
Storing pay slips online does not have the same requirements as archiving vacation photos. The digital safe Arkevia, published by Cegedim, specifically targets the long-term preservation of sensitive HR documents. The question arises: what technical and regulatory criteria truly distinguish this type of service from a simple cloud storage space?
Digital safe and cloud storage: regulatory distinguishing criteria
The confusion between a standard storage space and a digital safe persists because the user interface often looks similar. The differences lie beneath, in the technical and legal guarantees.
| Criterion | Standard cloud storage | Digital safe (type Arkevia) |
|---|---|---|
| Access to documents | Host and user | User only (and authorized persons) |
| Content encryption | Variable, often only in transit | Encryption making data incomprehensible to unauthorized third parties |
| Archiving standard | No specific obligation | NF Z42-020 (integrity and traceability) |
| Guaranteed retention period | Linked to the subscription | Up to 50 years or 75 years of the user |
| Hosting | Frequent international servers | Servers located in France |
| Applicable CNIL framework | General GDPR | CNIL recommendation of October 2023 on digital safes |
The recommendation published by the CNIL in October 2023 specifies that the term “digital safe” imposes specific obligations. The service must ensure that documents remain inaccessible and incomprehensible to any unauthorized third party, including the publisher itself. The information provided to the user must be explicit about the exact type of space made available and its potential limitations.
To learn everything about Arkevia and its safe, it is essential to understand that this regulatory distinction is not cosmetic. It conditions the evidential value of archived documents in the event of a labor dispute or audit.

Standard NF Z42-020 and digital sealing: what Arkevia really protects
The NF Z42-020 standard regulates the components of a digital safe in the strict sense. It defines the requirements for integrity, traceability, and long-term retrieval of electronic documents.
Arkevia relies on a mechanism of digital sealing that prevents any modification after deposit. Each deposited document receives a timestamp and a cryptographic fingerprint. If the file is altered, even by a single byte, the fingerprint no longer matches and the anomaly is detectable.
This system fundamentally differs from simple file versioning. In a standard cloud space, a document can be overwritten, renamed, or deleted by the user or administrator. In a safe compliant with NF Z42-020, the sealed document cannot be modified or deleted before the legal deadline.
Limitations of sealing in practice
Sealing guarantees the integrity of the deposited file, not the quality of the source document. If the employer deposits a pay slip containing an error, the safe faithfully retains that error. Correction requires a new deposit, with the old one remaining archived with its original timestamp.
The reversibility of data is another notable technical point. If the company changes providers or ceases operations, the employee must be able to retrieve all their documents. Arkevia maintains access to files even after the employee leaves the company, for the entire legal retention period.
Long-term preservation of pay slips: employer obligations and employee rights
The automation of the flow between the payroll software and the digital safe eliminates manual intervention. Pay slips arrive directly in the employee’s personal space each month, without any action on their part. This process reduces the risks of loss associated with paper distribution or unsecured email sending.
Three elements condition the reliability of this preservation:
- The legal retention period of 50 years (or until the employee turns 75) applies regardless of the contractual link between the employer and the safe provider
- The employee retains personal access via unique identifiers, even after leaving the company
- Personal documents (identity papers, contracts, certificates) can also be stored in a dedicated space, separate from the employer’s space
This last point is often underestimated. The free personal space integrated into Arkevia allows the employee to centralize their own administrative documents alongside their pay slips. The separation between the two spaces ensures that the employer has no access to the employee’s personal files.

CNIL Recommendation 2023: concrete impact on HR digital safes
The CNIL recommendation of October 2023 on digital safe services for individuals introduces requirements that the existing content on Arkevia does not detail.
The provider must clearly inform the user of the exact conditions of the service. This includes the encryption methods used, the individuals who may technically access the data, and the scenarios for retrieval in case of service closure.
This transparency is not optional. A service that presents itself as a “digital safe” without complying with these information conditions is exposed to reclassification. In practice, this means that the very designation legally binds the provider to a level of protection superior to simple storage.
Segregation and server-side encryption
The recommendation emphasizes strong segregation between users. In an HR context where thousands of employees share the same technical infrastructure, this segregation prevents a breach on one account from compromising another employee’s documents.
Encryption must render the contents incomprehensible even to the provider’s technical staff. This level of requirement exceeds what most consumer-grade online storage solutions offer, where the host generally retains the technical ability to read the files.
The protection of sensitive HR documents thus relies less on the user interface than on the underlying technical architecture. A compliant digital safe protects files even from its own publisher, which remains the most reliable criterion for assessing the robustness of a solution like Arkevia.