Per German data protection sources WeTransfer is viewed critically for B2B use due to caching on US servers and the absence of end-to-end encryption. A 2025 terms update referencing AI training was reverted after public criticism. Conbool SecureFiles is the German counterpart: no hard size cap, encrypted, no US cloud, with audit log.
Caching on US servers, CLOUD Act exposureEU hosting, ISO-27001 certified infrastructure
TLS only, no end-to-end encryptionTLS plus optional client-side zero-knowledge encryption
No audit log, no retention managementCentral audit log, GDPR Art. 30, configurable retention
WeTransfer is viewed critically by German data protection sources for B2B use. Conbool relies on EU hosting, end-to-end encryption and a verifiable audit log.
Right for you if:GDPR mandateNo US cloudMade in Germany
100 %
Hosted in the EU
0
US cloud caching
12 mon.
Passwordless for returning recipients
GDPR 30
Audit log per Art. 30
Sender
Recipient
EU region
GDPR DPA
Audit log
SecureFiles · Hand-off
Files travel directly from sender to recipient inside the EU.
Conbool SecureFiles hands files off as a direct line between two endpoints. In zero-knowledge mode the sender's browser encrypts, the server only sees ciphertext. Outlook add-in included, GDPR Art. 28 data processing agreement included.
EU hosting, ISO-27001 certified infrastructure.
End-to-end encryption on demand, TLS in transit always.
GDPR Art. 30 audit log, retention configurable.
WeTransfer Pro vs Conbool, side by side.
Seven points from real business file transfer.
Conbool SecureFiles
WeTransfer Pro
Hosting jurisdiction
EU jurisdiction, ISO 27001
Netherlands with US infrastructure
End-to-end encryption
Optional client-side
No, TLS only
Maximum file size
No hard size cap
20 GB on Pro plan
Audit log GDPR Art. 30
Standard
Limited
Virus scan by default
Built-in malware scan
Not documented
Outlook add-in
Classic, New, Web
Not available
Secure Inbox
Included
File request only
As of 2026. Statements about WeTransfer are based on publicly available terms of service 2024 to 2026, help-center documentation and press coverage.
GDPR and CLOUD Act
Why WeTransfer is viewed critically for B2B use.
Per German data protection sources WeTransfer caches files on US servers. The CLOUD Act allows US authorities to demand data from US providers regardless of storage location. Conbool hosts exclusively in the EU.
Conbool GmbH, German ownership
Independent German company. No US parent, no CLOUD Act exposure.
Hosting exclusively in the EU
Cloudflare EU region and EU storage. No transatlantic transfer by default.
Data processing agreement
GDPR Art. 28 DPA included, Standard Contractual Clauses for sub-processors.
GDPR Art. 30 record
Prepared record of processing activities, downloadable for customers.
Terms-of-service update 2025
What the 2025 terms change triggered.
In early 2025 WeTransfer phrased its terms in a way that potentially allowed uploaded files to train AI systems. After public criticism the clause was reverted. Conbool has a technically guaranteed position: in zero-knowledge mode the server sees no cleartext.
Conbool with no AI training clause
Terms include no training license. Content is not analyzed.
Zero-knowledge as a technical guarantee
Anyone using zero-knowledge mode gives Conbool no access to cleartext, not even theoretically.
Technical guarantees over policy clauses
Conbool grounds data protection in technical guarantees such as zero-knowledge and EU hosting, not in shifting policy text.
Data protection impact assessment
Prepared DPIA templates for Conbool SecureFiles, available to data protection officers.
Beyond simple upload
What Conbool offers beyond a plain upload link.
WeTransfer is essentially an upload link. Conbool adds Outlook integration, Secure Inbox and Entra ID, which makes the difference for everyday employee use.
Outlook add-in
Send straight from Outlook. Classic, New, Web. One click, done.
Secure Inbox
Externals send files to you encrypted, no account required. WeTransfer Receive done GDPR-compliant.
Passwordless retrieval
Returning recipients skip the password for 12 months. Safer than password by email.
Entra ID and Active Directory
Native SSO, group policies, user management. No separate IAM product needed.
FAQ WeTransfer alternative
Is Conbool GDPR compliant?
Yes. Conbool is a German company and runs SecureFiles exclusively in EU data centers on ISO-27001 certified infrastructure. GDPR Art. 28 DPA is included, GDPR Art. 30 record is prepared, and in zero-knowledge mode the server technically sees no cleartext.
How do I switch from WeTransfer to Conbool?
In three steps. First, set up a Conbool account and invite the team, typically one workday. Second, deploy the Outlook add-in centrally via the Microsoft 365 admin center, no end user needs to install anything. Third, update the internal policy: attachments larger than 25 MB go through Conbool, not WeTransfer. The existing WeTransfer Pro license runs out as scheduled.
What does Conbool cost compared to WeTransfer Pro?
WeTransfer Pro is licensed per user with a 20 GB file cap. Conbool is also per user but without a hard cap, with audit log and Secure Inbox. Concrete Conbool pricing is provided on request, depending on headcount and modules.
Is WeTransfer GDPR compliant?
Per multiple German data protection sources, using WeTransfer in a business context is GDPR-critical: files are cached on US servers, end-to-end encryption is missing, and a full Art. 28 GDPR DPA structure is impractical. For occasional private transfers it may be enough, for businesses it is a data protection risk.
What did the 2025 terms change mean?
In early 2025 WeTransfer phrased its terms in a way that potentially allowed uploaded files to train AI systems. After public criticism the clause was removed. For many data protection officers that triggered the search for a systemic alternative.
How large can files be on Conbool?
No hard cap per file, well beyond WeTransfer Pro's 20 GB. Enough for high-resolution video, DICOM datasets or full CAD projects.
Do recipients need an account?
No. The recipient gets an email with a download link, optionally password protected. For returning recipients passwordless retrieval kicks in, the first transfers require a password, the next 12 months don't. No Microsoft account, no OAuth chain, no registration.
Where is the data stored?
In the EU jurisdiction on ISO-27001 certified EU cloud infrastructure. Cloudflare is a US company, but the EU infrastructure is legally separated from the US parent via DPA and Standard Contractual Clauses. For true zero-knowledge enable client-side encryption, then nobody sees cleartext.
Statements about WeTransfer are based on publicly available terms of service 2024 to 2026, help-center documentation, coverage of the 2025 terms update and assessments by German data protection sources. Statements about Conbool are based on its own product documentation and ISO-27001 infrastructure certification.
WeTransfer is a trademark of WeTransfer B.V. Conbool is a trademark of Conbool GmbH. All statements without warranty of continued accuracy.
No US cloud caching. No AI training risk in the terms of service.