Jan 26, 2026 7 min read· by SendMe Team

GDPR and File Sharing: What You Actually Need to Know

Stripped of the lawyer jargon. The five GDPR principles that matter when you're sending files inside Europe, and how to actually comply.

If you handle files containing information about EU residents — names, emails, addresses, photos, salaries, health data — you're touching personal data under GDPR. The good news: GDPR is mostly common sense. The bad news: 'mostly common sense' is enforced by regulators who can fine you up to 4% of global revenue. Here's what file-sharing teams actually need to do.

Principle 1 — Data minimisation

Don't send personal data you don't need to send. If the recipient needs to validate that John exists, send just 'John' — not John's full HR record including his salary and his manager's evaluation. The fewer fields you transmit, the smaller the breach radius if something goes wrong.

Practical step: before any file goes out, ask 'does the recipient need every column / every row?' If not, redact or filter first.

Principle 2 — Purpose limitation

Data collected for one purpose can't be repurposed without consent. If you collected customer addresses for shipping, you can't share them with a marketing partner without explicit opt-in. This is the principle most often violated by accident — someone sends a customer list to a third party because 'we already have the list anyway'.

Practical step: maintain a one-line note in your transfer's filename or the email body — 'shared for invoice reconciliation only'. It documents your purpose and reminds the receiver they don't have a general licence.

Principle 3 — Storage limitation

Personal data shouldn't live forever in someone's inbox. GDPR requires you to define a retention period and delete after it. Email attachments are catastrophic for this — they live in two inboxes, in some backup tape, and probably in three forwards.

Practical step: use a transport tool with hard expiry. SendMe's 24-hour default puts an enforceable limit on how long the file exists in transit. Use a workspace tool for files you need to keep accessible, with a defined retention policy that periodic audits enforce.

Principle 4 — Integrity and confidentiality

You must protect personal data 'using appropriate technical and organisational measures'. Translation: encryption in transit, encryption at rest, access controls, and reasonable defences against breach. The case law has consistently treated 'we sent it as a plain email attachment' as inappropriate for sensitive data.

Practical step: every file containing personal data goes via an encrypted transport. For special-category data (health, biometrics, sexual orientation, political opinion), add password protection on top.

Principle 5 — Accountability

You must be able to demonstrate compliance — not just achieve it. Regulators will ask for records: what data you process, who you share it with, how long you keep it. 'We don't know' is the wrong answer.

Practical step: log every external file transfer in a simple register (a spreadsheet is fine). Who sent it, to whom, what data, when, what purpose, what expiry. Five columns, ten seconds per row.

Data subject rights — the ones that matter for file sharing

EU residents can request access to data you hold about them, correction, deletion, and a copy in portable format. If you're sharing files containing data subjects, you need to be able to honour these requests. The transport itself is rarely a problem — once a file has expired and been deleted, it's gone. The challenge is the persistent storage: workspaces, archives, backups.

Cross-border transfers

Sending personal data outside the EU is restricted unless the destination has 'adequate' protection. The US currently does (under the Data Privacy Framework), as does India for many purposes. Always check the data-residency of your file-sharing tool's storage. SendMe stores in Asia-South — fine for cross-border transfers under standard contractual clauses, but always check with your DPO.

The bottom line

GDPR compliance for file sharing reduces to: minimise what you send, encrypt it in transit and at rest, give it a hard expiry, and keep a log. Tools that bake those in by default (like a transport with mandatory expiry) make compliance the path of least resistance — which is the only kind of compliance that actually sticks.

securitycompliance
Try it

Send your next file the right way.

No sign-up. 6-digit code. Auto-expiry. Optional password.

Start sending