UK GDPR and file transfer

UK GDPR file exchange

GDPR compliant file sharing, with a clearer operational trail

Support personal-data handoffs with named access, proportionate permissions, expiry and activity evidence. The platform supplies technical controls within a wider privacy and governance programme.

Transfer of personal dataBounded
Lawful basisRecorded by the sender
Recipients2 named, MFA required
RetentionCloses after 30 days
LocationUK, where configured
Access, downloads and closure all recorded

Where transfers go wrong

GDPR compliant file sharing as part of a wider privacy programme

A privacy notice can describe recipients precisely while the actual transfer happens as an email attachment to an address somebody typed from memory. MX narrows that gap by making the recipient, the window and the record part of the act of sending.

The recipient is assumed

Attachments and open links treat possession as entitlement. Named access ties the file to a specific person instead.

The retention never ends

Storage retention is governed. Ad hoc external copies usually are not, and they outlive their purpose quietly.

The evidence is a mailbox

Reconstructing a disclosure from an email thread months later is slow and rarely complete.

Principle by principle

Six places where the transfer step touches UK GDPR.

None of these are satisfied by a product on its own. They are decisions your organisation makes, and a controlled route makes the decisions easier to apply consistently and easier to show afterwards.

Article 5(1)(f)

Integrity and confidentiality

Personal data should be processed with appropriate security, including protection against unauthorised access during transmission. Encryption in transit and at rest, named access and download conditions all speak to this.

Article 5(1)(c)

Data minimisation

Send the records the recipient needs for the stated purpose instead of a folder that happens to contain them. Assembling the package deliberately is a minimisation decision, not an administrative one.

Article 5(1)(e)

Storage limitation

An external copy that stays reachable indefinitely undermines a retention schedule that is otherwise sound. Setting an expiry at the point of sending keeps the two aligned.

Article 5(2)

Accountability

You are expected to demonstrate compliance, not merely assert it. A retained activity record showing who was invited, who accessed and when availability closed is the kind of evidence that supports this.

Article 32

Security of processing

Measures should be appropriate to the risk, taking account of the state of the art and the nature of the data. Configurable identity, permission and protection settings let the measure match the material.

Articles 44-49

International transfers

Where data location matters, choices over where information is held can help support the arrangements your organisation has put in place. The contractual and transfer-mechanism work remains yours.

My MX Data is a processor-side technical measure. It does not determine your lawful basis, your retention schedule or whether your processing is compliant.

A defensible transfer

Four steps that turn a send into something you can account for.

The sequence is short deliberately. A privacy control that adds five minutes to an urgent task will be bypassed, and a bypassed control protects nobody.

Step 01

State the purpose

Record why the data is moving and who is entitled to receive it.

Step 02

Minimise the package

Include the records the purpose requires and remove the rest.

Step 03

Bound the access

Name the recipients, set the window and apply conditions proportionate to the risk.

Step 04

Retain the record

Keep the activity attached to the transfer so it can be produced on request.

Practical guidance

Treat the transfer as a processing activity in its own right.

Organisations tend to map processing at the level of systems: a CRM holds customer records, a payroll platform holds employee data, a case management system holds client files. Transfers between those systems and the outside world often sit in the gaps of that map, described as a step in a process instead of as processing with its own recipients, retention and risk.

Naming the transfer separately changes what you can control. It gives the exchange an owner, a purpose and an end date. It also makes the difference between two apparently similar sends visible: a routine statement to a client and a bulk export to a new supplier deserve different treatment, and a single generic instruction to use secure sharing does not capture that.

A subject access request or a breach notification will ask you what left the organisation, when, and who received it. That is easier to answer if somebody decided it in advance.

The practical test is whether a colleague who was not involved could reconstruct the transfer from the record alone. If the answer depends on finding the original email thread or asking the person who sent it, the accountability position is weaker than the policy suggests.

Start with the transfers that involve special category data, large volumes or recipients outside the organisation's usual set. Those are where the consequences of an error are highest and where a defined route earns its cost most quickly.

Questions a reviewer will ask

  1. What was sent? The package, not just the filename, including which records it contained.
  2. Who received it? A named person, with evidence they were the one who accessed it.
  3. On what basis? The purpose and authority for the transfer, recorded at the time.
  4. For how long? The availability window and whether it was extended, by whom and why.
  5. What happened next? Access, download and closure events attached to the same transaction.

Be clear about the boundary

Software supplies the control. Compliance stays with the controller.

Any vendor claiming their product makes you GDPR compliant is describing something the Regulation does not recognise. What a product can do is make the right behaviour easier and the evidence easier to produce.

AES-256Encryption in transit and at rest
ASROptional anonymise, shard and restore layer
RecordedAccess and closure evidence per transfer
- INSERT TESTIMONIALS -
- INSERT ESSENTIAL READS -
- INSERT FAQs -

Data protection in practice

Give personal data transfers a route you can explain.

Start with a seven-day trial for up to five users, or ask for a demonstration focused on one transfer that currently worries your privacy team.