Is WeTransfer GDPR-compliant?
WeTransfer can be used in a GDPR-compliant way, and the harder question — the one that actually determines your exposure — is whether your use of it is. The service being capable of compliance and your particular workflow being compliant are different things, and the gap between them is where almost all real problems live.
Not legal advice. If you handle health data, children's data, or personal data at scale, talk to someone qualified.
The short answer
WeTransfer is a Dutch company, which puts it inside the EU and inside the GDPR's own jurisdiction. That is a genuinely meaningful starting point and better than most household names in this category.
Whether you are compliant using it depends on four things that are your responsibility, not theirs:
- Do you have a data processing agreement with them covering your use?
- Do you know where the data goes, including sub-processors?
- Have you set a retention period, or accepted their default without thinking?
- Would you be able to answer a client asking any of the above?
Most people using it for client work cannot answer question one, and that is the actual finding.
What WeTransfer publishes
From WeTransfer's own plan-limits documentation, checked 31 July 2026: the free tier is 3 GB, counted across a rolling 30 days rather than per transfer, and it is ad-supported. Transfers that never expire are a top-tier feature.
For current details of their processing terms, sub-processors and available agreements, go to their own documentation rather than trusting a comparison page — including this one. Those change, and a third party summarising them is exactly how stale claims spread. What I will not do is characterise their contractual terms from memory or from a review site.
The parts that are actually your problem
The free tier is advertising-supported
This is the detail worth pausing on. An ad-supported download page means third parties are involved in the page your recipient loads. That is a different data flow from the file transfer itself, and if you are sending on behalf of a client with strict requirements, it is the sort of thing that comes up in a questionnaire.
It also means your client sees advertising on the page you sent them to, which is a separate and smaller problem.
You probably have no DPA
If you signed up with an email address and started sending client files, you likely have not put a processing agreement in place. For personal data, that is the gap. It is not exotic or hard to fix — but it does need doing, and nobody does it until asked.
Retention is a decision you have not made
On a free account, expiry is the product rather than a setting. That is arguably good for data minimisation — data you no longer hold cannot leak. It is bad if you needed the file, which is the most common complaint in this category.
Either way, the compliance question is whether you chose it. "The service deleted it" is not a retention policy, though it accidentally produces a defensible outcome.
You are probably a processor, not a controller
If a client gave you their customers' data to work on, they are the controller and you are their processor — which means their requirements flow down to you, and WeTransfer becomes a sub-processor you may be contractually required to disclose. Plenty of client contracts require notification of sub-processors, and plenty of freelancers have never told a client which transfer service they use.
When WeTransfer is fine
- Sending your own work product that contains no personal data.
- Sending to a client who has no specific requirements and has not asked.
- One-off transfers where the short retention is a feature rather than a problem.
For a large share of freelance work, that is the honest situation, and switching services would be solving a problem you do not have.
When to look harder
- Special-category data — health, biometrics, anything about someone's private life. The obligations get sharper.
- A client with a compliance function. They will ask, and "WeTransfer" without a DPA is not an answer.
- Public sector or regulated work, where requirements are often written as hard rules about data location.
- Anything where you are contractually a processor and have obligations you have not read recently.
What to do this week
Three things, none of which require changing service:
- Find out whether you have a DPA with whatever you use. If not, get one or stop using it for personal data.
- Write down a retention rule. One sentence. "Client deliverables are kept for the length of the engagement plus six months, then deleted."
- Know your answer to "where is the data and who can compel access", because that is the question that arrives without warning. For any US-owned provider, the answer is more complicated than the data centre location suggests.
The full framework is in what GDPR-compliant file transfer actually requires. If you conclude you need a different service, the European options is the right starting point — and note that WeTransfer being Dutch means it belongs on that list rather than being excluded from it.
Disclosure: I run Yungle, a competing service, which is why this page goes out of its way to state what WeTransfer gets right. It is EU-incorporated, files sit in Germany with EU backups, and there is a DPA you can read.