GDPR document sharing sounds like a compliance headache, but the core idea is simple: whenever a document you share contains personal data, UK GDPR and the Data Protection Act 2018 place duties on you about how that data is handled, secured and disclosed. Personal data means anything that identifies a living individual, a name, an email, a salary, a National Insurance number, so far more of your everyday documents are in scope than people expect. Contracts, offer letters, client accounts, cap tables and investor lists routinely carry it. This guide explains, in plain English, what UK GDPR means for the way you share documents, the principles that actually matter in practice, and how a controlled sharing tool helps you meet them. It is general information, not legal advice.
The good news is that GDPR does not forbid sharing documents that contain personal data. It asks you to do it thoughtfully: share the right data with the right people, keep it secure, and be able to show what you did. The rest of this guide unpacks what that looks like when you are actually sending a file to a client, an investor or a colleague, and the Information Commissioner's Office guidance is the authoritative UK reference behind all of it.
What counts as personal data in a document
The first step is recognising when GDPR is even engaged, and the honest answer is: more often than you think. Under UK GDPR, personal data is any information relating to an identified or identifiable living person. In a business document that includes obvious fields such as names, home and email addresses, phone numbers and dates of birth, but also less obvious ones: an employee's salary in an offer letter, a director's details in board papers, a customer list, or a founder's shareholding in a cap table. If a document lets you single out a specific person, it contains personal data.
Some data is treated as more sensitive still. Special category data, which includes information about health, ethnicity, religion, sexual orientation, trade union membership and biometrics, attracts stricter conditions before you can process or share it. HR files and certain client records often contain it. If your documents include special category data, the bar for lawful, secure handling is higher, and the sharing method matters even more. We cover the practical side of that in how to share sensitive personal data under UK GDPR.
The practical takeaway: before you share, ask whether the document identifies anyone. If it does, GDPR applies, and the way you send it is no longer a matter of convenience alone.
The principles that actually matter when sharing
UK GDPR is built on a set of data protection principles. You do not need to recite them, but a few translate directly into how you should share a document.
Data minimisation and purpose limitation. Share only the personal data the recipient actually needs, for a clear purpose. If an investor needs to see revenue, they may not need the full customer list with names attached. Redacting or excluding what is not needed is not just tidy, it is a GDPR principle in action. A controlled room helps here because you can share specific documents with specific people rather than handing over a whole folder.
Security, or "integrity and confidentiality". This is the principle most relevant to sharing. You must protect personal data with appropriate technical and organisational measures against unauthorised access or loss. Emailing a spreadsheet of staff salaries as an open attachment is hard to square with this: once sent, it is copied, forwardable and beyond your control, which is why we call the email attachment the riskiest way to send a sensitive document. Sharing the same file through a gated, encrypted, revocable link is far easier to justify. This is where the choice of tool becomes a compliance choice, and our security and compliance page sets out the measures 99 Data Rooms applies.
Accountability. UK GDPR expects you not only to comply but to be able to demonstrate it. That means keeping records of who accessed what and when. An audit trail that shows a document was shared only with named, verified recipients, and can be revoked, is exactly the kind of evidence accountability calls for.
Storage limitation. Do not keep personal data, or leave access to it open, for longer than necessary. A share link that stays live forever quietly undermines this. Being able to expire and revoke links is a genuine data protection benefit, not just a convenience.
Roles: are you a controller or a processor?
A point that confuses many small businesses is the distinction between a data controller and a data processor, and it shapes your obligations. A controller decides why and how personal data is processed. If you are a company sharing your own employee or customer data, you are typically the controller. A processor handles personal data on a controller's behalf, following their instructions. A tool that stores and transmits your documents may act as a processor for you.
Why this matters for document sharing: when you use a third-party tool to handle documents containing personal data, that provider is usually your processor, and UK GDPR requires a written contract between controller and processor, commonly called a Data Processing Agreement. It sets out what the processor may do with the data, the security they must apply, and what happens when the relationship ends. If you are handling personal data through any sharing platform, you should have one in place. We explain the document itself in what is a Data Processing Agreement (DPA), and 99 Data Rooms provides a DPA on request.
Where your provider stores the data also matters, because international transfers of personal data carry their own conditions under UK GDPR. Keeping personal data hosted in the UK removes a whole category of transfer complexity, which is one practical reason UK-hosted matters, a point we develop in data residency explained. For regulated professions in particular, such as accountants handling client financial data, these choices are not optional niceties, as we discuss in our guide to secure document sharing for accountants.
How 99 Data Rooms supports GDPR-conscious sharing
99 Data Rooms is not a substitute for your own GDPR compliance, and no tool is. What it does is make the security, accountability and storage-limitation principles far easier to satisfy in practice. Documents are UK-hosted in London with data resident in the UK, encrypted with AES-256 at rest and TLS 1.2 or above in transit, and the platform uses no third-party viewer trackers, so viewer data is not leaked to advertising networks. A DPA is available on request, which supports the controller-processor requirement.
The sharing controls map cleanly onto the principles. You gate access so only a verified email plus a one-time code opens a document, which satisfies the "right people" side of security and gives you named recipients rather than an anonymous link. You share a tracked, revocable link rather than an attachment, so personal data does not escape into inboxes you cannot see, and you can honour storage limitation by expiring or revoking access when it is no longer needed. Page-by-page analytics and a 24-month audit trail give you the records that accountability expects, showing who accessed what and when. Documents can even be drafted from vetted England and Wales clauses first, using the AI Legal Drafting feature that assembles vetted clauses and never invents them. None of this makes you compliant on its own, but it turns the hardest parts of GDPR document sharing, security and evidence, into the default rather than an afterthought.
Share personal data the careful way, free
GDPR does not stop you sharing documents that contain personal data; it asks you to do it securely and accountably. 99 Data Rooms makes that the default, with UK hosting, encryption, gated access, revocable links and an audit trail, plus a DPA on request. The free tier is a real tier, not a trial: three rooms, twenty-five active links, forever, no card required. Start for free, share a document the careful way, and keep the records compliance expects. The platform is in beta and improving fast. Remember this is general information, not legal advice: verify anything critical with a qualified adviser.
Sources
- UK GDPR duties, personal data, special category data, and the controller/processor relationship: Information Commissioner's Office, UK GDPR guidance and resources, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
- The statute that sits alongside UK GDPR: Data Protection Act 2018, https://www.legislation.gov.uk/ukpga/2018/12/contents
Does UK GDPR apply to every document I share?
Only to documents containing personal data, meaning information that identifies a living individual. That covers far more than you might expect: names, emails, salaries, cap tables, client lists and board papers frequently qualify. If a document identifies someone, UK GDPR and the DPA 2018 apply to how you share it. This is general information, not legal advice.
Is emailing a document with personal data a GDPR breach?
Not automatically, but it is hard to reconcile with the security principle when the data is sensitive, because an attachment is copied and forwardable the moment it is sent and cannot be recalled. Sharing through a gated, encrypted, revocable link is far easier to justify as an appropriate technical measure.
Do I need a Data Processing Agreement with my sharing tool?
If the tool processes personal data on your behalf, UK GDPR generally requires a written contract between you (the controller) and the provider (the processor). That is what a DPA is. We explain it in what is a Data Processing Agreement, and 99 Data Rooms provides one on request.
What is special category data and why does it matter?
Special category data includes health, ethnicity, religion, sexual orientation and biometric information, and it attracts stricter conditions before you can process or share it. HR and some client files often contain it, so the sharing method matters even more. See how to share sensitive personal data under UK GDPR.
Does it matter where my documents are hosted?
Yes. International transfers of personal data carry extra conditions under UK GDPR, so keeping data hosted in the UK removes a layer of complexity. We cover this in data residency explained. 99 Data Rooms is UK-hosted in London with data resident in the UK.