Every business sends files: quotes, contracts, annual accounts, personnel data. Usually on autopilot, as an e-mail attachment or through the first free sharing service at hand. Until something goes wrong. Then "just sending a file" suddenly turns out to have been a decision about client data, liability and the GDPR.

The three options, compared honestly

The e-mail attachment. Familiar and available everywhere, but you give up all control the moment you hit send. An attachment cannot be recalled, never expires, and leaves copies on every mail server along the way. Fine for a newsletter, a risk for a payslip.

The free sharing service. WeTransfer and similar services are built for consumers: sending something large quickly, no hassle. They do that well. But for business use you miss the basics: no password (in the free tier), no revocable links, no insight into who downloads, and traffic that may route through American servers. We compared the differences point by point.

The secured sharing link. The file lives in one place, encrypted, inside the EU. You decide per recipient who gets in, with which password, and until when. If something goes wrong, you revoke the link and access ends immediately.

Why this is not a detail

The largest category of data breaches in the Netherlands has for years not been a hack but a mistake: personal data sent to the wrong recipient. In the Dutch DPA's annual figures it is consistently the most reported type of breach, with over 1,700 reports about misaddressed e-mail in a single half year. One typo in an address field is enough, and a sent attachment can never be recalled. Such a mistake can be a reportable breach: where there is risk to the people involved, you must report within 72 hours.

With a sharing link the same mistake is a non-incident: revoke the link, send a new one to the right address, and the audit log shows nothing was ever downloaded.

The GDPR checklist

What should business file sharing look like? Eight requirements, also available as a shareable checklist below (save it, pass it on):

  1. Storage inside the EU, under European jurisdiction
  2. A data processing agreement: once a service processes your clients' personal data this is a GDPR requirement (article 28), not a luxury
  3. Encryption at rest, not just in transit
  4. Access per file: a link should open exactly one document
  5. Revocable links, for when things go wrong anyway
  6. An expiry date: access that ends by itself
  7. A password through another channel, so a forwarded link is worthless
  8. An audit log, so you can reconstruct who did what during an audit or incident

GDPR checklist: secure file sharing

About that data processing agreement

Point 2 is skipped most often, and it is exactly where an accountant, lawyer or data protection officer will push back first. If you share client documents through a service, that service is a processor and a data processing agreement belongs with it: what happens to the data, where it lives, and what happens in case of an incident. Free consumer services rarely offer one. At codocs it is available for business clients; e-mail hello@codocs.nl.

Practical: send better tomorrow

It does not have to be a big change. Pick one document type that really matters (annual accounts, contracts, IDs) and agree that it never travels as an attachment again. Upload, create a link per recipient with a password and an expiry date, and revoke links once an engagement ends. The rest of your e-mail can stay as it is; the sensitive ten percent deserves the secured route.

That is exactly what codocs is built for: sending business files with control, from European servers, with an audit log that does the accountability for you.