
WeTransfer changed its terms in late June 2025 with a clause that looked like it allowed AI training on uploaded files, sparked a backlash and rolled the wording back on 15 July 2025. This guide explains why WeTransfer remains a data protection risk in a business context, what GDPR compliant file transfer actually requires and how Conbool SecureFiles offers an EU hosted alternative.
Die neuesten Beiträge aus unserem Blog.

WeTransfer im Unternehmen: Der AGB-Streit um eine KI-Klausel im Sommer 2025 hat das Datenschutzrisiko sichtbar gemacht. Dieser Beitrag erklärt, warum der Dienst für den Mittelstand heikel bleibt, was…

Mit der Übernahme von Hornetsecurity durch Proofpoint gerät ein bisher deutscher E-Mail-Security-Anbieter unter US-Eigentümerschaft. Dieser Beitrag ordnet den Eigentümerwechsel ein, erklärt die…
A staff member needs to send a 400 megabyte design file to a client. The mailbox rejects the attachment, the deadline is close, and the fastest path is a free consumer upload tool. This everyday scene is how confidential company data ends up on platforms that nobody in IT signed off on. In mid 2025 the habit collided with a very public controversy around WeTransfer, a useful lens on why convenient file sharing and data protection so often pull in opposite directions.
This article looks at what happened with the WeTransfer terms in 2025, why the service remains a GDPR risk in a business context regardless of the eventual rollback, what compliant file transfer requires and how Conbool SecureFiles answers those requirements. It complements our WeTransfer alternative page and the overview of GDPR compliant file transfer with the news context of the 2025 terms dispute.
TL;DR: In late June 2025 WeTransfer updated its terms of service with a licence clause that many users read as permission to train AI models on uploaded files. After a backlash the company said no content is used for AI training and revised the wording on 15 July 2025. The rollback resolved the immediate dispute but not the structural issue: a consumer service can change the rules for your data unilaterally, often stores files outside the EU and leaves the controlling company without a data processing agreement. GDPR compliant transfer needs encryption, EU hosting, a signed agreement and real access control. Conbool SecureFiles delivers these and lets staff send large files straight from Outlook instead of a public consumer link.
At the end of June 2025 WeTransfer rolled out updated terms of service. One clause granted the company a broad licence to use uploaded content, with phrasing that referenced operating, developing and improving the service using machine learning. Many users read it as a licence to feed their files into AI training.
The reaction was swift. Photographers, designers, agencies and journalists, the very groups that rely on the tool to move large creative files, voiced concern on social media and in the press that their unpublished work could be used to train models. WeTransfer responded that the clause was never meant that way, stated plainly that it does not use uploaded content to train AI and does not sell user content, and on 15 July 2025 it revised and simplified the wording.
So the dispute ended with a clarification rather than a confirmed AI training programme, which is fair to the provider. It does not, however, undo the lesson for companies: the terms governing your uploaded data changed overnight, without negotiation, and only shifted back under public pressure. For a one off personal transfer that is an inconvenience. For a company moving client contracts, design assets or personal data, it is a governance problem.
The terms controversy is the headline, but the structural reasons a consumer transfer tool is hard to use compliantly were there before June 2025 and remain after the rollback.
When a company uploads files that contain personal data, it acts as the controller under the GDPR. Whoever stores and processes that data on its behalf is a processor, and Article 28 GDPR requires a data processing agreement, an Auftragsverarbeitungsvertrag, between the two. A standard free or low tier consumer account typically does not come with such an agreement in place, which means a core legal foundation for the transfer is simply missing.
Where the file physically rests matters. Consumer transfer services frequently store data on infrastructure operated under United States jurisdiction. That triggers the rules on international data transfer and exposes the data to foreign access regimes. For sectors with strong confidentiality duties, from law firms to healthcare to public bodies, that uncertainty alone can be disqualifying.
Once a file leaves through a public link, the sending company has little visibility. Who downloaded it, when, and from where? Can the link be revoked? Is the file encrypted at rest, and who holds the keys? The 2025 episode added one more question: what future purpose might the stored content serve if the terms change again? Loss of control is the common thread, and it is precisely what data protection law asks companies to avoid.
Compliant transfer is not a single feature, it is a set of guarantees that keep control of the data with the company. The expectation flows from the state of the art principle in Article 32 GDPR and overlaps with the duties many companies face under the NIS2 directive.
The table below turns the requirements into a side by side comparison between a typical free consumer transfer tool and what an enterprise grade service should provide. Use it as a procurement shortlist.
| Criterion | Typical free consumer tool | Enterprise grade transfer |
|---|---|---|
| Hosting location | Often United States jurisdiction | EU hosting under EU jurisdiction |
| Data processing agreement | Usually not provided | Signed agreement under Article 28 GDPR |
| Encryption at rest | Unclear or operator controlled | Encrypted storage as standard |
| Access control | Public link, hard to revoke | Password, expiry and revocation |
| Audit trail | Limited or none | Records who downloaded what and when |
| Secondary use of content | Governed by changeable terms | Contractually excluded |
| Workflow | Separate website and public link | Integrated into Outlook and Microsoft 365 |
The last row is the one that decides adoption in practice. A solution that is more secure but harder to use loses to the convenient consumer tool every time. The fix is not a policy memo telling staff to stop using free uploaders, it is giving them a secure path that is at least as easy.
Conbool SecureFiles is built around exactly the criteria above. Files are hosted in the EU and stored encrypted, a data processing agreement is part of the business relationship, and every transfer can carry a password, an expiry date and the option to revoke access. Uploaded content is used to deliver the transfer and nothing else, so the question the 2025 terms dispute raised does not apply.
The point that matters most for day to day adoption is the workflow. Instead of sending people to a separate consumer website, SecureFiles lets staff send large files straight from Outlook. When a recipient sends material back, a secure inbox for receiving files keeps that direction controlled too. The secure path becomes the path of least resistance, which is the only reliable way to retire shadow tools.
SecureFiles sits inside the wider Conbool platform, so transfer is not an isolated bolt on. The same gateway runs inbound protection through Conbool MailGuard, so phishing protection and attachment scanning also cover the messages that carry transfer links. For organisations under NIS2 email security duties, consolidating transfer and protection under one EU based vendor simplifies both operations and evidence.
WeTransfer can be used in a privacy aware way, but for processing personal or confidential company data it raises several open questions. A company that uploads such files acts as a controller and needs a data processing agreement, clarity on where data is stored and a guarantee that content is not used for other purposes. The 2025 terms dispute showed that the provider can change these conditions unilaterally, which makes WeTransfer hard to rely on for regulated business use without a dedicated business contract and configuration.
In late June 2025 WeTransfer published updated terms of service that contained a broad licence clause. Many users read it as permission to use uploaded files to train or improve machine learning and AI models. The wording triggered a public backlash on social media and in the press. WeTransfer responded, said the clause was not intended that way and that no content is used to train AI, and on 15 July 2025 it revised and clarified the terms. The episode showed how quickly the basis for handling uploaded data can shift.
A small or mid sized company should choose a transfer service that hosts data in the EU, offers a data processing agreement, encrypts files in transit and at rest, and provides access control with expiry and revocation. A service that integrates with the existing Microsoft 365 mailbox keeps the workflow familiar. Conbool SecureFiles is built for this profile: EU hosting, encrypted storage, link expiry and the option to send large files straight from Outlook instead of a public consumer link.
Key criteria are encryption in transit and at rest, hosting inside the EU under EU jurisdiction, a signed data processing agreement, granular access control with passwords, expiry and revocation, an audit trail of who downloaded what, and a clear statement that uploaded content is never reused for analytics or model training. Together these points satisfy the state of the art expectation under Article 32 GDPR and keep control of the data with the company rather than a third country provider.
Most mailboxes reject attachments above roughly 20 to 35 megabytes, so staff reach for a quick consumer upload tool when a file is too big. That habit moves sensitive data onto an external platform outside the company policy, often without encryption control or a data processing agreement. A managed transfer service that plugs into Outlook removes the temptation by handling large files securely from inside the familiar mail client.
The WeTransfer terms episode of 2025 ended with a clarification, and that is fair to record. What it did not end is the structural mismatch between a consumer file tool and the duties a company carries for the data it moves. A provider that can rewrite the rules overnight, store files under a foreign jurisdiction and operate without a processing agreement is hard to square with the GDPR, no matter how convenient the upload button is. The durable answer is a transfer path that is encrypted, EU hosted, contractually clear and easy enough that staff actually use it.
The next step is yours: see how Conbool SecureFiles compares on the WeTransfer alternative page, and review the requirements in detail under GDPR compliant file transfer.
Further reading: