WispFile

GDPR and file transfers: what to check

By the WispFile team · Updated 24 September 2026

GDPR does not ban any particular tool; it asks you to protect personal data appropriately and to know who processes it, where, and for how long. For file transfers, the useful questions are where the file is stored, who could read it, and how long anything is kept. This page is practical guidance, not legal advice.

Key facts

  • Data minimisation: send only the personal data the recipient needs.
  • Storage limitation: a file that is never stored cannot be kept too long.
  • Encryption is named in GDPR as an appropriate security measure.
  • Metadata such as file names can itself be personal data.

Questions to ask any provider

QuestionWhy it mattersWispFile’s answer
Is the file stored? Where, for how long?Storage limitation, transfers abroadNever stored; it goes browser to browser
Can the provider read it?Security, accessNo: end-to-end encrypted, key only in the link
What metadata is kept?Names can be personal dataFile names, sizes, message, while the link exists
Are IP addresses logged?IPs are personal dataNot by default
Who are the sub-processors?AccountabilityListed in the Privacy Policy

Good practice when sending personal data

  • Rename files so the name does not reveal whose data it is.
  • Use a password and a one-download link for special-category data.
  • Record what you sent, to whom and why.
  • Delete your own local copies when they are no longer needed.

See the Privacy Policy for what WispFile processes and on what basis, and ask us if your organisation needs more.

Frequently asked questions

Is WispFile GDPR compliant?

Compliance depends on how an organisation uses any tool. What we can say is how WispFile is built: files are never stored, contents are end-to-end encrypted, IP addresses are not logged by default, and the Privacy Policy lists what is processed.

Does a direct transfer count as a transfer outside the EU?

The file goes between the two devices, so it travels wherever the sender and receiver are. If the relay is used (paid plans), encrypted data passes through our relay server without being stored.

Is a file name personal data?

It can be, for example “Jane_Doe_passport.pdf”. Rename files before sending if the name identifies someone.

Related guides

Send it directly now

Open WispFile, add your files and share the link. No account, nothing uploaded, nothing stored. Free.

Send files with WispFile