Skip to content

GDPR and online PDF tools: what is allowed at work, in plain words

By the getPDF team · Published 11 October 2026

The short answer

Uploading a PDF that contains someone else’s personal data to an online converter is “processing” under the GDPR, and the converter becomes a processor working for your employer. Article 28 then expects a contract with that company and sufficient guarantees about security; most people using a free converter at work have neither. A tool that runs entirely on your device sends the file nowhere, so the converter question never arises, although the rest of the GDPR still applies to what you do with the file.

This page explains the rules in plain words; it is not legal advice. For a decision about your own case, ask your data protection officer.

Redact PDFRemoves content, not just a black box. Free, runs on your device.

Is uploading a PDF “processing personal data”?

Almost always, yes, if the PDF names people. The GDPR’s definitions are wide on purpose:

  • Personal data (Article 4(1)) is any information about an identified or identifiable person. A contract with a name, a CV, a payslip, an invoice to a sole trader, a scanned ID: all personal data.
  • Processing (Article 4(2)) is any operation on it, and the list names storage, use, “disclosure by transmission” and erasure. An upload transmits the file, the converter stores it, works on it and later erases it. Each of those is processing.
  • The controller (Article 4(7)) decides why and how the data is processed. When you upload a client’s file at work, that is normally your employer.
  • The processor (Article 4(8)) processes on the controller’s behalf. The converter, doing the conversion you asked for, fits that description.

So the question is not “is a PDF converter allowed?” but “may my employer hand this personal data to this processor?”.

What Article 28 asks before a processor gets the file

Article 28(1) lets a controller use only processors that give “sufficient guarantees” of appropriate technical and organisational measures. Article 28(3) adds that the processing must be governed by a contract or another binding legal act, usually called a data processing agreement. That contract has to set out, among other things, that the processor:

  • acts only on the controller’s documented instructions,
  • binds its staff to confidentiality,
  • applies the security measures of Article 32,
  • deletes or returns the data when the service ends,
  • gives the controller the information needed to check all this.

A free converter you open in a browser tab on a deadline has, in practice, none of this with your employer. Its privacy policy is a promise to the world, not a contract with your company. Some converters do offer one: iLovePDF attaches a data processing agreement to its privacy policy, Smallpdf has one for its Team and Business plans, and PDF24 asks business users of its online tools to conclude one (all checked on 11 October 2026). With such an agreement in place, the question becomes one your company can actually answer.

The 5 questions a data protection officer asks

When someone asks “may we use this tool for client files?”, these are the questions that decide it. The table puts a typical online converter’s answer next to a tool that runs on your device.

Question GDPR article A typical online converter A tool that runs on your device
Is there a data processing agreement? 28(3) Some offer one (iLovePDF, Smallpdf on its team plans, PDF24 for businesses); many free sites do not Not needed for the file: the maker never receives it
Where are the servers, and does data leave the EU? 44 to 46 Stated in the policy, sometimes vaguely; may include non-EU providers The file stays on your device
How long is the file kept? 5(1)(e), 28(3)(g) A deletion promise, often 1 to 2 hours Never stored by anyone but you
What security protects it, and who can access it? 32, 28(3)(b) and (c) Described in the policy; cannot be checked from outside Your own device’s security
What happens if their storage is breached? 33, 34 The processor must tell the controller; with no contract, it may not know who you are No third-party copy to breach

The right column has its own limit, which is the honest part below: the tool removes the transfer, not your other duties.

Why “deleted after 2 hours” does not answer the question

Short retention is good, and Article 5(1)(e) (storage limitation) asks for exactly that. But a deletion window answers only 1 of the 5 questions. During those hours the file sits on a server under a policy your company never agreed to. Backups and logs are rarely described in detail. And a deletion promise says nothing about who could reach the storage before the deletion ran.

That last point is not theoretical. In July 2024, Cybernews researchers found that 2 converter sites, PDF Pro and Help PDF, had left more than 89,000 uploaded files open in cloud storage, among them passports, driving licences and contracts (Cybernews, “Online PDF maker leaks user-uploaded documents”, 11 July 2024: 89,062 files in an Amazon S3 storage bucket left open). When the article was published, the operators had not answered and the files were still exposed.

Under the GDPR, such an event is a personal data breach (Article 4(12): unauthorised disclosure of, or access to, personal data). The duty to report it to the supervisory authority within 72 hours of becoming aware (Article 33), and to tell the people affected when the risk to them is high (Article 34), lies with the controller: the employer whose staff uploaded the files. A processor must tell the controller “without undue delay” (Article 33(2)). A free site with no contract and no customer record has no way to do that.

Transfers outside the EU

Many online tools run on cloud providers in several regions. Under Articles 44 to 46, personal data may leave the EU only to a country with an adequacy decision, or with safeguards such as the Commission’s standard contractual clauses. For the United States, the EU-US Data Privacy Framework (Commission decision of 10 July 2023) covers companies certified under it. The EU General Court dismissed a challenge to it on 3 September 2025 (case T-553/23, Latombe); an appeal to the Court of Justice is pending (C-703/25 P), and on 31 July 2026 the European Data Protection Board wrote to the Commission about a US Supreme Court judgment that affects it (checked on 11 October 2026). The framework stays in force until it is withdrawn or annulled. For a company, that means checking where a tool’s servers are is not a formality.

The skip: a tool that never receives the file

If the conversion runs in your browser and the file is never sent anywhere, the 5 questions above change character. There is no transmission to a converter, no copy on its servers, no retention window, no foreign server, no third-party storage to breach. The GDPR attaches duties to whoever processes the data; a software maker that never receives your data is not processing it for you. No regulator has, as far as we found, published a specific rule for tools that run on the device (checked on 11 October 2026).

The condition is that “runs on your device” is true, and a website saying so is not proof. Check it the way IT would, in under a minute: run the tool once, turn the connection off, run it again. The Wi-Fi off test explains it, with the network panel in every major browser.

Every getPDF tool works this way. The one message the site sends after a job contains the tool id, success or failure, and a duration and size bucket: no file, no file name, nothing about the people in the document. The privacy page explains the architecture.

Try it here, nothing is uploaded

PDF · any size

The honest part

A tool that runs on your device removes the processor question. It does not make what you do compliant.

  • You still need a reason to hold the data (Article 6, lawful basis) and should keep only what the task needs (Article 5(1)(c), data minimisation). Redacting what the recipient does not need is data minimisation in practice.
  • Your own device and accounts must be secure (Article 32 applies to the controller too): a laptop with disk encryption, a Downloads folder you clean up.
  • Sending the result is processing as well. A perfectly redacted contract emailed to the wrong person is still a breach. Send a confidential PDF by email ranks the options.
  • Company rules come first. Your employer may have approved tools, or banned browser tools altogether. Online PDF tools at work has a policy that both sides can work with.

Article references are to Regulation (EU) 2016/679, as published on EUR-Lex; the summaries here are ours and simplified.

Questions

Is it a GDPR breach to upload a client's PDF to a free converter?

Not automatically. It is processing personal data, and the converter becomes your processor, which under Article 28 normally needs a contract and sufficient guarantees. Without those, the upload is hard to justify. Whether a specific case is a breach is a question for your data protection officer or a lawyer.

Does a converter's 2-hour deletion make it GDPR compliant?

No, not by itself. Short retention helps with storage limitation (Article 5), but the transfer, the contract, the server location and the security still have to be in order.

Does the GDPR apply to a tool that runs on my device?

The GDPR applies to what you do with the data, whatever the tool. But if the tool sends nothing to its maker, the maker never receives the data, so there is no processor relationship to set up. Regulators have not written a specific rule for such tools.

What should I do if I already uploaded client files to a converter?

Tell your data protection officer or whoever handles data protection where you work, with the date, the site and what the files contained. They decide whether anything needs reporting; Article 33 gives the employer 72 hours from becoming aware of a breach.

The tools for this job