Skip to content

What does GDPR mean for password sharing?

P
PassTransfer
Published July 5, 20234 min read

GDPR and access to personal data

The General Data Protection Regulation (GDPR) requires organisations that process personal data to implement appropriate technical and organisational measures to protect it. Article 32 specifically requires measures to ensure ongoing confidentiality, integrity, and availability of processing systems — which includes access controls.

Passwords and credentials that grant access to systems containing personal data are, by extension, within scope of GDPR's security requirements. If you handle those credentials carelessly, you're potentially failing to meet the security standard GDPR requires.

What does "appropriate technical measures" mean for credentials?

GDPR is not prescriptive about specific technologies or methods. It requires that the measures be appropriate to the risk. For credential management, regulators and security frameworks generally expect:

  • Access controls that limit who can access personal data
  • Secure handling of credentials, including how they are transmitted
  • Regular rotation of credentials, especially after personnel changes
  • Documentation of access control measures

Sending a database password or CMS login in a plain email is difficult to characterise as an "appropriate technical measure." The transmission is not end-to-end encrypted, the credential persists in multiple inboxes, and there is no mechanism to ensure it was not intercepted.

The data breach connection

A significant portion of data breaches trace back to compromised credentials. Under GDPR, a data breach must be reported to the supervisory authority within 72 hours if it is likely to result in a risk to individuals' rights and freedoms. If a credential was shared carelessly and subsequently compromised, leading to unauthorised access to personal data, your credential sharing practice becomes part of the breach narrative — and part of the regulator's assessment of whether you met your security obligations.

Demonstrating that credentials were shared via encrypted one-time links, with automatic expiry and no persistent copies, is meaningfully better than explaining that you used email.

Practical GDPR-aligned credential sharing practices

Use encrypted transmission Credentials that grant access to personal data should be transmitted in a way that is encrypted both in transit and at rest. A one-time encrypted link satisfies this requirement; a plain email does not.

Apply the minimum access principle Only share credentials with people who genuinely need access. Where possible, create individual accounts with limited permissions rather than sharing high-privilege credentials.

Document access grants and revocations Maintain a record of who has been granted access to systems containing personal data, and when that access was granted or removed. This supports your ability to demonstrate compliance if challenged.

Rotate credentials on personnel changes When someone who had access to personal data systems leaves the organisation, rotate the relevant credentials immediately. Our offboarding checklist for shared passwords covers this in detail.

Use tools with appropriate security properties PassTransfer encrypts passwords at rest, delivers them once, and deletes them immediately after retrieval. This aligns with GDPR's requirements for appropriate security measures far better than email-based sharing.

A note on processors and sub-processors

If you share credentials with third parties — contractors, IT support firms, partner agencies — who process personal data on your behalf, GDPR requires you to have data processing agreements in place with them. Secure credential handling should be part of the contractual expectation, not an afterthought.

Conclusion

GDPR doesn't specifically mandate a particular tool or method for credential sharing, but it does require appropriate security. In practice, that means treating passwords that grant access to personal data with the same care as the data itself — which means not putting them in plain emails or chat messages. An encrypted one-time link is a straightforward, auditable approach that aligns with what regulators expect. For the full picture of the requirements, see our guide to GDPR and password sharing.

Try PassTransfer for free →

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password