GDPR file transfer: share personal data with an encrypted service hosted in France

PrivCloud encrypts your files in the browser, hosts them in France and sets out its role as a processor in a DPA. Whether your processing complies also depends on the choices you make.

Hosted in France

Article 28 DPA

Deleted on expiry

What the service guarantees

End-to-end encryption by default

Files sent with an account are encrypted with AES-256-GCM in the browser. By default, neither PrivCloud nor its hosting providers receive the key needed to read them.

Hosted in France

The server and object storage are located in France. PrivCloud does not transfer any data outside the European Union.

An Article 28 DPA

The data processing agreement covers security measures, sub-processors, breach notification and data deletion.

Limited retention

Every share expires on the date you choose, within your plan's limit, and its files are then deleted automatically.

Who does what: the service and the data controller

The GDPR splits duties between the controller, who decides to send the data, and the processor, who provides the service. Here is how they divide for a file transfer.

RequirementArticleWhat PrivCloud providesYour part
Security of processingArt. 32End-to-end encryption, TLS, optional two-factor authenticationSecure your devices and share the link over a suitable channel
Using a processorArt. 28Published DPA, hosting providers based in FranceRecord this processor in your record of processing activities
Data minimisation and retentionArt. 5An expiry date on every share and automatic deletionSend only the data needed and pick a short expiry
Transfers outside the EUArt. 44Hosted in France, no transfer outside the EU by PrivCloudCheck what recipients do with the files they download
Personal data breachesArt. 33Notice to the customer within 48 hours, as set out in the DPANotify your supervisory authority within 72 hours where required

For a detailed look at these duties and the French regulator's guidance, read our guide to GDPR and file transfers.

No tool makes processing GDPR-compliant on its own

No file transfer service can guarantee GDPR compliance by itself. It depends on what you send, to whom, why and for how long. PrivCloud acts as a processor: it provides technical and contractual safeguards, while you remain the controller.

Before sending files that contain personal data, a few checks usually go a long way.

  • Identify the purpose of the transfer and its lawful basis.
  • Strip the file down to the data the recipient actually needs.
  • Pick a short expiry date that matches the need.
  • Confirm who the recipient is and that they are entitled to the data.
  • Send the link, or its key, through a channel you trust.
  • Keep your records up to date and inform the people concerned.

Sending sensitive files: HR, legal, health

Payslips, job applications, ID documents, contracts or medical reports put the people concerned directly at risk if they leak. End-to-end encryption cuts that risk sharply, since the content stays unreadable to the provider and its hosts.

Health data is also subject to sector rules. PrivCloud is not certified under the French HDS health data hosting scheme, so check your obligations before using it for that kind of data, even briefly. For other cases, see our advice on sending sensitive files and sharing HR documents.

Large file transfers and the GDPR

Paid plans handle up to 250 GB per transfer, with the same encryption. File size does not change your obligations, but a large export often holds far more personal data than a single document, which makes minimisation and a short expiry even more important.

How the encryption works is explained on our secure file transfer page.

Data kept by the service. Even when content is end-to-end encrypted, the server keeps file names, sizes and dates, along with account and connection data. These are described in the privacy policy and the DPA.

Frequently asked questions

Share sensitive files with an encrypted service

Create a free account: your transfers are end-to-end encrypted and hosted in France from the very first file.

Further reading