Home

/

Blog

/

GDPR and file transfer

GDPR and File Transfer: What the CNIL Really Requires in 2026

RGPD / GDPR
CNIL
Article 32
Encrypted files
Secure sharing
16 min read

By Simon Thémiot, cybersecurity consultant. Published April 27, 2026. This article does not constitute legal advice. When in doubt, consult your DPO or a specialist lawyer.

Key takeaways

  • Sending an email with a client attachment is already GDPR processing. File sharing almost always falls under the regulation.
  • Article 32 requires "appropriate technical measures": the CNIL explicitly lists encryption among them.
  • Any provider hosting your files is a data processor. A written contract (DPA) is mandatory.
  • Outside the EU = regulated transfers (standard contractual clauses or adequacy decision). The topic remains sensitive since Schrems II.
  • End-to-end encryption does not exempt you from GDPR, but it can reduce risk and affect breach analysis when the key is not compromised.
  • Sending sensitive files (contracts, payslips, medical records) without encryption exposes your data and your clients' data to real risks: data leaks, hackers, legal compulsion. Password protection is a first step; end-to-end encryption is best practice for secure file sharing.
  • Common cloud storage services (Google Drive, Dropbox) encrypt your files, but hold the decryption keys themselves. For truly secure encrypted file sharing, the encryption key must stay only with you and your recipient.

1. The applicable legal framework for file sharing

GDPR applies as soon as personal data is processed, meaning any information relating to an identified or identifiable natural person. The threshold is very low: a name in a Word document, an email address in an Excel file, an ID photo in a PDF. All fall under the regulation.

When you send a file via WeTransfer or an equivalent service, you perform processing (within the meaning of Article 4): transmission, temporary storage, access. You are the data controller, and the service used becomes a processor. This chain of responsibility is the basis of any GDPR analysis of file sharing.

In addition to GDPR, certain sectors have extra obligations: HDS hosting for health data, ACPR rules for the banking sector, professional secrecy for lawyers and notaries. These regimes do not replace GDPR - they add to it.

2. GDPR Article 32 and the notion of appropriate measure

Article 32 of the GDPR requires both the data controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The text explicitly mentions:

  • The pseudonymisation and encryption of personal data.
  • The ability to ensure ongoing confidentiality, integrity, availability and resilience of systems.
  • The ability to restore availability after an incident.
  • A process for regularly testing the measures.

The CNIL has published several guides detailing what it expects concretely. The "Guide to the security of personal data" (2024 edition) recommends for file sharing: encryption in transit (TLS 1.2+), encryption at rest (AES-128 or higher), strong authentication, and limited retention. For sensitive data, end-to-end encryption is mentioned as best practice.

The key word is "appropriate". Sharing a guest list for a public meeting does not carry the same requirements as transferring payslips. Proportionality is part of the analysis. In case of an audit, you must be able to justify your choices.

How to encrypt and share files in practice?

Encrypting files before sharing does not always require advanced technical skills. Several methods exist depending on the required level of protection and user profiles. A sharing service can provide an E2E option that encrypts content client-side before upload. The recipient then decrypts it in the browser through the received link, with no installation required.

For large files or complete folders, tools like 7-Zip (AES-256 encryption with password), Cryptomator (folder encryption on cloud storage) or VeraCrypt (encrypted volumes) allow encryption before storage or sharing. The encryption key - in practice the password - must be transmitted to the recipient via a separate channel (different e-mail, SMS, phone call). Never send the password in the same e-mail as the link to the encrypted files.

  • Online E2E service (symmetric encryption) (e.g. PrivCloud): AES-256-GCM client-side encryption. A 256-bit symmetric key is generated in the sender's browser, used to encrypt files, then shared with the recipient via the URL fragment (#key=...) - this part of the URL is never sent to servers by HTTP design. The same key is used for both encryption and decryption (that is the definition of symmetric encryption). The server only receives an unreadable blob.
  • 7-Zip + password: use the 7z format with AES-256 and a strong password; avoid legacy ZipCrypto. Communicate the password to the recipient through a separate channel.
  • Cryptomator: AES symmetric encryption of files and filenames in folders stored in the cloud (Dropbox, OneDrive, etc.). The master key stays local. Allows protecting files on a cloud storage service without native E2E encryption.
  • PGP/GPG: hybrid encryption - asymmetric for key exchange (RSA or ECDH), symmetric for content (AES). The fundamental difference from E2E services with a key in the URL: the sender encrypts the session key with the recipient's public key, without ever having to share a secret via an external link. Only the recipient's private key can decrypt. Recommended for advanced users and very sensitive exchanges (lawyers, doctors, CISOs), but requires public key management (keyring, WKD, etc.).

Whatever tool is chosen for file sharing, the important thing is to define a clear internal policy: which files must be encrypted, how to transmit keys or passwords to recipients, and what retention period to apply to sharing links. Without a written policy, users will make inconsistent choices and risks will remain high.

3. The processor status and the DPA obligation

Any provider that processes personal data on your behalf is a data processor under Article 28. This includes file sharing services, email providers, and cloud hosts. With each of them, you must sign a Data Processing Agreement (DPA) specifying:

  • The subject matter, duration, nature and purpose of the processing.
  • The types of data and categories of data subjects.
  • The processor's obligations (confidentiality, security, sub-processing, assistance, deletion at end of contract).
  • The right of audit by the data controller.

In practice, major online services publish a standard DPA. WeTransfer, Dropbox, Google and the like offer one, signable online. For a company, reading and archiving this document is the bare minimum. If the DPA is not suitable, negotiate or change provider. Many CISOs discover during a CNIL audit that they have never signed the DPA for their main tool.

4. Cross-border transfers since Schrems II

The Schrems II ruling (July 2020) invalidated the Privacy Shield that governed EU-US transfers. The Data Privacy Framework of July 2023 partially restored a framework, but it is still subject to legal challenges. The prudent position is to avoid cross-border transfers when possible, and to document them strictly when unavoidable.

In practice, storage in a non-EEA region or access from a third country may constitute a transfer. Depending on the country and entity, verify an adequacy decision or implement appropriate safeguards, then assess any necessary supplementary measures.

A service hosted in France or the EEA with a documented subprocessor chain simplifies the assessment. SwissTransfer is hosted in Switzerland, a country covered by an adequacy decision. In every case, review the DPA, remote access, subprocessors, and actual processing locations.

5. The activity register and documentation

Article 30 requires any organisation of more than 250 people, and any smaller organisation processing sensitive data or doing so on a non-occasional basis, to maintain a record of processing activities. For file sharing, this record must include:

  • The purpose (transmission of commercial, HR, or legal documents, etc.).
  • The categories of data subjects and data types.
  • The recipients or categories of recipients.
  • Any cross-border transfers and associated safeguards.
  • The planned retention period.
  • A general description of security measures.

The CNIL provides a free template. The classic mistake is to fill it out once and forget it. The register must be kept up to date. If you switch file sharing tools during the year, you must trace the change.

6. Breach notification within 72 hours

In case of a data breach (a leaked WeTransfer link, a file left publicly accessible, a compromised account), Article 33 requires notification to the CNIL within 72 hours, unless the breach is unlikely to result in a risk to individuals. This is where end-to-end encryption becomes strategic.

If exposed files were protected by strong encryption and the key was not compromised, that measure weighs heavily in the risk assessment. Notification to the authority is required only when the breach is likely to result in risk; individual communication falls under Article 34 for high risk, including an exception where data was rendered unintelligible to unauthorised persons.

Encryption therefore does not automatically make a breach a legal non-event: document scope, algorithms, key management, exposed metadata, and other consequences. It can nevertheless substantially reduce content-related risk.

A link shared without access control, a compromised account, or misconfigured storage can expose SMEs and large organisations alike. For HR, legal, or financial information, combine a risk-appropriate tool, short expiry, controlled recipients, strong authentication, and, where the threat model warrants it, E2E encryption.

7. Compliance checklist for SMEs

Here is a checklist for structuring a quick SME audit. Ticking these boxes does not prove compliance by itself, but provides a solid baseline for file sharing.

  • The file sharing service is identified, documented and entered in the activity register.
  • The provider's DPA (data processing agreement) is read, signed and archived. The provider is confirmed as a processor under Article 28 GDPR.
  • File hosting is in the EU, or a documented transfer framework (standard contractual clauses, adequacy decision) exists for non-EU servers.
  • Sharing links have a configured expiration date. No permanent sharing link exists for sensitive files or personal data.
  • Sensitive files (HR documents, contracts, medical data, banking information) are encrypted before sending, and protected by password or end-to-end encryption.
  • Passwords for file sharing links are transmitted to recipients via a separate channel - never in the same e-mail as the link.
  • Users have received clear written guidance: which tools to use, for which types of files and data, and how to access shared files securely.
  • Access to shared folders and files is limited to identified recipients. Generic links accessible to anyone with the link are reserved for non-sensitive files.
  • Strong authentication (two-factor) is enabled on all accounts with access to file sharing and storage tools.
  • An inventory of shared file types is up to date. Sensitive data (health data, personal information, confidential files) is identified and their sharing is subject to strict, documented rules.
  • A data breach notification procedure exists, is documented and has been tested (simulating a sensitive file leak scenario).
  • An annual review of sharing tools, access policies and associated risks is scheduled.

None of these points requires a significant budget. Most are organisational decisions. The budget then goes towards choosing the right tool, but without this documentary foundation, even the best tool in the world will not protect you during an audit.

8. Encrypted file sharing: concrete best practices

Beyond the regulatory framework, secure file sharing in a business relies on simple and systematic practices. Here are the features and methods to prioritise for protecting your files and users' data.

Set an expiration date on all sharing links

A file shared without an expiration date remains accessible indefinitely. If the link is forwarded by e-mail and that e-mail is copied or shared further, anyone with the link can download the files. Setting an expiration date of 7 to 30 days on file sharing links drastically reduces this risk window. It is one of the most important features to require from a secure file sharing service, and one of the simplest measures to implement.

Protect sensitive files with a password

For sensitive files, a link password adds useful access control. Send it through a channel separate from the link. On PrivCloud, that password is an Argon2-derived server-side access gate; it does not replace the E2E encryption key and should not be presented as one.

Verify that your files are encrypted client-side (zero-knowledge)

There is an important difference between server-side encryption and client-side encryption with a key absent from the server. A URL fragment can carry that key without sending it in the HTTP request, as with PrivCloud E2E links. That signal alone is insufficient: review client code, network requests, the build chain, security headers, and the published threat model.

Limit access to shared folders and files

Secure file sharing also involves rigorous access management. In business, using named user accounts rather than generic links makes it easier to audit access to sensitive files and detect anomalies. Disabling the ability for recipients to re-share the link, and tracking downloads (who accessed the file, when, from which device) are important features for truly critical data. These measures make it easy to document data access and respond quickly in the event of a supervisory authority audit.

9. FAQ - Secure file sharing and encryption

What is encrypted file sharing?

Encrypted file sharing makes content unreadable without the key. With correctly designed E2E, the service does not receive the content key: the user encrypts before upload and the recipient decrypts client-side. This protects stored content but does not remove risks involving endpoints, recipients, metadata, or delivered client code.

How to send files securely without technical skills?

One simple approach is a service with integrated E2E encryption: the browser encrypts before upload and decrypts for the recipient. Depending on risk, add a separately transmitted access password, short expiry, and download limits. Always verify the recipient's identity before sharing the key.

Are Dropbox and Google Drive secure for sharing business files?

Dropbox and Google Drive both offer a DPA and are partially hosted in Europe. They can be used in a GDPR context provided you sign the DPA, verify sub-processors and document any cross-border transfers. However, these cloud storage services do not offer native end-to-end encryption: they hold the decryption keys for your files. For very sensitive files (health data, confidential information, personal data), it is recommended to add a client-side encryption layer (Cryptomator) or choose a secure file sharing service with built-in E2E encryption and France hosting.

Do you need an account to receive encrypted files?

This depends on the service used. On PrivCloud, the recipient does not need to create an account to access shared files. They simply need to open the link received by e-mail in their browser: files are decrypted automatically client-side. This ease of use is an important advantage for businesses that share files with partners, clients or external providers who do not have access to the same sharing tools or services.

What are the risks of unsecured file sharing in a business?

Poorly controlled sharing can cause data leaks, intellectual-property exposure, loss of trust, and, depending on the infringement, corrective action or penalties. GDPR's general upper tier can reach EUR 20 million or 4% of worldwide annual turnover. E2E, passwords, expiry, and strong authentication are possible controls to select according to risk.

Going further

PrivCloud is a temporary-sharing service hosted in France, with optional client-side E2E encryption, open source code, and an available DPA. It provides useful controls for a GDPR programme without making processing or an organisation compliant by itself. Any HDS offering requires a certified host and suitable contractual scope.

Try PrivCloud

Last updated: July 14, 2026. Regulations change regularly. Verify official sources before any strategic decision. This article is for informational purposes only and does not replace personalised legal advice.