TransferNow

Security

GDPR: 5 checks before sending personal data

Hosting, legal basis, retention period, traceability, minimization: what the GDPR actually means for your file transfers.

The TransferNow teamPublished on May 15, 20262 min read

A scanned ID, an HR file, a customer list: as soon as a file contains data that can identify a person, sending it is personal data processing under the GDPR — and the tool you use becomes a link in that chain. Here are the five checks to run before you click “send”.

Does this concern you? (spoiler: yes)

The GDPR doesn’t apply only to big platforms: the accounting firm receiving payslips, the photographer delivering portraits, the small business sending an HR file — they all process personal data. The responsibility can’t be delegated to the tool, but the choice of tool commits you.

1. Where the data is hosted

The first question to ask your transfer service: where are the files stored? Hosting within the European Economic Area radically simplifies compliance; a transfer outside the EEA requires additional safeguards (adequacy decision, standard contractual clauses). TransferNow hosts in Europe, with a choice of region depending on the plan.

2. The contractual framework (DPA)

If you act on behalf of a legal entity, the transfer service is your processor under Article 28: a data processing agreement (DPA) must govern the relationship. Check that it exists and is accessible — it’s a document your DPO will ask for. Ours is public, linked from our privacy policy.

3. The retention period

The GDPR requires that data not be kept longer than necessary. Translated into file transfer terms: an expiring link is a compliance asset. Favor a duration that matches the actual need — 7 days is often enough — and a service that lets you deactivate the link as soon as the handover is done.

4. Traceability

If a question comes up — from a client, from an authority — you must be able to say who had access to the data. A named notification for every download provides that trail with no extra procedure: who retrieved the file, and when.

5. Minimization

The simplest and most forgotten principle: send only what’s necessary. The complete “just in case” folder multiplies exposure. Before every sensitive transfer, one question: does this recipient need all of these files?

These five points are no substitute for legal advice — but they cover what a DPO will check first. For the technical side, our security checklist complements this one.

Frequently asked questions

Can I send personal data with a free consumer service?

The criterion isn’t free vs. paid but the guarantees: EEA hosting, an available DPA, controlled retention, traceability. Check those four points — many consumer services cover none of them.

Does the recipient of a transfer have to be in Europe too?

Not necessarily, but if the data leaves the EEA, additional safeguards apply (adequacy, standard clauses). The service’s European hosting covers storage; the recipient falls under your own case-by-case assessment.

Where can I find TransferNow’s DPA?

It’s linked from our privacy policy (transfernow.net/en/privacy-gdpr) as a PDF, in French and in English.

What is a DPA and when do you need one?

The DPA (data processing agreement) is the contract governing the relationship with a processor under Article 28 of the GDPR. As soon as you send personal data on behalf of a legal entity, your transfer service is a processor: the DPA must exist and be accessible.

Does an expiring link help with GDPR compliance?

Yes, directly: the GDPR requires that data not be kept longer than necessary, and a time-limited link embodies that principle with no extra procedure. Complement it with manual deactivation as soon as the handover is confirmed.

5 GB per transfer for free, no sign-up

Transfer your files with complete confidence on TransferNow