Skip to content

How to choose a GDPR-compliant password sharing tool

P
PassTransfer
Published June 17, 20263 min read

Why password sharing is a GDPR concern

GDPR applies to the processing of personal data. Passwords themselves are not personal data, but they frequently provide access to systems that contain personal data. A CMS login, a hosting control panel, a CRM — these grant access to customer records, user data, and other personal information that falls under GDPR protection.

Sharing credentials carelessly — via email, in plain text chat messages, in shared documents — creates persistent copies of access credentials in uncontrolled locations. If any of those locations is later breached, the attacker gains access to systems containing personal data. Under GDPR, this could constitute a personal data breach requiring notification to the relevant supervisory authority.

Article 32 of GDPR requires organizations to implement "appropriate technical and organisational measures" to ensure a level of security appropriate to the risk. Sending credentials via unencrypted email is difficult to characterize as an appropriate technical measure. For a broader look at these obligations, see our overview of GDPR and password sharing.

The key GDPR criteria for a password sharing tool

When evaluating a tool, assess it against these criteria:

1. Data location

Where is the tool's infrastructure located? Tools hosted within the EU/EEA are the simplest from a GDPR perspective — no cross-border data transfer issues arise. Tools hosted outside the EU (US, for example) require either a Data Processing Agreement that includes Standard Contractual Clauses or another lawful transfer mechanism.

What to look for: EU or EEA hosting. A clear data processing addendum (DPA) if you need a formal agreement.

2. Data retention

How long does the tool store the secrets you share? Secrets that persist indefinitely are a liability. GDPR's data minimization principle requires that personal data (including data that provides access to personal data) is not retained longer than necessary.

What to look for: Secrets deleted immediately after retrieval. Unopened links deleted after expiry. No long-term storage of credential content.

3. Encryption

How is the data encrypted at rest and in transit?

What to look for: HTTPS (TLS) for all data in transit. Strong encryption at rest (AES or equivalent). Ideally, no plain text copies stored at any point.

4. Access controls and logging

Can the tool demonstrate who accessed what credential and when? In the event of a breach investigation, this information is valuable.

What to look for: Access confirmation (whether a link was opened), optional logging of share events.

5. Subprocessors

Does the tool use third-party subprocessors who also handle your data? Cloud hosting providers, email delivery services, analytics tools — all of these may process data on your behalf.

What to look for: Transparent subprocessor list. All subprocessors within GDPR-compliant jurisdictions or covered by appropriate agreements.

Checklist for evaluating a tool

  • [ ] Hosted in EU/EEA, or valid SCCs in place for non-EU hosting
  • [ ] Secrets deleted after retrieval (not stored persistently)
  • [ ] Unopened links expire and are deleted
  • [ ] Encryption at rest and in transit
  • [ ] No plain text storage of credential content
  • [ ] Clear privacy policy covering data processing
  • [ ] DPA available if required by your compliance framework

For a broader evaluation beyond GDPR, see the ultimate checklist for choosing a password sharing tool.

PassTransfer's GDPR position

PassTransfer is hosted in the EU. Secrets are encrypted in the browser with AES-GCM (end-to-end) and deleted immediately after retrieval. Unopened links expire automatically. No credential content persists in the system after delivery.

For businesses operating under GDPR, this addresses the key technical requirements for secure credential sharing. If your organization requires a formal DPA, contact PassTransfer's team to arrange this.

Learn more about PassTransfer's security →

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password