Skip to content
HexaTransfer
Back to blog
GDPR & Compliance

GDPR File Transfer Compliance: The Complete Guide

Complete guide to GDPR-compliant file transfers covering legal bases, data protection requirements, consent management, and practical implementation.

GDPR-compliant file transfers require four things: a documented lawful basis under Article 6, appropriate technical safeguards (encryption at rest and in transit), a data processing agreement with your transfer provider under Article 28, and an auditable trail of who sent what to whom and when. If personal data leaves the EEA, you also need transfer tools from Chapter V — Standard Contractual Clauses or an adequacy decision. Miss any of these and you're exposed to fines of up to 4% of global turnover or EUR 20 million, whichever is higher.

Article 6 lawful basis before you attach the file

Every transfer of personal data needs a lawful basis written down before the file leaves your laptop. For internal HR files, Article 6(1)(b) covers contracts with employees. Client deliverables usually sit under 6(1)(b) as well. Marketing lists move under 6(1)(a) consent or 6(1)(f) legitimate interests after a balancing test. If you send a 500 MB folder of CVs to a recruiter without recording which basis applies, you've already broken Article 5(2) accountability. Keep a one-line justification in your ticketing system or shared drive — auditors ask for it.

Encryption expectations under Article 32

Article 32(1)(a) names encryption as an example of appropriate technical measures. The ICO, CNIL, and Germany's BfDI all interpret "appropriate" as AES-256 for data at rest and TLS 1.3 for data in motion. End-to-end encryption using AES-256-GCM with keys derived via PBKDF2-SHA-256 at 600,000 iterations or Argon2id meets the bar even for special category data under Article 9. Services that terminate TLS and re-encrypt at the application layer — the WeTransfer and Dropbox Transfer model — are compliant but don't qualify for breach notification exemptions under Recital 87 the way true E2EE does.

Article 28 processor obligations

The moment a third-party service touches personal data on your behalf, you need a written contract covering the eight items in Article 28(3): subject matter, duration, nature and purpose, types of personal data, categories of data subjects, controller obligations, sub-processor rules, and deletion or return at the end of processing. Most reputable services — SwissTransfer, Tresorit, Proton Drive — publish a DPA you can countersign in minutes. If a provider refuses or their DPA omits Article 28(3)(h) audit rights, walk away.

Data minimization at the file level

Article 5(1)(c) says you must limit data to what's necessary. That applies inside the .xlsx file, not just at the transfer layer. If the marketing team asks for a list of active customers, don't send the full CRM export with phone numbers, birthdates, and purchase history — filter columns to name and email first. Strip EXIF GPS coordinates from photos before sending. Redact social security numbers in scanned PDFs with proper PDF redaction, not black rectangles on top. The transfer is the last line of defense, not the only one.

Chapter V transfers outside the EEA

Sending a file to a processor in the United States, India, or any country without an adequacy decision triggers Chapter V. Since Schrems II (July 2020) and the EU-U.S. Data Privacy Framework (July 2023), the path for U.S. transfers runs through either DPF-certified recipients or 2021 Standard Contractual Clauses plus a Transfer Impact Assessment. The TIA documents whether U.S. surveillance law (FISA 702, EO 12333) could compel access to your data, and what supplementary measures — typically encryption where the provider can't decrypt — you've added. A client-side encrypted transfer satisfies supplementary measure requirements because the U.S. processor holds only ciphertext.

Breach notification inside 72 hours

Article 33 gives you 72 hours from awareness to notify the supervisory authority of a personal data breach. If an employee sent the wrong .csv to the wrong recipient, that's a breach. Your file transfer tool should log enough to reconstruct the event: sender, recipient, file hash, timestamp, IP, and whether the link was opened before you revoked it. The CNIL's online notification form asks exactly these fields. Services with link-expiry controls and access logs — including HexaTransfer, which expires links after seven days and records download events — make the 72-hour window much easier to hit.

Data subject rights on shared files

Articles 15 through 22 give data subjects rights over their data wherever it sits, including inside a transfer link. If someone submits an Article 17 erasure request and their CV is in a shared folder that went to three recruiters last month, you need to delete the original and document that downstream copies are beyond your control only if you can show you notified the recipients (Article 17(2)). Link-expiring services handle this automatically — once the link dies, the copy at the transfer service is gone. Self-hosted SFTP and shared cloud drives require manual cleanup and a register of who received what.

Records of processing activities

Article 30 requires controllers with 250+ employees — and smaller organizations processing regularly or handling special categories — to maintain a Record of Processing Activities. File transfers belong in that register. For each recurring flow, document the purpose, categories of data subjects and personal data, recipients, international transfers, retention periods, and security measures. A client-side encrypted transfer with seven-day expiry and AES-256-GCM becomes a one-line entry: "Client deliverables via [provider], E2EE, auto-delete at day 7, EEA storage." That's the level of specificity supervisory authorities want.

Practical compliance checklist

Before rolling out any file transfer tool across your organization, verify: (1) the DPA covers Article 28(3) in full; (2) encryption is AES-256 at rest and TLS 1.3 in transit at minimum; (3) data residency is documented and contractually locked; (4) access and download logs are retained for at least six months; (5) link expiry and revocation work as advertised; (6) the provider publishes sub-processor lists and notifies of changes; (7) a DPIA under Article 35 is on file if transfers involve special category data or large-scale profiling.

Run those seven checks once per quarter and keep the output in your compliance register. Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file