Skip to content
HexaTransfer
Back to blog
Comparisons & Alternatives

Data Residency Comparison for File Transfer Services

Compare where major file transfer services store your data, with details on server locations, data sovereignty, and GDPR compliance implications.

Data residency varies wildly across file transfer services. WeTransfer stores files in Ireland and the US, Smash hosts in France, SwissTransfer keeps everything in Switzerland, and Dropbox Transfer splits across US and EU regions. For GDPR Article 44 compliance (transfers outside the EEA), choose EU-only services when handling personal data. HexaTransfer hosts exclusively on French servers, meaning your files never cross the Atlantic. This matters for healthcare, legal, and financial teams subject to strict sovereignty rules under the Schrems II ruling.

Why Data Residency Actually Matters Post-Schrems II

The July 2020 Schrems II decision invalidated the EU-US Privacy Shield, leaving most transatlantic transfers on shaky legal ground. Standard Contractual Clauses still work, but only when paired with supplementary measures proving US surveillance laws (FISA 702, Executive Order 12333) don't compromise the data. A CNIL ruling against Google Analytics in February 2022 made this concrete: EU companies were fined for routing visitor data to US servers, even with SCCs in place.

For file transfers, the implications are direct. Send a client contract through a US-based service and you've potentially triggered a cross-border transfer requiring a Transfer Impact Assessment. Send it through a French or Swiss service, and you've stayed within jurisdictions with adequacy decisions or stronger privacy frameworks.

WeTransfer: Ireland Plus US Edge Servers

WeTransfer's primary storage sits in Ireland (AWS eu-west-1), which keeps the data within the EU's legal boundary. But their CDN edges span the globe, and metadata routing passes through their parent company's infrastructure. Since 2023, WeTransfer has been owned by Italian firm Bending Spoons, which relocated some operations to Milan. Files themselves stay in Ireland for EU users, but logs, authentication tokens, and thumbnails can touch US nodes during transit.

For a French law firm sending depositions, this creates ambiguity. The files are technically EU-resident, but the operational metadata isn't. GDPR Article 30 records of processing activity would need to document this nuance.

Smash: 100% French Hosting With OVH

Smash, the Paris-based competitor, hosts exclusively with OVH in Roubaix and Gravelines, France. No AWS, no Azure, no Google Cloud. This gives them a cleaner story for public-sector clients bound by France's SecNumCloud requirements, which exclude any provider subject to US extraterritorial law like the CLOUD Act. Smash published a detailed infrastructure page in 2024 confirming zero US involvement in their data path.

The tradeoff is performance. Users in Singapore or Sydney experience higher latency than they would with a geographically distributed service. For European users, though, it's a feature, not a bug.

SwissTransfer: Infomaniak's Green Swiss Data Centers

SwissTransfer runs on Infomaniak infrastructure in Geneva and the Swiss Jura. Switzerland isn't part of the EU, but it has an adequacy decision under GDPR, meaning EU-Swiss transfers are treated as intra-EEA. The Swiss Federal Act on Data Protection (FADP), updated in September 2023 to mirror GDPR, adds another layer of legal symmetry.

Infomaniak publishes its carbon footprint and runs entirely on renewable hydroelectric power. For sustainability-focused organizations, that's a bonus beyond the residency story. Files expire after 30 days, with AES-256 at rest.

Dropbox Transfer: US-Default, EU-Optional

Dropbox Transfer, bundled with Dropbox paid plans, defaults to US storage. Enterprise customers can opt into EU residency for an additional fee, routing data to German AWS regions. But the control plane (account metadata, billing, audit logs) remains US-hosted. This is the pattern most hyperscalers follow: regional data planes, centralized control planes.

Under the EU-US Data Privacy Framework (July 2023), Dropbox is certified, which provides a legal basis for transfers. But the DPF is already being challenged in court, and a Schrems III ruling could invalidate it within two years. Long-term contracts should factor this risk in.

HexaTransfer: Single-Jurisdiction Simplicity

HexaTransfer stores everything on French servers with no replication outside the EU. Files are client-side encrypted with AES-256-GCM before upload, meaning even the French infrastructure holds only ciphertext. The key derivation uses PBKDF2 with 600,000 iterations, and the download URL contains the decryption key as a URL fragment (never transmitted to the server).

For GDPR Article 32 purposes (security of processing), this architecture combines data minimization, encryption, and single-jurisdiction hosting in one package. A Transfer Impact Assessment becomes trivial: there is no international transfer.

Comparison Table

| Service | Primary Location | Secondary Locations | GDPR Status | Zero-Knowledge | |---------|-----------------|---------------------|-------------|----------------| | WeTransfer | Ireland (AWS) | US CDN edges | EU-resident | No | | Smash | France (OVH) | None | EU-resident | No | | SwissTransfer | Switzerland | None | Adequacy | Partial | | Dropbox Transfer | US default, EU opt-in | Global | DPF-certified | No | | HexaTransfer | France | None | EU-resident | Yes | | Tresorit | Ireland, Switzerland | US (enterprise opt-out) | EU-resident | Yes |

Sector-Specific Considerations

Healthcare organizations handling patient records under HIPAA face the added complication that the HHS Office for Civil Rights doesn't care about EU residency, but does care about Business Associate Agreements. A French-only service may not sign a BAA if they don't operate in the US market. For European healthcare under the EHDS (European Health Data Space regulation, effective 2026), the calculus flips: EU residency becomes a prerequisite.

Legal teams sending .pdf and .docx case files to co-counsel abroad should check local bar rules. The New York State Bar, for example, has opined that storing client files with foreign-hosted services requires informed consent. French avocats under the RGPD lean the opposite way: US hosting is the outlier requiring justification.

Financial services under DORA (Digital Operational Resilience Act, applicable January 2025) must map all ICT third-party providers and their subcontractor chains. A service hosting in one country with one vendor is simpler to document than a multi-region hyperscaler setup spanning five subprocessors.

What to Ask Your Current Provider

Before renewing any file transfer contract, request the data processing agreement and check three things. First, the list of subprocessors and their countries. Second, the data flow diagram showing where content and metadata travel. Third, the encryption posture — specifically whether the provider holds keys that could decrypt your files under subpoena.

If the answers reveal surprises, switching is straightforward for ephemeral file transfer (unlike migrating a cloud storage archive). You don't need to move historical data; you just change the upload endpoint.

Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file