Is Dropbox GDPR-compliant?
Dropbox provides the pieces you need to use it compliantly — a data processing agreement, EU storage options on some plans, and published security documentation. The complication is that it is a US company, so an EU data centre answers where the bytes sit but not which government can compel access to them. Whether that matters depends entirely on what you are storing.
Not legal advice. For health data, children's data or anything at scale, get qualified advice.
The two separate questions
People collapse these into one and then argue past each other.
Where is the data stored? Dropbox offers EU storage on some plan types. Check which applies to your account, because it is not universal and it is not always the default.
Who can compel its production? Dropbox is incorporated in the United States. A US company can be served with lawful process for data under its control regardless of where that data physically sits. Storing it in Germany does not remove the company from US jurisdiction.
Neither of these is an accusation. Dropbox's security engineering is serious and its documentation is better than most. But the second question is a structural fact about corporate jurisdiction, not a quality judgement, and it is the one that decides a lot of procurement outcomes. The longer explanation.
What you need to do to use it compliantly
Get the data processing agreement in place. Dropbox publishes one; having it available and having accepted it for your account are different states. Check.
Know your sub-processors. Dropbox publishes a list. If your client contract requires you to disclose sub-processors, you need it.
Confirm your storage region. Do not assume. It varies by plan and by when the account was created.
Set retention deliberately. Dropbox's default is to keep things until you delete them, which is the opposite failure from a transfer service that deletes too soon. Storage limitation is a GDPR principle, and "we kept everything because it was easy" is a straightforward failure of it. Choosing a retention period.
Audit your shares. This is the big one in practice. Most Dropbox accounts have folders shared as "anyone with the link" from years ago, and every file added since has inherited that. That is not a Dropbox flaw; it is how link sharing works. It is also the most likely way you will actually leak something.
Dropbox versus Dropbox Transfer
Worth separating, because they have different properties.
Dropbox shares a file out of your storage. The recipient's access is a permission against your account, ongoing, and it changes meaning if you move or edit the file.
Dropbox Transfer hands over a copy. From Dropbox's own documentation, checked 31 July 2026: 2 GB free, 30 days by default, no advertising. Nothing the recipient does touches your files, and they see only what you sent.
For sending personal data to a third party, Transfer is the better shape — it is a bounded handover with an expiry rather than an open permission. The fuller argument.
When Dropbox is a reasonable choice
- Internal collaboration where the data stays within your organisation.
- Client work where the client has no data-location requirement.
- Teams that already run on it, where introducing a second vendor adds a data flow rather than removing one.
That last point deserves weight. Adding another service means another processor, another DPA and another place data lives. If Dropbox already meets your requirements, moving files to a second vendor can make your compliance position worse rather than better.
When to look elsewhere
- A written requirement that data stay within the EU, interpreted strictly.
- Public-sector or regulated work where jurisdiction is specified.
- Clients whose own DPAs prohibit US sub-processors.
- Special-category data where you have decided US jurisdiction is not acceptable risk. What changes with sensitive data.
If any of those apply, the European options is the place to start, and the test to apply is company incorporation rather than data centre location.
The practical checklist
- Is the DPA accepted for your account, not merely published?
- Which region is your data actually in?
- Have you read the sub-processor list this year?
- When did you last audit "anyone with the link" shares?
- What is your retention rule, and what enforces it?
- Does any client contract restrict sub-processors or jurisdictions?
Question four finds more real problems than the rest combined, and it takes five minutes.
The general framework is in what GDPR-compliant file transfer requires. If you are considering moving off Dropbox Transfer specifically, here is what else exists.
Disclosure: I run Yungle, which competes with Dropbox in a small way. It is EU-incorporated with files in Germany — which is why this page says plainly that adding a second vendor can make your compliance position worse rather than better.