital patient records). For collecting client documents in a private practice, GDPR compliance is a sufficient framework.
Can a WordPress plugin serve as a vault?
Yes, for client portal and document collection purposes, provided the plugin covers GDPR requirements (encryption, traceability, segmentation). No, for NF Z42 uses or very high legal value evidentiary archiving, which require a specific architecture.
What is the difference between a vault and a DMS?
A DMS stores and shares documents. A vault goes further: strict segmentation by user, verifiable traceability, GDPR compliance by design, and controlled retention. Box or Dropbox are DMS. Coffreo, Digiposte, or Client Vault are vaults.
Are Coffreo and Digiposte suitable for a professional practice?
For standard client portal use, they are oversized and costly. For large-volume HR archiving or long-term storage of payslips, they are perfectly suitable. The choice depends on the use case, not the industry.
Which hosting should be chosen for a sovereign digital vault?
For a standard professional practice, a qualified French host — OVH, Scaleway, Infomaniak, o2switch — is suitable. For health data, a host with HDS certification — OVHcloud Healthcare or Outscale. For very high volumes or strict sector-specific regulatory requirements, assess on a case-by-case basis.
Is encryption at rest mandatory?
GDPR Article 32 explicitly mentions it among appropriate technical measures. For sensitive data, the lack of encryption at rest will be difficult to justify during a CNIL audit.
What is the retention period per document type?
It varies by sector. Accounting records: ten years (R. 123-200 of the French Commercial Code). Training attendance records: five years (L. 6362-7-2 of the French Labor Code). Payslips: fifty years for the employer. Health data: depends on the profession, generally twenty years for hospital patient records (DPI).
{“@context”:”https://schema.org”,”@type”:”Article”,”headline”:”Coffre-fort numérique conforme RGPD France : le guide WordPress”,”author”:{“@type”:”Person”,”name”:”Dragan Stamenkovic”},”datePublished”:”2026-05-10″,”dateModified”:”2026-05-10″,”publisher”:{“@type”:”Organization”,”name”:”Client Vault”},”mainEntityOfPage”:”https://clientvault.pro/blog/coffre-fort-numerique-rgpd-france”}{“@context”:”https://schema.org”,”@type”:”FAQPage”,”mainEntity”:[ {“@type”:”Question”,”name”:”Qu’est-ce qu’un coffre-fort numérique conforme RGPD ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Un dispositif qui couvre les articles 5, 28, 32 du RGPD : chiffrement, contrôle d’accès, traçabilité, encadrement sous-traitance, limitation des durées.”}}, {“@type”:”Question”,”name”:”La certification NF Z42 est-elle obligatoire ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Non. Elle encadre l’archivage probant à long terme. Pour la collecte de pièces clients standard, le RGPD suffit.”}}, {“@type”:”Question”,”name”:”Un plugin WordPress peut-il servir de coffre-fort ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Oui pour les usages portail client et collecte de pièces. Non pour les usages NF Z42 ou archivage probant à très forte valeur juridique.”}}, {“@type”:”Question”,”name”:”Quelle différence entre coffre-fort et GED ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Une GED stocke et partage. Un coffre-fort ajoute cloisonnement strict, traçabilité opposable, conformité RGPD by design.”}}, {“@type”:”Question”,”name”:”Coffreo et Digiposte sont-ils adaptés à un cabinet ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Surdimensionnés pour un portail client classique. Adaptés pour archivage RH grands volumes ou bulletins de paie longs.”}}, {“@type”:”Question”,”name”:”Quel hébergement choisir pour un coffre-fort souverain ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”OVH, Scaleway, Infomaniak ou o2switch pour un cabinet libéral. OVHcloud Healthcare ou Outscale pour les données de santé.”}}, {“@type”:”Question”,”name”:”Le chiffrement au repos est-il obligatoire ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Mentionné par l’article 32 RGPD. Difficile à justifier son absence en cas de contrôle CNIL pour des données sensibles.”}}, {“@type”:”Question”,”name”:”Quelle durée de conservation par type de document ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Pièces comptables 10 ans, émargements formation 5 ans, bulletins de paie 50 ans côté employeur, DPI santé généralement 20 ans.”}} ]}



