THE WEAK LINK: FILE TRANSFERS
You protect your premises, your servers, your passwords. But what happens when you send a confidential document to a client or partner?
A contract sent by email passes through several servers before reaching its destination. A file uploaded to an online sharing service is stored on third-party servers, often located outside Europe. At each step, your data can be intercepted, copied, or accessed by third parties.
The GDPR requires the protection of personal data during processing, and this explicitly includes transfers.
WHAT THE GDPR SAYS ABOUT TRANSFERS
Article 32: Securing data in transit
Article 32 of the GDPR requires appropriate technical measures to ensure data security. Among these measures, the text cites first the encryption of personal data.
These requirements particularly apply to file transfers. Sending an unencrypted document by email or via a consumer cloud service exposes data to risks that the GDPR specifically asks you to avoid.
The problem with cloud services outside Europe
Since the invalidation of the Privacy Shield in 2020 (Schrems II ruling), data transfers to the United States raise complex legal questions. Consumer sharing services often store your files on servers subject to US law, including the Cloud Act.
For sensitive data (contracts, HR documents, medical information), using these services without prior encryption may constitute a GDPR violation.
THE SOLUTION: END-TO-END ENCRYPTION
How it works
End-to-end encryption means the file is encrypted before leaving your computer and can only be decrypted by the intended recipient. Throughout the entire transit:
- Email servers only see an unreadable file
- Cloud services cannot access the content
- Network interception reveals nothing exploitable
Only the recipient, with the appropriate password or certificate, can read the file.
Why it's different from HTTPS
HTTPS protects the connection between you and a server, but not the file itself. When you upload a document to a cloud service via HTTPS, the file arrives unencrypted on their servers. With end-to-end encryption, the file remains encrypted even on the intermediate server.
CONCRETE RISKS WITHOUT ENCRYPTION
Here are common situations where your data is exposed:
- A lawyer sends a contract by email: the file transits unencrypted through several servers
- An accountant shares financial statements via a cloud service: data is stored on servers outside Europe
- An HR department sends a payslip as an attachment: any mail administrator can view it
- An engineering firm transmits confidential plans: has the client verified the storage conditions?
In all these cases, a data breach could trigger a notification obligation (Article 34 of the GDPR) and engage your liability.
HOW SIGALION VAULT SECURES YOUR TRANSFERS
Encryption before sending
With Sigalion Vault, you encrypt your files before transferring them, regardless of the channel used afterwards (email, cloud, USB drive). The recipient receives an encrypted file that they decrypt with Sigalion Vault (free mode) using the password you communicate separately.
The file remains protected throughout transit. Even if your email is intercepted or the cloud service is compromised, the data remains unreadable.
Sigalion uses AES-256 and ChaCha20, algorithms recommended by ANSSI (French National Cybersecurity Agency).
Integrated transfer with notification
For users with an account, Sigalion Vault offers an integrated transfer service: the encrypted file is temporarily hosted on our servers in France, and the recipient receives a download link by email or SMS. Once downloaded or after expiration, the file is automatically deleted.
CONCLUSION
File transfer is often when your data is most vulnerable. Unsecured email, cloud services outside Europe, network interception: the risks are real and the GDPR asks you to anticipate them.
End-to-end encryption is a simple and effective answer:
- The file is protected before leaving your computer
- Only the recipient can decrypt it
- You maintain control of your data, regardless of the transmission channel
- You demonstrate your GDPR compliance in case of an audit
Protecting your exchanges means protecting your clients and your reputation.