GDPR and file transfers: what to check
By the WispFile team · Updated 24 September 2026
GDPR does not ban any particular tool; it asks you to protect personal data appropriately and to know who processes it, where, and for how long. For file transfers, the useful questions are where the file is stored, who could read it, and how long anything is kept. This page is practical guidance, not legal advice.
Key facts
- Data minimisation: send only the personal data the recipient needs.
- Storage limitation: a file that is never stored cannot be kept too long.
- Encryption is named in GDPR as an appropriate security measure.
- Metadata such as file names can itself be personal data.
Questions to ask any provider
| Question | Why it matters | WispFile’s answer |
|---|---|---|
| Is the file stored? Where, for how long? | Storage limitation, transfers abroad | Never stored; it goes browser to browser |
| Can the provider read it? | Security, access | No: end-to-end encrypted, key only in the link |
| What metadata is kept? | Names can be personal data | File names, sizes, message, while the link exists |
| Are IP addresses logged? | IPs are personal data | Not by default |
| Who are the sub-processors? | Accountability | Listed in the Privacy Policy |
Good practice when sending personal data
- Rename files so the name does not reveal whose data it is.
- Use a password and a one-download link for special-category data.
- Record what you sent, to whom and why.
- Delete your own local copies when they are no longer needed.
See the Privacy Policy for what WispFile processes and on what basis, and ask us if your organisation needs more.
Frequently asked questions
Is WispFile GDPR compliant?
Compliance depends on how an organisation uses any tool. What we can say is how WispFile is built: files are never stored, contents are end-to-end encrypted, IP addresses are not logged by default, and the Privacy Policy lists what is processed.
Does a direct transfer count as a transfer outside the EU?
The file goes between the two devices, so it travels wherever the sender and receiver are. If the relay is used (paid plans), encrypted data passes through our relay server without being stored.
Is a file name personal data?
It can be, for example “Jane_Doe_passport.pdf”. Rename files before sending if the name identifies someone.
Related guides
- How to securely share confidential documents with clients — A checklist for contracts, IDs and records.
- Secure file transfer without cloud storage — Confidential documents, and why the safest copy is the one never made.
- End-to-end encrypted file transfer — Who holds the key decides who can read the file.
Send it directly now
Open WispFile, add your files and share the link. No account, nothing uploaded, nothing stored. Free.
Send files with WispFile