A corporate alternative to WeTransfer is an encrypted sending channel with expiry, recipient verification, a download log and revocation. You need one because the free plan caps you at 3 GB and deletes files after 3 days, and because Article 32 of the GDPR requires encryption and traceability when what you are sending is personal data.
Why your team uses it even though it is banned
Because the official channel runs out of road exactly where the work starts. These are the real ceilings anyone who has to send something bigger than a PDF runs into:
| Channel | Limit | What happens in practice |
|---|---|---|
| Gmail attachment | 25 MB per message | A drawing, a short video or ten high-resolution photos already will not fit. |
| Exchange Online | 35 MB by default (the admin can set anything from 1 to 150 MB) | Mail encoding adds roughly a third to the size, so a file that "fitted" bounces anyway. |
| Free WeTransfer | 10 transfers or 3 GB per rolling 30 days; available for 3 days | It works first time and needs no account. That is why it wins. |
| The in-house FTP | No practical limit | You have to request an account, explain to the client how to log in, and wait. Nobody uses it when they are in a hurry. |
It is the same pattern we already saw with artificial intelligence: when the approved tool does not solve the task, an unapproved one appears. We covered it in shadow AI at work, and with files it behaves in exactly the same way. The conclusion is the same too: banning without offering an alternative does not remove the usage, it only removes your visibility of it.
What you are really exposed to (it is not the file)
The risk is not that the file travels: it is that you lose the answers to the questions you will be asked afterwards. Four concrete consequences:
- You do not know who opened it. The link circulates through forwarded emails and chat groups. If it ends up where it should not, you have no way of knowing and no way of cutting it off.
- You cannot revoke. Once it is sent, it is sent. The most common and most expensive mistake is the wrong recipient, and the only defence against that is being able to switch the link off.
- You do not control retention. Neither when it is genuinely deleted, nor whether copies exist. When someone exercises their right to erasure, you cannot answer for what you cannot see.
- There is no contract behind it. If the account belongs to the employee personally, your company is having a third party process data with no processor agreement and no guarantees about where it is hosted.
And this is not a theoretical risk. The AEPD, the Spanish supervisory authority, received 2,765 personal data breach notifications in Spain in 2025, 80% of them from the private sector, and lists sending information to the wrong recipient among the most frequent causes. In other words: the typical breach is not caused by a sophisticated attacker, it is caused by autocomplete in the "To" field.
If the honest answer is no, that is the hole. Bring your three most common transfers (documentation to a client, a delivery to a supplier, intake of case files) and in 20 minutes we build the channel with expiry, an audit log and an intake inbox.
What the rules require about how information leaves the company
No rule says "do not use WeTransfer". What they do say is which measures you have to be able to evidence, and that is precisely where a consumer service runs out of answers:
| Rule | What it requires | What you have to be able to show |
|---|---|---|
| GDPR, Art. 32 | Technical and organisational measures appropriate to the risk, expressly naming encryption and the ability to ensure the ongoing confidentiality, integrity and availability of processing systems. | That transfers go out encrypted and that you can limit who gets access. |
| NIS2, Art. 21 | Risk-management measures that include policies on cryptography and encryption, supply chain security and the use of secure communications. | The channel's policy and the control you exercise over the providers involved. |
| Public-sector security frameworks (in Spain, the ENS, RD 311/2022) | Protection of communications and of information, with access control and traceability, for anyone working with the public sector. | The access log and segregation by role. |
| DORA | For financial entities: protect data in transit and at rest and govern ICT third-party providers. | A contract with the channel provider and a record of the information that leaves. |
If you are in scope of NIS2, the channel files leave through is part of the perimeter you have to govern, and any incident arising from it falls under the notification deadlines we explain in notifying a NIS2 incident at 24 hours, 72 hours and one month.
The ten requirements of a corporate channel
This is the list you can score any candidate against, including the paid plan of the service you already use. If it fails the first four, it is not a corporate alternative:
- Encryption in transit and at rest, with the data hosted where you decide and never leaving the European Economic Area unless you authorise it.
- Expiry and a download limit per transfer, not a fixed policy set by the provider.
- Recipient verification: a password or a one-time code, so that the link is worthless if it gets forwarded.
- Immediate revocation of a transfer that has already gone out.
- An exportable audit log: who sent what, to whom, when it was opened and from where.
- Antivirus and content rules in both directions, with every block recorded.
- Retention and automatic deletion by document type, aligned with your retention policy.
- An intake inbox so third parties can send you documentation without opening an account.
- Integration with your identity provider: single sign-on and two-factor for internal users, as we explain in the SSO guide.
- A data processing agreement signed with your company, not terms of service accepted by an employee.
And one requirement that appears on no purchasing checklist but decides the project: sending has to take the same number of seconds as before. If adopting the corporate channel adds three steps, people will be back to the old way within a fortnight.
Comparison: consumer service, corporate cloud, FTP and managed transfer
The four options that land on the table in any steering committee, with what each of them actually contributes:
| Criterion | Consumer service | SharePoint / Drive | In-house FTP | Managed file transfer |
|---|---|---|---|---|
| Ease for the sender | Maximum | High inside, clumsy outside | Low | Maximum |
| For the external recipient | No account needed | Sometimes asks for an account | FTP client and credentials | No account needed |
| Traceability | Partial | Good inside the tenant | Logs that are barely usable | Complete and exportable |
| Revocation | Limited | Yes | By deleting files | Immediate |
| Rules on what goes out | No | With advanced licences | Only if you bolt it on | Yes |
| Receiving from third parties | No | With shared folders | With an account per client | A branded intake inbox |
| Maintenance | None | Tenant governance | A server to patch | None |
The corporate cloud you already have covers internal collaboration well; for sending to third parties and for orderly intake of documentation it only gets halfway, which is exactly where the risk lives. And if you are also thinking about tidying up what is already inside, the starting point is migrating from SharePoint to a document management system with AI.
How to switch in 30 days without a revolt
The order matters more than the tool. Almost every project that fails does so by starting with the block:
- Week 1, measure. Pull from the proxy or the firewall which file-sharing services are in use, how much and from which departments. Not to point the finger: to know what you have to replace and at what volume.
- Week 2, configure. Set the defaults (expiry, downloads, when a password is mandatory), build the intake inbox for the two most frequent inbound flows and connect your corporate sign-in.
- Week 3, pilot. Start with the two teams that move the most files, usually sales and whoever deals with suppliers. If it fixes their day, they will be the ones defending it.
- Week 4, communicate and block. Announce the channel, explain why, and only then close consumer services on the network. Blocking before there is an alternative is what turns this into an internal war.
- Afterwards, review. Once a month, look at the log: what is being sent, to whom, which blocks were triggered. That report is the evidence you will be asked for at the next audit.
One detail that saves a lot of arguing: leave the FTP running read-only for another month for system-to-system exchanges and move those flows to managed SFTP or an API at a calmer pace. People move fast; integrations do not.
How Dokuflex solves it: the file ends up where it belongs
Dokuflex, the low-code BPM platform with AI, includes secure file transfer inside the same platform where your case files and your processes already live. The difference from a stand-alone transfer tool is not the link, it is where the file ends up:
- Sending is drag and drop. An encrypted link with the expiry and download count you set, a password or code for the recipient, antivirus before the link is published and revocation in one click. For the sender it costs exactly what it cost before.
- Receiving stops meaning an overflowing inbox. The intake inbox is a page with your branding where a third party uploads their documentation without an account, and what they upload arrives classified in the right case record.
- The file lands in the case record. It stays in the document management system with its permissions and its retention period, not in the cloud of a provider it was only passing through.
- And the process starts. What comes in can trigger a Dokuflex BPM workflow: supplier onboarding, a KYC file, an insurance claim or an invoice approval, with AI classifying and extracting the data and human validation when confidence falls below the threshold.
- With evidence when you need it. If you also have to prove that you sent something and what you sent, certified email adds the evidence certificate; if you need agreement, eIDAS electronic signature runs in the same workflow.
What Dokuflex does not do is stop someone photographing their screen. What it does is make the easy path also the controlled path, so that the day someone asks what left the company and where it went, the answer is a report and not a guess.
Create your free account and send your first file today with expiry and an audit log →
Frequently asked questions
Is it illegal to use WeTransfer at work? +
Not illegal in itself. What it may breach is Article 32 of the GDPR, which requires technical measures appropriate to the risk when you send personal data, and your own security policy. The practical problem is twofold: you cannot show who downloaded the file or when it was deleted, and if the account belongs to the employee personally, the processing is being carried out by a provider your company has no processor agreement with.
Why do my employees use consumer services if they are banned? +
Because the official channel does not do the job. Gmail attachments cut off at 25 MB and Exchange Online ships with a 35 MB default, so any drawing, video, backup or photo folder simply will not fit. When the corporate alternative means requesting FTP access and waiting two days, people pick whatever works in thirty seconds. A ban with no usable alternative does not change behaviour, it only makes it invisible.
What are the limits of the free WeTransfer plan? +
According to its help centre, the free plan allows up to 10 transfers or 3 GB in total in a rolling 30-day window, and files stay available for 3 days. The paid plans (Starter and Ultimate) raise the volume and add configurable expiry, password protection and access control. The Pro and Premium plans were withdrawn in the plan revision at the end of 2024.
What must a corporate alternative have? +
Ten things: encryption in transit and at rest, expiry and a download limit, recipient verification, antivirus, content rules, an exportable audit log, immediate revocation, retention with automatic deletion, an inbox for receiving files from third parties, and a data processing agreement with the data held in the European Union. If traceability or revocation are missing, it is not a corporate alternative, it is the same thing with a different logo.
Do SharePoint or Google Drive work as an alternative? +
They work for collaborating inside the organisation and they are reasonable for occasional sharing with outsiders if the company controls the tenant, applies expiry and reviews public links. Where they fall short is high-volume sending to third parties who have no account, orderly intake of external documentation, content rules over what leaves the company, and leaving the file inside the case record of the process it belongs to.
What about the FTP server we already have? +
It is usually the weakest point: shared accounts nobody rotates, passwords hard-coded in scripts, no second factor, and logs that technically exist but that nobody knows how to turn into an audit report. Moving system-to-system exchanges to managed SFTP or to an API keeps the automation and adds access control, modern encryption and a usable log, with no server of your own to patch.
How long does the switch take? +
A month is realistic for a small or mid-sized company: one week to measure what goes out today and to whom, one to configure the channel, the rules and the intake inbox, one to pilot with the two or three teams that move the most files, and the last one to block consumer services on the network once the alternative exists. Blocking before there is an alternative is what makes most of these projects fail.
Sources
- WeTransfer, Plan limits: free-plan limits (10 transfers or 3 GB per rolling 30-day window, 3 days of availability) and the Starter and Ultimate plans.
- Gmail Help: the 25 MB limit per message with attachments.
- Microsoft, Exchange Online limits: default message size and the range an administrator can configure.
- AEPD (Spanish data protection authority): 2,765 personal data breach notifications in Spain in 2025, 80% of them from the private sector, with sending to the wrong recipient among the most frequent causes. Figures for Spain only.
- Regulation (EU) 2016/679 (GDPR): Article 32, security of processing.
- Directive (EU) 2022/2555 (NIS2): Article 21, cybersecurity risk-management measures.
- Spain — Royal Decree 311/2022, National Security Framework (ENS): protection of communications and of information, for organisations working with the Spanish public sector.
- Regulation (EU) 2022/2554 (DORA): digital operational resilience for the financial sector.
Make the easy path the controlled path
Book 20 minutes with your three most common transfers. We build the channel with expiry and an audit log with you, the inbox for receiving documentation from third parties, and the workflow that fires on what arrives. No commitment.