GDPR-oriented file sharing controls
Support more controlled handling of personal data when files move between organisations.
My MX Data provides technical controls that can support GDPR-aligned file-exchange processes, including named access, protected transfer, expiry and reviewable activity. The platform does not make an organisation GDPR compliant on its own.
Useful technical controls inside a wider privacy programme.
Named-user access
Keep personal-data exchanges associated with the intended participants.
Defined availability
Use permissions and expiry to reduce indefinite access after the business purpose ends.
Reviewable activity
Retain evidence that can help with governance, incident review and subject-related questions.
Your organisation remains responsible for lawful basis, transparency, retention, data-subject rights, processor arrangements and the wider governance required by data-protection law.
Trusted for sensitive, accountable file exchange.
Frequently asked questions
Clear answers about GDPR-Compliant File Sharing.
Does using My MX Data make an organisation gdpr-compliant?
No. Using My MX Data does not make an organisation GDPR-compliant by itself. GDPR compliance depends on the full way personal data is collected, used, shared, retained and deleted, as well as the organisation's lawful basis, policies, contracts, staff behaviour and wider technical controls.
MX can support that wider framework by giving organisations more control over external file exchanges. Named-recipient access, permissions, multi-factor authentication, expiry settings and activity records can help reduce uncontrolled sharing and provide clearer evidence of what happened to a file after it was sent.
Those controls still need to be configured and used appropriately. An organisation remains responsible for matters such as data minimisation, retention periods, processor relationships, international transfers and responding to data-subject rights.
For a broader view of the platform controls that may support a data-protection programme, see the MX security and file-sharing features. Legal and compliance teams should assess MX alongside their own policies, risk assessments and contractual requirements. A compliant process also needs documented responsibilities and regular review, not just technical settings.
Which MX controls can support this compliance area?
MX provides several controls that can support an organisation's GDPR-related file-sharing responsibilities. These include named-recipient access, permission controls, multi-factor authentication, expiry settings, AES-256 encryption and detailed activity records.
In practical terms, those controls can help limit who receives personal data, reduce reliance on open public links and give administrators clearer evidence of access or download activity. Expiry settings can also reduce the chance of a file remaining available for longer than the business purpose requires.
For particularly sensitive information, MX can also use ASR, which stands for Anonymise, Shard and Restore. ASR is separate from standard encryption and adds another method of protecting the underlying data during an exchange.
These capabilities support technical and organisational measures, but they do not replace lawful processing decisions, retention policies or staff procedures. The encrypted file-sharing page explains more about how the protection layer works during controlled exchanges.
How does MX restrict access to personal data and other protected information?
MX can restrict personal data to approved or named recipients instead of making it available through an unrestricted public link. This gives the sender a clearer connection between the information being shared and the person or organisation it was intended to reach.
Permission settings can then be used to control what different recipients or team members are allowed to view, download or manage. Multi-factor authentication adds an additional identity check before access is granted, while expiry settings can limit how long access remains available.
These controls are useful where a business shares customer records, employee information, financial details, due-diligence documents or other files containing personal data. They help make the exchange more deliberate without assuming that every file requires the same conditions.
Where the requirement involves external customers or professional advisers, the secure client file-sharing approach shows how named access and traceability can be applied to routine client exchanges.
What audit evidence does MX retain?
MX records activity associated with file exchanges, providing evidence that can be useful for internal reviews, investigations and compliance work. Depending on the transaction, records may include uploads, access, downloads, comments, recipient activity, timestamps, user information and relevant IP details.
This can help an organisation answer practical questions later. For example, a team may need to establish whether a recipient accessed a file, whether the current version was downloaded or whether an exchange remained incomplete.
Audit records do not prove GDPR compliance on their own, but they can support accountability by showing how a particular exchange was handled. The usefulness of that evidence also depends on the organisation's retention rules, review processes and how access to the records is governed.
For more detail on why this evidence matters, our guide to building a file audit trail explains how activity logs can support audits and investigations without turning logging into a substitute for broader governance.
How does MX protect data in an exchange?
MX protects information through a combination of controls rather than relying on one security feature. AES-256 encryption forms part of the security model, alongside named-recipient access, permissions, multi-factor authentication, expiry settings and audit records.
For organisations handling highly sensitive or commercially valuable information, MX also offers ASR, which stands for Anonymise, Shard and Restore. ASR transforms the data so the underlying content is not recognisable, separates the transformed information into protected shards and restores it for an authorised recipient.
ASR should not be treated as another name for encryption, and neither control removes every possible risk. Endpoint security, recipient behaviour, account management and internal policies still affect the security of the wider process.
The encrypted file-sharing page covers the protection model in more detail, including how controlled access and encryption can be combined when sensitive information needs to move outside the organisation.
Can MX support data residency or sovereignty requirements?
Yes, MX can support data-location and storage-region requirements, subject to the selected service, configuration and contractual arrangement. This can be relevant where an organisation needs greater certainty about the jurisdictions in which sensitive information is stored or processed.
Data residency may be driven by customer contracts, sector rules, internal governance, procurement requirements or the organisation's assessment of cross-border transfers. The correct setup therefore depends on the specific legal and operational context rather than a single default rule.
MX can provide options that help organisations align file exchanges with those requirements, but the organisation remains responsible for deciding what locations are acceptable and whether additional contractual or legal safeguards are needed.
If residency forms part of a broader cloud or storage review, the secure data storage page provides useful context on controlled business information handling. Enterprise requirements should be confirmed before deployment.
Can regulated organisations exchange very large files with MX?
Yes. MX is designed to support very large file transfers without arbitrary file-size restrictions, which can be particularly useful for regulated organisations that need to exchange large document sets, technical data, media, software packages or complete project folders.
Large files often create awkward workarounds when email or a general-purpose tool cannot accept the transfer. Teams may split files, compress datasets or switch to an unapproved service. Keeping the exchange inside one controlled process can reduce that fragmentation.
The same recipient, authentication, permission and audit controls can still apply around the transfer. That means the file can be large without losing the identity and activity controls that matter when information is sensitive or subject to internal governance.
Our large-file sharing guidance explains the practical transfer use case in more detail. Organisations should still check their own retention, data-classification and compliance rules before sending regulated information.
What should an organisation verify before relying on MX for this use case?
Before relying on MX for a GDPR-related workflow, an organisation should verify that the proposed configuration fits its legal, contractual and information-governance requirements. The platform can provide useful controls, but the surrounding compliance decisions remain with the organisation.
That review should consider who will send and receive personal data, what permissions are appropriate, how long access should remain available, where the data needs to be located and what audit evidence must be retained. Integration, identity-management and administrator responsibilities may also matter in larger deployments.
Organisations should also confirm the relevant MX plan, service configuration and any contractual arrangements required for their use case. Features and service availability can vary, particularly where enterprise identity, data-location or custom security requirements are involved.
For complex requirements, a tailored enterprise demonstration can help security, governance and operational stakeholders review how the exchange process would work before it is adopted.