Regulations
Published on
23.10.2020

Sending files and attachments: what the GDPR changes

Caroline Boisramé Moreau

Quick reply

Unencrypted attachments, transfers outside the EU, double opt-in: what the GDPR changed in the way companies send files and attachments.

In this article

With the technological leaps of the past two decades, data protection law had to be improved and completed. That is how the GDPR came to reinforce the data protection directives in force since 1995. Institutions and companies in the European Union have to meet the requirements of this regulation in order to send and receive files and attachments. What is the GDPR? And what are the new rules governing file transfers?

What is the GDPR, and what are its main objectives?

GDPR stands for General Data Protection Regulation. Passed by the European Union on 14 April 2016, it went through a two-year transition period before coming into force on 25 May 2018. That transition allowed each EU member state to bring the new rules into its own national law.

The GDPR is the reference text governing the protection of the personal data of people living in the EU. Each member state has a data protection authority to enforce the law and make sure the principles of the GDPR are respected. In France, that is the CNIL.

The objectives of the GDPR are to strengthen the protection of EU citizens' personal data more than ever, by imposing new security standards on the companies that handle it. The main objectives are:

  • to harmonise data protection across the EU;
  • to hold those who process data accountable;
  • to respect the rights of natural persons.

Failure to comply carries fines of up to 4% of turnover in the previous year.

But what has to change when it comes to sending files and attachments?

New rules on transferring data outside the EU

Transferring files outside the EU is now only possible where a sufficient level of protection exists. It also has to be framed by properly codified legal instruments. The data concerned can include:

  • first name and surname;
  • date of birth;
  • payslip or salary;
  • phone number;
  • personal or work email and postal addresses;
  • IP address, where it is linked to other information;
  • payment card details;
  • social security number;
  • cookies;
  • digital identifiers and others.

So what changes in practice for companies?

The GDPR sets out several protective measures governing how files and attachments are sent.

No more sending files by plain email

Transfers by plain email are now ruled out. Emails have to be accompanied by additional protective measures. It is recommended that you encrypt the items you send, using cryptography, encryption or a password, for instance.

You could, for example, send an email protected by a password that you pass to your recipient by text message. You can also give it to them directly over the phone. You can equally use the most recent versions of confidentiality and authentication protocols such as SFTP or HTTPS, whose role is to guarantee that the receiving server is authentic.

For fax users, you have to:

  • restrict access to the room to authorised people only;
  • confirm the identity of the receiving fax before sending anything;
  • follow the fax transfer by sending the original documents to the recipient;
  • register your potential recipients in advance where possible.

Have the right legal instruments for transfers

There are two kinds. Using some instruments requires prior authorisation from the CNIL, others do not. You will not need prior authorisation from that body if your transfer is based on:

  • BCRs, or binding corporate rules, for private multinationals operating in several EU countries;
  • the standard contractual clauses for data protection adopted by the European Commission;
  • a code of conduct attested by a supervisory authority;
  • a certification approved by a national accreditation body;

CNIL authorisation is, however, necessary where sending files and attachments rests on:

  • specific contractual clauses between the various parties processing a file;
  • measures built into administrative arrangements between public authorities and institutions.

In exceptional cases, files can be transferred by way of derogation from these legal instruments. Those particular situations are set out in article 49 of the GDPR.

Newsletters brought into line

Subscribing now works through double confirmation. When you agree, on a website, to sign up to a newsletter, your subscription is only confirmed if you click a link you receive by email. That is what is known as "double opt-in".

Respecting people's rights over their own data

Under article 4 of the GDPR, users have to be consulted before their personal data is handled in any way. So if an organisation wants to send you emails, it first has to make sure it has your free, informed, unambiguous and specific consent. And you are free to withdraw that consent at any time.

In light of all these changes now facing companies, it is clear they have to rely on a platform that meets the requirements of the GDPR in order to avoid penalties. So where should they turn?

NetExplorer is at your service with a platform that complies with the GDPR's requirements around sending files and attachments.

A complete platform for transferring files and attachments

As a service provider, NetExplorer does everything necessary to meet the requirements of the GDPR. Alongside its PCI DSS level 3, HDS and ISO 27001 certifications, not forgetting its external data protection officer and data encryption, special protective measures are taken for data transfers.

NetExplorer secures your file transfers through a download link. It is, in effect, a cloud solution particularly well suited to professionals. You can set the expiry date, how long access lasts, a password and the maximum number of downloads you want.

Our platform also offers you "Privacy by Service", a principle that limits data collection to the minimum needed for what you do on the platform. Every action involving the processing of personal data is carried out with strict respect for users' privacy.

A great many habits around sending files and attachments have been called into question by the arrival of the GDPR. Companies now have to entrust their needs to reliable platforms such as NetExplorer. Doing so keeps their clients' privacy intact and keeps them out of reach of penalties from the CNIL.

https://vimeo.com/918335378

No items found.
No items found.

Definition

No items found.

FAQ

No questions found.

Best practices / Common pitfalls

No items found.

Key figures

No items found.

Key takeaways

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

You could keep all your documents on a floppy disk.
Vintage office chair with a pile of folders and a beige corded telephone, handset off the hook on red carpet.

But let's be honest, our cloud-based file storage and sharing solution is much easier.