Why WeTransfer isn't built for professionals
Quick reply
US subprocessors, no DPA, a link nobody can find afterwards: the concrete GDPR risks of sending company files through WeTransfer.

WeTransfer has established itself as a quick, easy way to send large files. Behind that simplicity, though, sit real legal and strategic risks, particularly around the General Data Protection Regulation (GDPR) and digital sovereignty.
For French companies and institutions, using the tool can run counter to their values and their regulatory obligations. And to their sector, too.
WeTransfer is an online file transfer service originally designed for creatives. It remains firmly anchored in that positioning today: its website, its campaigns, its look. Everything points that way.
And that may be part of why security has been left to one side.
A practical service, certainly, but not a sovereign one
Founded in 2009 in the Netherlands, WeTransfer lets you send large files quickly and easily to one or several people. One of its headline advantages? The free version needs no account.
It comes in two versions:
• Free: files up to 2 GB, automatic expiry, no traceability.
• WeTransfer Pro / Premium: customised transfers, storage, configurable expiry, password-protected links, files up to 200 GB.
Although WeTransfer is a Dutch company, it uses cloud computing services provided by American companies. That means that even where the data is hosted in the European Union, it can be subject to American law. The Cloud Act is a case in point: it allows the American authorities to reach data held by American companies, even when that data sits abroad.
According to the "WeTransfer Sub-processors" document updated in April 2025, WeTransfer relies on several subprocessors, among them:
• Amazon Web Services (AWS) – Location: EU/United States – Service: cloud infrastructure
• Google Cloud – Location: United States – Service: data analytics
• Stripe – Location: United States – Service: payment processing
• SendGrid – Location: United States – Service: transactional email
• CrowdStrike LogScale – Location: United States – Service: SIEM
• Slack – Location: United States – Service: Zendesk integration for ticket management
...
These tools therefore raise concerns around digital sovereignty and GDPR compliance.
On top of that, the GDPR generally requires organisations to sign a data processing agreement (DPA) with any provider processing personal data on their behalf.
In WeTransfer's case:
• No DPA is provided automatically when using the free version
• It is hard to obtain even on a paid plan (and only on specific request)

A lack of control over the data you share
In a company, sharing heavy files can be a recurring difficulty. For a one-off send, most employees turn to the free version of WeTransfer. Quick, simple, effective. It does the job. Within minutes the file has gone out as an email or a link.
In the free version, though, WeTransfer offers:
• no end-to-end encryption,
• no strong authentication of the recipient,
• no activity log to track who opens or downloads what.
A leak or a wrong recipient is therefore not only possible, but impossible to trace or to account for in the event of a CNIL inspection or a security incident.
And that is before counting the company's exposure to shadow IT. Your data, sometimes sensitive, goes out without approval or oversight, through links anyone can open.
That does not only weaken your security policy: it undermines your reputation and how rigorous you look to clients and partners.
What WeTransfer can actually cost you
Picture an HR manager transferring a folder of confidential data through WeTransfer (contracts, payslips and the like). They pick the wrong recipient, or the link gets passed to an unauthorised third party.
The result: the link cannot be revoked, access cannot be traced, and the security measures taken certainly cannot be proved.
Immediate consequence: a mandatory report to the CNIL within 72 hours (article 33 of the GDPR).
And at worst? A public leak that does lasting damage to your organisation's image (a story that gets picked up, trust called into question, press coverage).
🔎 A reminder. The GDPR provides for penalties of up to 4% of worldwide turnover or 20 million euros, depending on how serious the breach is.
In short, a WeTransfer link can cost you far more than a subscription to a secure solution.

An alternative: sovereign, compliant and secure
Sending files instantly has become essential to how effectively an organisation runs. Cybersecurity, meanwhile, is the chief concern when it comes to protecting your data.
Where WeTransfer became popular through its simplicity, NetExplorer is a French solution positioned as a sovereign specialist in file sharing, through a secure platform designed specifically for organisations that care about protecting their data.
Compliant with the GDPR, NIS 2 and DORA, and certified ISO 27001, ISO 9001 and HDS (Health Data Hosting), we make data security our priority. We are also going through SecNumCloud qualification. As a sovereign software vendor and host, NetExplorer will keep carrying that commitment to transparency.
→ To go further and get a clearer view of the risks of using WeTransfer, do download our full webinar and ebook on the subject.
Other articles you might like
How to exchange health data securely
Sharing with colleagues, labs and patients: the guarantees to demand from any channel carrying data covered by medical confidentiality.


But let's be honest, our cloud-based file storage and sharing solution is much easier.


