Data Processing Agreements for File Sharing Services
Everything about data processing agreements for file sharing including key clauses, GDPR Article 28 requirements, and template recommendations.
A GDPR-valid Data Processing Agreement for a file sharing service must cover the eight mandatory subjects in Article 28(3): subject matter and duration, nature and purpose of processing, types of personal data, categories of data subjects, controller rights and obligations, processor instruction, sub-processor rules, and end-of-contract deletion or return. Missing any of those eight makes the contract non-compliant and exposes both parties to enforcement action. Beyond Article 28, a strong DPA also defines security measures, breach notification timelines, audit rights, and international transfer safeguards under Articles 32, 33, and Chapter V.
When you need a DPA
Any time a third party processes personal data on your behalf, you need a DPA — even if the processing is limited to transient storage of an uploaded .zip for seven days. That includes SwissTransfer, WeTransfer, Dropbox Transfer, Smash, Tresorit, Box, and HexaTransfer. The threshold isn't "sensitive data" — it's "personal data," which includes customer emails in recipient lists. If you use a transfer service for any business file that names a person, the DPA is mandatory under Article 28(3). No DPA means processing without a valid contractual basis, which is unlawful under Article 5(1)(a).
The eight Article 28(3) mandatory subjects
Article 28(3) reads like a checklist. (a) Subject matter and duration: what processing, for how long. (b) Nature and purpose: file transfer and short-term storage for delivery. (c) Types of personal data: names, emails, file contents, metadata. (d) Categories of data subjects: the controller's employees, customers, and counterparties. (e) Obligations and rights of the controller. (f) Processing only on documented instructions. (g) Confidentiality commitments from authorized personnel. (h) Security measures appropriate to the risk, sub-processor rules, assistance with data subject rights, breach notification, DPIA assistance, and deletion at contract end.
Sub-processor clauses and the 30-day notice
Article 28(2) and 28(4) require processors to disclose sub-processors and give controllers the chance to object to changes. Market practice: a public list of current sub-processors (Cloudflare for CDN, OVH for hosting, SendGrid for email), 30 days' advance notice of material changes, and a contractual right for the controller to object on reasonable grounds. If the controller objects, the processor may either find an alternative or allow termination of the affected service without penalty. Watch for DPAs that claim unlimited sub-processor substitution without notice — those are non-compliant.
Audit rights under Article 28(3)(h)
Controllers have the right to audit processors. For small controllers, this usually means accepting the processor's SOC 2 Type 2, ISO 27001, or ISAE 3402 report instead of sending in an auditor. Larger controllers (banks, hospitals, government) retain on-site audit rights. DPAs should specify the form: right to review published attestations, right to request additional information, and — for high-risk processing — right to commission an independent audit at the controller's expense. Refusing all audit rights is non-compliant; restricting them to annual reviews with 30 days' notice is reasonable.
Security measures and Article 32 alignment
Article 32(1) lists four example measures: pseudonymization and encryption (a), confidentiality, integrity, availability, and resilience of systems (b), timely restoration after an incident (c), and regular testing and evaluation (d). A good file-sharing DPA annexes a Security Measures schedule listing specifics: AES-256-GCM at rest, TLS 1.3 in transit, MFA for admin access, ISO 27001 certification, vulnerability management with patching SLAs, and annual penetration testing. Vague language — "industry-standard security" — fails audits because it's not measurable.
Breach notification timelines between processor and controller
Article 33(2) requires processors to notify controllers of a personal data breach "without undue delay." Most DPAs specify 24-48 hours. The processor's job is rapid notification, not the 72-hour clock — that's the controller's job under Article 33(1). A well-drafted DPA specifies: what counts as a breach (loss, unauthorized disclosure, unauthorized access), what the notification contains (nature of breach, categories and approximate numbers of data subjects and records, likely consequences, measures taken), and how it's delivered (named contact, backup channel if email is compromised).
International transfer safeguards in the DPA
If the processor stores or accesses data outside the EEA, Article 44 kicks in. The DPA should incorporate the 2021 Standard Contractual Clauses (Commission Implementing Decision 2021/914), specify the applicable module (Module 2: Controller to Processor), and include a Transfer Impact Assessment by reference. For U.S. sub-processors, add DPF (Data Privacy Framework) certification status or a specific supplementary measures description. UK transfers need the ICO's International Data Transfer Addendum to the 2021 SCCs, effective since March 2022.
Deletion or return at contract end
Article 28(3)(g) requires the processor to delete or return all personal data at the end of the service, unless EU or member state law requires retention. Clarify which: most file transfer services default to deletion with a short grace period (7-30 days). If the controller wants return instead (all files exported), specify the format and timeline. Deletion needs to cover backups — cite the backup rotation cycle (90 days is standard) and document that restored data is re-processed or re-deleted consistent with the erasure request.
Joint controller and multi-party scenarios
File sharing sometimes involves joint controllers under Article 26 — for example, a recruitment platform where both the employer and the platform decide purposes and means. The Article 26 arrangement is different from a DPA and must allocate responsibilities transparently. If you're the platform and you position yourself as a processor but exercise genuine control (training your AI on user content, monetizing metadata), regulators may reclassify you as a joint controller. Get the classification right upfront; the CNIL and ICO have both issued fines for mis-classification.
Practical templates and where to find them
The European Commission publishes Standard Contractual Clauses between controllers and processors (Commission Implementing Decision 2021/915). Most reputable file transfer providers publish a pre-signed DPA based on these clauses — download, counter-sign, done. Tresorit, Proton Business, Box, Microsoft, Google Workspace, and HexaTransfer all do this. For custom negotiations, IAPP and CIPL publish template DPAs. Never draft from scratch unless you have specialist privacy counsel; the edge cases (joint controllers, sub-processor chains, TIA language) have specific expected wording.
Read every clause against the eight-point Article 28(3) checklist. Try it at hexatransfer.com — free, no account, 10 GB max.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file