Four areas where consumer file sharing tools cause problems for organisations – and how a secure file transfer service addresses them.
Key takeaways
- Consumer file sharing solutions are generally designed for individuals. Free accounts and links that anyone can open reflect that.
- Four areas commonly cause problems for organisational use: data residency, control, auditability and governance. Each problem is examined below, followed by how a purpose built secure file transfer service such as AMS File Transfer is designed to address it. AMS File Transfer is UK hosted, ISO 27001 certified, Cyber Essentials certified and NHS DSPT compliant.
- Under UK GDPR, an organisation is still responsible for the personal data it sends through a third party service, including where that service holds it. A UK hosted service with a stated data location makes that responsibility easier to meet.
Most people already have an established method of sending files. A consumer file sharing solution takes a minute to use, needs no set up and is usually free. These solutions are convenient and are typically designed for personal use. However, problems arise when the same services are used to send personal or confidential business data from an organisation.
The four areas are set out below, followed by a comparison of the common ways files leave an organisation and answers to some of the most common questions.
Unknown residency
Many consumer file sharing platforms provide limited visibility over where data is stored or processed. Some publish a default storage region, and it is not always in the UK. Others state that the location depends on the plan, or that data may be transferred internationally. For organisations handling sensitive information, this can create uncertainty around data sovereignty, governance requirements and regulatory obligations.
Under UK GDPR, sending personal information to an organisation outside the UK, or making it accessible to one, is a restricted transfer and must be covered by a recognised mechanism. An organisation that uses a third party to process personal data must also have a written contract with that processor. A free consumer account is typically governed by standard terms written for individuals, and an organisation that does not know where a service holds its data cannot readily establish whether either requirement is met.
Limited control
Consumer focused solutions are often designed for convenience rather than governance. This can restrict an organisation’s ability to control access, manage permissions and enforce security policies across users and external recipients.
In practice, this means a link that can be forwarded to anyone who receives it, a download that cannot be prevented once the file has been received, and a retention period set by the service rather than by the organisation. Free tiers commonly delete transfers after a fixed number of days, which may be too short for an open matter or too long for a file that should already have been removed.
Poor auditability
When handling sensitive information, visibility matters. Limited auditing and reporting capabilities can make it difficult to track file activity and demonstrate compliance.
A consumer service may confirm that a file was downloaded. It will not usually show who accessed it or whether it was sent on, and a transfer made from a personal account may leave the organisation with no record at all. The ICO expects organisations to keep a log of user access to systems holding personal information, and requires every personal data breach, including a file sent to the wrong recipient, to be recorded whether or not it is reported. A transfer with no record is difficult to investigate and even harder to evidence.
Governance gaps
Without appropriate controls and oversight, organisations may struggle to meet internal governance standards and compliance requirements. This can increase operational risk and reduce confidence when sharing sensitive information with colleagues, customers and third parties.
The National Cyber Security Centre describes staff storing enterprise data in personal cloud accounts as a form of shadow IT, and notes that risk cannot be managed for assets the organisation does not know about. For regulated organisations the gap is specific: any organisation with access to NHS patient data must use the Data Security and Protection Toolkit to provide assurance that personal information is handled correctly, and a disclosure made through a consumer service falls outside the systems that assurance was based on. The same applies to a council or a law firm working to its own information security policy.
How the common options compare
Sensitive files usually leave an organisation in one of three ways: as an email attachment, through a consumer file sharing service, or through a secure file transfer service procured by the organisation. The table below compares them to the four areas discussed.
| Email attachment | Consumer file sharing service | Secure file transfer service | |
| Data residency | Depends on the email provider and on every recipient’s mail system. | Set by the service. Often outside the UK by default, or dependent on plan. | Specified by the provider and contractually agreed. AMS File Transfer: UK based cloud infrastructure, Microsoft Azure UK datacentres. |
| Control after sending | None. The file is a copy in the recipient’s mailbox. | Limited. Expiry date set by the service. | Configurable. Recipient authentication, file expiry rules and optional restrictions on downloading, printing or forwarding. |
| Audit trail | Sent items folder only. No record of access. | Limited. Typically at most a download notification. | Full audit trail end to end; delivery tracking shows when files are received, accessed and downloaded. |
| Governance | Covered by the organisation’s email policy, but attachment size limits push staff to workarounds. | Usually outside any assessed system or processor contract. | Assessed once and applied to every transfer. Certifications are published by the provider. |
What a business grade alternative provides
A purpose built secure file transfer service is designed to address the four areas above.
AMS File Transfer stores files within UK based cloud infrastructure in Microsoft Azure UK datacentres, with each customer’s information held in a dedicated storage account and database.
Transfers are protected with 256 bit AES encryption and only the intended recipient can access shared files. Optional controls such as Digital Rights Management can limit downloading, printing or forwarding.
Automated rules help manage file expiry and deletion. A full audit trail records the process end to end, and delivery tracking shows when files have been received, accessed and downloaded.
AMS is ISO 27001 certified and Cyber Essentials certified, and is listed on the NHS Data Security and Protection Toolkit register.
FAQ
Where is my data stored if I use a consumer file sharing service?
It depends on the service and the plan. Some publish a default region, commonly outside the UK, with UK or EU storage available only on business plans. Others do not state a location in their consumer terms. If the location cannot be established, the organisation cannot establish whether a transfer is taking place within GDPR requirements.
What are the alternatives to sending sensitive documents as email attachments?
The two main alternatives are a consumer file sharing service and a secure file transfer service. Both remove the common problem of hitting file size limits. Only a secure file transfer service gives the organisation control over data residency, recipient authentication, expiry and an audit trail.
What should an organisation do if staff are already using consumer tools for work files?
Establish which services are in use, since the NCSC describes this as shadow IT and notes that risk cannot be managed for assets the organisation does not know about. Then provide an alternative that is more convenient than the tool it replaces.
Is it safe to use a consumer file sharing service to share patient data?
Not without assessment. Any organisation with access to NHS patient data must use the Data Security and Protection Toolkit to provide assurance that personal information is handled correctly. A consumer service used from a personal account sits outside that assessment and usually outside the UK. AMS File Transfer is used across NHS and healthcare environments for the secure handling of patient identifiable data, and is NHS DSPT compliant.
How can an NHS trust send patient records securely to external organisations such as solicitors or insurers?
Through a secure file transfer service assessed against the trust’s information governance requirements, with the recipient authenticated, the file encrypted, an expiry applied and every access recorded. AMS File Transfer is used across NHS and healthcare environments for the secure handling of patient identifiable and highly sensitive data.
Keep reading: Keeping control of sensitive data after you hit send.
If your organisation is currently relying on consumer tools to move sensitive files, describe it to us and our sales team will advise on the right fit for your requirements.
Was this article helpful?
Thanks — your feedback helps us decide what to write next.