US visitor Some of our content is UK-flavored. USD pricing, US data region and Delaware C-Corp diligence are all supported. See the US guide →

Beamprobe Beamprobe v1.0
Free tool

UK GDPR file-sharing checklist.

Seven Article 32 measures. Tick what your firm has in place. Get a defensibility score and gap analysis.

Printable

Download the A4 PDF version

Single-page printable. Save in your compliance archive.

Download PDF
Read more

The full GDPR file-sharing pillar.

For the deep version of each checklist item - what the ICO actually requires, how email fails the Article 32 test, and what to do about it - see the pillar guide.

GDPR-Compliant File Sharing for UK Businesses
FAQ

UK GDPR file-sharing questions

What does UK GDPR Article 32 require?

"Appropriate technical and organisational measures" proportionate to the risk. In practice: encryption at rest and in transit, access control, an audit trail, breach notification within 72 hours, and the ability to demonstrate compliance. Email attachments fail at least three of these tests for confidential documents.

Is email attachment GDPR compliant?

For non-personal data, yes. For personal or commercially sensitive data, usually not. Email lacks encryption-at-rest after delivery, an audit trail of who opened the attachment, and any access revocation mechanism. A data room with NDA gate and audit log meets all three.

Does UK GDPR require ICO registration?

Most UK businesses processing personal data must register with the ICO unless an exemption applies. The fee is £40-£2,900 per year depending on size. Sharing client documents via a data room does not by itself trigger registration if you are already registered for your normal processing.

Where should UK personal data be stored?

UK or EU is the lowest-friction answer. US storage requires the UK International Data Transfer Addendum (IDTA) or adequacy regulations, which adds paperwork your counterparty may not sign. Beamprobe defaults to EU jurisdiction on Cloudflare R2 with UK and US optional.

Do I need a DPA with my data room vendor?

Yes if you are processing personal data through the vendor. UK GDPR Article 28 requires a written Data Processing Agreement covering subject matter, duration, nature, types of personal data, controller obligations, and sub-processors. Beamprobe publishes its DPA at /legal/dpa.