To share personal data securely under UK GDPR, you need a lawful basis for the sharing, appropriate security around how the data moves, and a record of who accessed it. Under the UK GDPR and the Data Protection Act 2018, "personal data" is any information relating to an identified or identifiable living person, which includes names, contact details, salary figures and bank details. A narrower set, "special-category data", covers more sensitive information such as health, ethnicity, religious beliefs, sexual orientation and biometric data, and it carries extra conditions before you can process it. Sharing personal data safely is less about the file format and more about controlling access, proving who saw what, and keeping the data somewhere you can account for. This guide explains the categories, the practical steps and how 99 Data Rooms supports compliant sharing. It is general information, not legal advice.
Most teams share personal data every week without thinking of it as a data protection event: an HR file to a payroll bureau, a client list to an accountant, employee records to an adviser. The obligations apply whether or not you notice them, so it is worth getting the basics right.
Personal data vs special-category data: the distinction that matters
The single most common mistake is confusing "sensitive" in the everyday sense with "special category" in the legal sense. They are not the same thing, and the difference changes what you are allowed to do.
Personal data, as the Information Commissioner's Office (ICO) sets out, is any information relating to an identified or identifiable living individual. That is a wide net. It includes obvious identifiers like names and addresses, but also things people often feel are "sensitive" without being special category. Salary is the classic example: a person's pay is unquestionably personal data, and it feels private, but it is not on its own special-category data. The same goes for bank account details, national insurance numbers and performance reviews. They are personal data, they deserve care, but they do not attract the extra special-category conditions.
Special-category data is a specific, closed list under the UK GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, data concerning health, and data concerning a person's sex life or sexual orientation. This data attracts stricter treatment, because misuse can cause more serious harm, so you generally need both a lawful basis and a separate condition before you can process it.
Getting this right matters practically. If you treat every HR document as special category, you over-engineer routine sharing and slow yourself down. If you treat health information as ordinary personal data, you under-protect it. Salary belongs in the first bucket, an occupational health report in the second. Our guide on the best ways to share HR and salary documents in the UK works through the everyday HR case in more detail.
Step one: establish a lawful basis before you share
Under UK GDPR you need a lawful basis for processing personal data, and sharing is processing. The ICO lists six: consent, contract, legal obligation, vital interests, public task and legitimate interests. For most business sharing, the relevant bases are contract (for example, sending payroll data to a bureau that runs payroll under your contract), legal obligation (for example, providing records to a regulator), or legitimate interests (for example, sharing a client list with your accountant to prepare accounts).
For special-category data you need one of those bases plus an additional Article 9 condition, such as explicit consent or a condition relating to employment, social security or health. This is why the personal vs special-category distinction is not academic: it directly changes what paperwork and justification you need before the data leaves your control.
You do not usually need to over-think this for routine sharing, but you should be able to say, in a sentence, why you are lawfully allowed to share. "We share salary data with our payroll provider to perform the employment contract" is a clear, defensible basis. "We emailed it because someone asked" is not.
Step two: control how the data actually moves
A lawful basis is necessary but not sufficient. UK GDPR also requires appropriate technical and organisational security. This is where most real-world breaches happen, and it is almost always a sharing-method problem rather than a legal one.
Email is the usual culprit. An attachment is copied to every server it passes through, can be forwarded to anyone, cannot be recalled, and gives you no record of who opened it. That is a poor fit for personal data and an outright liability for special-category data. Our piece on UK GDPR and document sharing covers why the delivery mechanism is itself part of your compliance posture, and why an email attachment is a weak default for anything sensitive.
Better practice is controlled sharing: send a link rather than a file, require the recipient to verify who they are before they see anything, limit access to named people, keep a record of who opened the document, and be able to withdraw access when the purpose is done. This is not gold-plating, it is the practical expression of "appropriate security". It also supports data minimisation and storage limitation, because you are sharing a view of a document rather than scattering permanent copies.
Where the data sits geographically matters too. International transfers of personal data carry their own UK GDPR rules, so keeping data hosted in the UK removes a whole category of transfer questions. Our explainer on data residency and why UK hosting matters covers the point.
Step three: keep a record and a data processing agreement
Accountability is a core UK GDPR principle: you must be able to demonstrate compliance, not just assert it. Two things help.
First, a record of access. If you can show exactly who opened a document, when, and whether they were verified, you can answer a subject access request or a regulator's question with evidence rather than guesswork. A permanent audit trail turns "we think only the right people saw it" into a defensible fact.
Second, where you use a third party to process personal data on your behalf, a data processing agreement (DPA) is generally required under Article 28. This is the contract that binds your processor to handle the data only on your instructions and with appropriate security. Our guide on what a data processing agreement is explains when you need one and what it should contain. Accountants, in particular, sit at the centre of a lot of personal data, and our roundup of secure document sharing for accountants covers that flow.
How 99 Data Rooms supports compliant sharing
99 Data Rooms is built around exactly the controls UK GDPR expects. It is UK-hosted in London with data resident in the UK, which keeps international-transfer questions off your plate, and data is encrypted with AES-256 at rest and in transit over TLS 1.2 or higher. You can see the full picture on the security and compliance page.
Instead of emailing a file, you share a tracked, revocable link. Before anyone sees the data you can gate access behind a verified email and a one-time code, and on the Business tier you can require an NDA first, so only the named, verified recipient gets in. As they view, page-by-page analytics record who opened the document and give you the access record accountability calls for, with a clear split between a raw visit and a verified viewer. A 24-month audit trail keeps that history. If the purpose ends or you shared with the wrong person, you revoke access in one click, which is the recall that email can never offer. A DPA is available on request for teams that need one. None of this makes you compliant on its own, compliance is about your basis and your processes, but it gives you the technical controls to share personal data without turning every transfer into a risk.
Share personal data with confidence, for free
You can share personal data through verified, tracked, revocable links that stay hosted in the UK, all inside 99 Data Rooms. The free tier gives you three rooms and twenty-five active links forever, with no card required, and gating and watermarking unlock on Business. Start for free, or read the security and compliance page to see how UK hosting, encryption and audit trails fit together. The wider platform is in beta and improving fast, but the controlled-sharing basics are in place today. This is general information, not legal advice: verify anything critical with a qualified adviser.
Sources
- Definition of personal data and special-category data, lawful bases and Article 9 conditions: Information Commissioner's Office, UK GDPR guidance and resources, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
- Data Protection Act 2018: https://www.legislation.gov.uk/ukpga/2018/12/contents
Is salary special-category data under UK GDPR?
No. Salary is personal data, and it deserves care, but it is not on the closed list of special-category data, which covers things like health, ethnicity, religious beliefs and sexual orientation. This distinction matters because special-category data needs an extra condition before processing. This is general information, not legal advice.
Do I need consent to share personal data?
Not necessarily. Consent is only one of six lawful bases under UK GDPR. Contract, legal obligation and legitimate interests often apply to business sharing, for example sending payroll data to a bureau under your contract. Special-category data needs an additional condition on top of the lawful basis.
Is emailing personal data a UK GDPR breach?
Emailing is not automatically a breach, but it is a weak security choice: attachments cannot be recalled, can be forwarded, and leave no access record. UK GDPR requires appropriate security, and controlled link sharing is a much better fit, especially for sensitive information. See our guide on UK GDPR and document sharing.
When do I need a data processing agreement?
Generally whenever a third party processes personal data on your behalf, such as a payroll provider or an outsourced service. Our guide on what a DPA is explains the detail. 99 Data Rooms provides a DPA on request.
Does hosting location matter for UK GDPR?
Yes. International transfers of personal data carry extra rules, so keeping data hosted in the UK avoids a whole category of transfer questions. 99 Data Rooms is UK-hosted in London with UK data residency; see data residency explained.
Can I prove who accessed a shared document?
With controlled sharing, yes. 99 Data Rooms records who opened each document and whether they were verified, backed by a 24-month audit trail, which supports the accountability principle far better than an emailed attachment.