Sending files and attachments: what the GDPR changes
Quick reply
Unencrypted attachments, transfers outside the EU, double opt-in: what the GDPR changed in the way companies send files and attachments.

With the technological leaps of the past two decades, data protection law had to be improved and completed. That is how the GDPR came to reinforce the data protection directives in force since 1995. Institutions and companies in the European Union have to meet the requirements of this regulation in order to send and receive files and attachments. What is the GDPR? And what are the new rules governing file transfers?
What is the GDPR, and what are its main objectives?
GDPR stands for General Data Protection Regulation. Passed by the European Union on 14 April 2016, it went through a two-year transition period before coming into force on 25 May 2018. That transition allowed each EU member state to bring the new rules into its own national law.
The GDPR is the reference text governing the protection of the personal data of people living in the EU. Each member state has a data protection authority to enforce the law and make sure the principles of the GDPR are respected. In France, that is the CNIL.
The objectives of the GDPR are to strengthen the protection of EU citizens' personal data more than ever, by imposing new security standards on the companies that handle it. The main objectives are:
- to harmonise data protection across the EU;
- to hold those who process data accountable;
- to respect the rights of natural persons.
Failure to comply carries fines of up to 4% of turnover in the previous year.
But what has to change when it comes to sending files and attachments?
New rules on transferring data outside the EU
Transferring files outside the EU is now only possible where a sufficient level of protection exists. It also has to be framed by properly codified legal instruments. The data concerned can include:
- first name and surname;
- date of birth;
- payslip or salary;
- phone number;
- personal or work email and postal addresses;
- IP address, where it is linked to other information;
- payment card details;
- social security number;
- cookies;
- digital identifiers and others.
So what changes in practice for companies?
The GDPR sets out several protective measures governing how files and attachments are sent.
No more sending files by plain email
Transfers by plain email are now ruled out. Emails have to be accompanied by additional protective measures. It is recommended that you encrypt the items you send, using cryptography, encryption or a password, for instance.
You could, for example, send an email protected by a password that you pass to your recipient by text message. You can also give it to them directly over the phone. You can equally use the most recent versions of confidentiality and authentication protocols such as SFTP or HTTPS, whose role is to guarantee that the receiving server is authentic.
For fax users, you have to:
- restrict access to the room to authorised people only;
- confirm the identity of the receiving fax before sending anything;
- follow the fax transfer by sending the original documents to the recipient;
- register your potential recipients in advance where possible.
Have the right legal instruments for transfers
There are two kinds. Using some instruments requires prior authorisation from the CNIL, others do not. You will not need prior authorisation from that body if your transfer is based on:
- BCRs, or binding corporate rules, for private multinationals operating in several EU countries;
- the standard contractual clauses for data protection adopted by the European Commission;
- a code of conduct attested by a supervisory authority;
- a certification approved by a national accreditation body;
CNIL authorisation is, however, necessary where sending files and attachments rests on:
- specific contractual clauses between the various parties processing a file;
- measures built into administrative arrangements between public authorities and institutions.
In exceptional cases, files can be transferred by way of derogation from these legal instruments. Those particular situations are set out in article 49 of the GDPR.
Newsletters brought into line
Subscribing now works through double confirmation. When you agree, on a website, to sign up to a newsletter, your subscription is only confirmed if you click a link you receive by email. That is what is known as "double opt-in".
Respecting people's rights over their own data
Under article 4 of the GDPR, users have to be consulted before their personal data is handled in any way. So if an organisation wants to send you emails, it first has to make sure it has your free, informed, unambiguous and specific consent. And you are free to withdraw that consent at any time.
In light of all these changes now facing companies, it is clear they have to rely on a platform that meets the requirements of the GDPR in order to avoid penalties. So where should they turn?
NetExplorer is at your service with a platform that complies with the GDPR's requirements around sending files and attachments.
A complete platform for transferring files and attachments
As a service provider, NetExplorer does everything necessary to meet the requirements of the GDPR. Alongside its PCI DSS level 3, HDS and ISO 27001 certifications, not forgetting its external data protection officer and data encryption, special protective measures are taken for data transfers.
NetExplorer secures your file transfers through a download link. It is, in effect, a cloud solution particularly well suited to professionals. You can set the expiry date, how long access lasts, a password and the maximum number of downloads you want.
Our platform also offers you "Privacy by Service", a principle that limits data collection to the minimum needed for what you do on the platform. Every action involving the processing of personal data is carried out with strict respect for users' privacy.
A great many habits around sending files and attachments have been called into question by the arrival of the GDPR. Companies now have to entrust their needs to reliable platforms such as NetExplorer. Doing so keeps their clients' privacy intact and keeps them out of reach of penalties from the CNIL.
https://vimeo.com/918335378
Other articles you might like
SecNumCloud, ISO 27001, HDS: what are the differences?
ISO 27001, HDS, SecNumCloud: the question each standard answers, what it really covers, and which one to aim for in your sector.


But let's be honest, our cloud-based file storage and sharing solution is much easier.


