If you're in the EU and convert files that contain personal data, GDPR cares about where those files go. Uploading them to a server-based converter means a third party is processing personal data on your behalf. A browser-based converter that never uploads sidesteps most of that, because the data never leaves your device. (This is general guidance, not legal advice.)
How GDPR relates to file converters
Many documents you convert — CVs, contracts, scanned IDs, customer lists — contain personal data. Under GDPR, sending those to an online converter makes that service a data processor handling EU personal data, with obligations around security, retention, and lawful basis. For a business, using such a tool can call for a data-processing agreement.
What to check before uploading
- Where are the servers located — the EU, or a country with an adequacy decision?
- Is there a stated deletion window for uploaded files?
- Does the privacy policy let them use your files to "improve the service" (i.e. training)?
- Is a data-processing agreement available for business use?
Why in-browser conversion avoids most of this
If the file is never uploaded, no third party processes it — so the cross-border-transfer, retention, and processor questions largely fall away. The conversion is just your own device handling your own data, which is the simplest possible position under GDPR.
For businesses handling client files
If you routinely convert documents containing client or employee personal data, a no-upload tool removes a whole category of compliance risk. Convert a Word doc to PDF or a PDF to Word in the browser and the file stays on your machine.
The bottom line
GDPR doesn't ban online converters, but it does mean you should know where your files go. For personal data, the safest answer is a converter that doesn't send them anywhere. See client-side vs server-side conversion.
Where a converter sits in the regulation
If you upload a file containing someone else's personal data to a third-party service, that service is processing personal data on your behalf — which in GDPR terms makes you the controller and them a processor, and means the relationship is supposed to be governed by a contract with defined obligations. Most people uploading a spreadsheet of customer records to a free converter have not considered that they have just engaged a processor.
Why local processing changes the analysis
If the file never leaves your device, no transfer to a third party has occurred, so there is no processor relationship, no international transfer question, and nothing on someone else's infrastructure to be breached. That is a structurally simpler position than any policy or retention promise can give you.
This is a description of how the technology maps onto the regulation, not legal advice. If you handle personal data at scale, your DPO or counsel should be the one making the call.