File safety
Does using an online file converter make it a processor under GDPR?
Uploading a document to an online converter usually discloses personal data to a third party. Here is what that means for your Article 28 contracts, your Article 30 record, and your transfer assessment.
Reviewed and updated
You have a signed contract, a scanned ID, or an HR file, and it needs to be smaller or in a different format. Somebody opens a free converter, drags the file in, and gets the result back in four seconds. The work is done and nobody thinks about it again.
That upload is a disclosure of personal data to a third party, and the tidy version of your compliance documentation no longer matches what actually happened.
What the upload actually does
The regulation defines a processor as anyone who processes personal data on behalf of the controller. Nothing in that definition requires a subscription, a login, or a paid tier. A provider that receives your file and converts it is acting on your instruction and is holding personal data because you sent it. That is the relationship, whether or not either side has acknowledged it.
Three obligations follow directly, and they are the ones auditors ask about.
A written contract. Article 28 requires processing by a processor to be governed by a contract setting out the subject matter, duration, nature and purpose, the categories of data subject, and the processor’s obligations. Many free converters publish terms of service and a privacy policy but offer no data processing agreement at all. If there is no agreement, there is no way to demonstrate compliance for that activity, and the gap belongs to you rather than to them.
An entry in your record. Article 30 requires controllers to maintain a record of processing activities including the categories of recipients to whom personal data have been disclosed. A converter that receives files is a recipient. If it is not in the record, the record is incomplete.
A transfer assessment. If the provider stores or processes outside the EEA, or outside the UK for UK GDPR, Chapter V applies. You need a transfer mechanism and, following Schrems II, an assessment of whether the destination country’s law undermines it. Most free tools do not publish their processing locations clearly enough for you to complete that assessment honestly.
The answers that sound reassuring and are not
“Files are deleted after an hour.” Retention is a control on how long exposure lasts, not a reason the exposure did not occur. The provider received the data. Article 28 is still engaged.
“The connection is encrypted.” TLS protects the file between your browser and their server. It is doing its job precisely up to the point where the server decrypts the file in order to convert it. Encryption in transit is not a limit on who receives something.
“We are ISO 27001 certified.” A certification describes how an organisation manages security. It is evidence you can rely on when choosing a processor. It is not itself the contract that Article 28 requires.
“We do not look at your files.” Almost certainly true, and beside the point. The obligations attach to receiving the data, not to reading it.
What changes when the file never moves
A tool that runs the conversion in your browser reaches a different answer, and it reaches it structurally rather than by policy.
The file is read by code already running on your device. No request carries the bytes anywhere. There is no recipient, so there is no processor for that step, no Article 28 contract to negotiate, no sub-processor chain to monitor, and no transfer to assess. Your obligations as controller are unchanged, because the document and the personal data in it are still yours to protect, minimise and delete. What disappears is an entire relationship you would otherwise have had to paper and maintain.
The useful part of that claim is that you do not have to take it on trust. Open your browser’s network panel, clear it, run a file through the tool, and watch what is requested. Code and fonts loading from the tool’s own origin are the page working. A request carrying your document to a server is the thing that would create the processor relationship, and it either appears or it does not.
Being straight about the limits
Browser processing removes the file transfer. It does not make you exempt from anything else.
You are still the controller. Storage on the device, retention of the output, who has access to the machine, and what you do with the result afterwards all remain yours. Visiting any website involves a server, so hosting and content delivery still exist as processing relationships even when your document is not part of them. Large tools that rely on a processing engine or a model download that engine to your device the first time, which is code arriving rather than your file leaving, and it is worth confirming which direction traffic is going rather than assuming.
We build local file tools, and we are not lawyers. Nothing here is legal advice. Your data protection officer or counsel should decide how these obligations apply to your organisation, and this is meant to describe the mechanism accurately enough that the conversation starts from the right facts.
What to do on Monday
Search your expense claims and browser history for the converter your team actually uses, because it is rarely the one in the policy. For each tool that receives files, find out whether a data processing agreement exists and whether you have signed it. Where one does not, either stop routing personal data through it or move that task to a tool that never transmits the file at all. Our compress PDF, merge PDF and protect PDF tools run entirely in your browser, so the document is not disclosed to us and there is no agreement for you to chase. Then update the record so it describes the tools in use rather than the tools that were approved.
The cheapest of those steps is the last one, and it is the one that removes the finding.
The FileGizmo way
Free tools. Never uploaded.
Good to know
Frequently asked questions
Does a privacy policy saying files are deleted after one hour make a converter GDPR compliant?
No. Deletion is a retention control, not a lawful basis and not a contract. The provider still received the personal data, still counts as a recipient, and still needs an Article 28 agreement. A short retention window reduces exposure but does not remove the processing relationship.
Is a free online converter acceptable for documents containing personal data?
It depends entirely on whether you have a processor agreement with that provider and whether the transfer is lawful. Free consumer tools frequently offer no data processing agreement at all, which leaves the controller unable to demonstrate Article 28 compliance for that activity.
Does browser-based processing remove GDPR from the picture entirely?
No. You remain the controller of the document and of any personal data in it, with the same duties of security, minimisation and retention. What changes is that no third party receives the file, so there is no processor to contract with and no transfer to assess for that step.
Does HTTPS satisfy the transfer requirements?
No. Encryption in transit protects the file from interception on the way to the server. It does not change who receives it at the other end, and Chapter V is concerned with the destination rather than the route.