Skip to main content
WeTransfer logo

WeTransfer

GDPR evidence

wetransfer.comCloud storageLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

WeTransfer and GDPR

CertReports found no public GDPR evidence for WeTransfer as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
30 Mar 2020
Scope
WeTransfer processes data of its users. WeTransfer collects, processes or hosts personal information provided by users: - Contact information: your name and your email address or the email address of the recipient(s). - Information about yourself: age, gender, city. - Preferences: for example language settings or interests. - Content and metadata: you may choose to upload or create Content which contains all sorts of personal information about you and others. Such Content also contains a filename, size and filetype. - Personal messages: the ones you send to people along with sharing your files. Personal information we collect by automated means: - Browser information: type of browser, language settings, country and timezone. - Cookie or web beacon information: cookie IDs and settings and other personal information received through cookies, web beacons or pixel tags. - Device information: the type of device, hardware model and operating system. - Identification details: unique identifiers such as an IDFA (for iOS), MAC address or a UserID. - Network information: IP-addresses and mobile network information. - Location data: data on your geo-location. - Service usage: information regarding the way you interact with our Services, websites and mobile apps. Personal information we receive from partners: - Integration information: you can choose to integrate some of our Services with your account, such as Slack, in order to provide you with a rich messaging functionality. - Marketing information: some partners may provide additional (aggregated) information, for instance through their Software Developer Kits (SDKs). - Legal Information: when law enforcement agencies or courts order us to take down Content, we may initially receive personal information about you and your behaviour. Purposes for processing personal data: Service: the most important reason for using personal information is, of course, to offer our users our Services. Support: we provide a wide range of support services to help out users, for instance when they need technical assistance. Account & billing: creating and upholding personal accounts. Safety, integrity & security: WeTransfer follows up on abuse reports, NTD/DMCA reports, fraud investigations and could investigate your compliance with our of our Terms of Services and/or API Terms of Use. Furthermore, we detect & block Child Sexual Abuse Imagery (CSAI). Improvement & development: we evaluate the use of our Services to improve our Services, fix bugs, develop new products and services. We do this either by market research or by performing analyses. Marketing, advertisement & communication: we use personal information for marketing and (interest based) advertising for instance by using SDKs or cookies, as well as communication. Legal: in so far as necessary, we might use personal information to defend WeTransfer in legal proceedings. Legal grounds are contractual obligations with users, legal obligations, consent and/or legitimate interest.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026WeTransfer Corp: Inactive
Live pagesha256 113c1be6ff
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is WeTransfer GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Cloud storage category) whose GDPR row is verified or vendor-stated, ranked by similarity.