Short answer: the GDPR does not ban the fax, but a fax is not inherently secure either. A fax travels unencrypted, with no authentication of the recipient, and most often materialises in a paper tray accessible to an entire department. Staying compliant therefore requires three things: reducing the data transmitted to the strict minimum, framing the act of sending (double-checking the number, cover page, confirmation receipt), and treating any wrong-recipient incident as a data breach to be documented — and possibly notified to the CNIL within 72 hours.
About MondialFax. This guide covers fax confidentiality in general, not the guarantees of any particular service. MondialFax sends faxes, free of charge and without registration, to seven destinations (France, Belgium, Germany, Spain, Italy, Portugal, Canada). It does not assign a number and does not offer reception: the receiving scenarios described below assume a third-party provider. See receiving a fax and our fax-to-email guide.
The fax carries a flattering — and largely undeserved — reputation as the "secure" channel. In medical practices, notaries' offices and HR departments, you still regularly hear it: "we're sending it by fax, it's more confidential than email." That belief has a genuine historical origin: in the 1990s, tapping a switched telephone line required physical access to the copper pair, whereas an email travelled in the clear through half a dozen servers. Thirty years on, the balance has flipped. Email is encrypted in transit in the vast majority of cases; the fax never learned how.

What the GDPR does — and does not — say about faxing
The General Data Protection Regulation (Regulation EU 2016/679) does not name any transmission channel. It neither bans the fax nor blesses email. What it imposes is a proportionate obligation as to results: Article 32 requires technical and organisational measures "appropriate to the risk", explicitly citing encryption and pseudonymisation among the means to be considered.
Three principles apply directly to a fax:
- Minimisation (Article 5(1)(c)). Transmit only the data that is strictly necessary. A full hospital discharge summary sent when only a dosage was requested is already non-compliant, whatever the channel.
- Integrity and confidentiality (Article 5(1)(f)). The organisation must guarantee protection against unauthorised processing and accidental loss. A fax printing out on a shared machine in an open-plan office does not meet that bar.
- Accountability (Article 5(2)). You must be able to demonstrate your compliance. Hence the importance of the send log and transmission receipts.
The CNIL, in its recommendations on health data and in its guide to personal data security, does not prohibit faxing but insists on one point: the fax machine must be located in a restricted-access room, and documents must never be left waiting in the output tray. In practice, that is the most widely breached measure of all.
A fax is not encrypted, full stop
Technically, a Group 3 fax (ITU-T standard T.30) modulates a greyscale image onto an audio band from 300 to 3,400 Hz. There is no encryption layer in the standard. Confidentiality rests entirely on that of the transport: the line. Yet in 2026, that line is almost never a dedicated copper pair any more.
With the end of the PSTN and the general shift to VoIP, the fax signal is digitised, encapsulated (often in T.38) and relayed by several transit carriers. Every gateway sees the image go past. The difference with an unencrypted email is no longer qualitative: there is none. Our article on T.38 failures details this technical path.
There is indeed an end-to-end fax encryption standard (T.36, with the HKM/HFX modes), but it requires both machines to support it and share a key. Suffice to say that outside certain government uses, nobody uses it.
The four incidents that come up most often
According to the breach typologies published by the CNIL and by its European counterparts, "sending to the wrong recipient" ranks year after year among the most frequent causes of notification — ahead, in volume, of many cyberattacks. The fax contributes heavily, for very mundane reasons.
1. A single mistyped digit
No verification mechanism exists on the fax side: unlike an email whose invalid address bounces back, a wrong but valid number rings somewhere, and the page prints. Documented cases of medical records landing at a private individual's home or an unrelated company have led to penalties in both the United Kingdom and Germany. The only safeguard is human: two-person proofreading, or the use of a validated number directory.
2. The shared output tray
A fax received at 6.40 p.m. in a corridor remains readable by the cleaner, the intern, the visitor. It is the most commonplace and the costliest weakness. The remedy comes down to three measures: the machine in a locked room, PIN-secured printing, or — far more effective — a switch to paperless reception as a PDF in a named mailbox.
3. The discarded draft
Failed pages, sets of copies, printed receipts: all of it too often ends up in an ordinary bin. A simple cross-cut shredder rated P-4 (DIN 66399 standard) handles this risk at a trivial cost compared with a fine. It is the first piece of equipment to install next to any fax machine still in service.
4. The machine's memory
Few users know it: most professional multifunction devices store faxes sent and received on an internal drive, sometimes for months. When the fleet is renewed, those machines go off to recycling — or resale — with their data on board. The CNIL and ANSSI recommend a documented secure erasure before any removal from inventory.

Paper fax, online fax: an honest risk comparison
| Risk | Physical fax machine | Online fax (cloud) |
|---|---|---|
| Encryption in transit | None (T.30 in the clear) | HTTPS/TLS up to the provider, clear thereafter |
| Access control over the received document | Weak (paper tray) | Strong (named mailbox, password) |
| Traceability of sends | Local log, erasable | Timestamped log on the provider's side |
| Wrong-number risk | High | High (identical) |
| Data remanence | Forgotten internal drive | Provider's servers (retention to be set by contract) |
| New risk introduced | — | Processing by a third party: the provider reads the content |
The honest reading of this table is as follows: online fax markedly improves the "downstream" side (who sees the document once it arrives, and with what traceability) but does not improve the "transit" side towards an analogue fax machine, and adds an intermediary. That intermediary is a processor within the meaning of Article 28 of the GDPR: you need a contract, you need to know where the servers are located, and you need to set a retention period.
Questions to ask an online fax provider
- Where is the data hosted? Hosting within the European Union avoids the debate about transfers outside the EU and the Data Privacy Framework.
- How long are transmitted documents retained? Ideally: automatic deletion after send confirmation.
- Is the service HDS-certified (Hébergeur de Données de Santé) if you handle medical data? In France this is a legal obligation, not an option (Article L.1111-8 of the Public Health Code).
- Is there an accessible access log, and a procedure for notification in the event of an incident?
Reducing the risk: the operational checklist
Here is what actually works, ranked by effectiveness-to-effort ratio.
Before sending
- Ask whether the fax is necessary at all. A secure portal, a health messaging system (MSSanté in France) or an encrypted file drop does the job better in nine cases out of ten.
- Minimise. Mask unnecessary identifiers. A roll of opaque correction tape or masking labels do the job cleanly before scanning, without letting the text show through the way a black marker does on a backlit scan.
- Always use a cover page, carrying the confidentiality notice and instructions to destroy the document in case of misdelivery. It has no binding force but it documents your diligence.
- Double-check the number with a second person for any transmission containing sensitive data.
During and after
- Keep the transmission receipt: it carries the time, the number of pages and the recipient's CSID. It is your only proof of sending. Our guide to fax archiving details the applicable retention periods.
- Leave nothing in the tray. If the machine is in a shared area, provide at least a lockable flap folder for documents awaiting collection.
- Destroy drafts immediately.
- Wipe the machine's memory before any repair, resale or disposal.
At organisational level
- Enter the fax in the record of processing activities, with its purpose and legal basis.
- Train your teams. A copy of the CNIL's practical guide to personal data security, or a practical DPO handbook freely available in the office, is worth more than a forgotten internal memo.
- Prepare the breach procedure: who decides, within what timeframe, using which notification template.

A fax sent to the wrong number: what to do within the hour
This is the most frequent scenario, and the one where organisations improvise the most.
- Qualify. Is there any personal data involved? Is it sensitive (health, criminal offences, banking data)? How many data subjects are affected?
- Contain. Call the number dialled by mistake, ask for the document to be destroyed, and keep a written record of it. This is often the only containment measure available.
- Document. Every breach, even one that is not notified, must be entered in the breach register (Article 33(5)). The absence of that register is in itself a non-compliance that inspections systematically pick up.
- Notify the CNIL within 72 hours if there is a risk to rights and freedoms. The online procedure is available on cnil.fr. A late notification is better than no notification: it must then be justified.
- Inform the data subjects if the risk is high — typically, a medical file or bank details disclosed.
One point often overlooked: sending to the wrong recipient is a breach of confidentiality, whereas the loss of a fax that never arrived is a breach of availability. Both fall under the same Article 33.
Frequently asked questions
Is the fax safer than email in 2026?
No, as a general rule. An email between two modern servers is encrypted in transit by TLS; a fax never is. The fax's perceived superiority comes from its paper downstream — but that is precisely where most leaks occur.
Can health data be sent by fax in France?
It is not prohibited, but it is discouraged and regulated. The preferred reference framework remains secure health messaging (MSSanté). If faxing is unavoidable, the machine must be in a restricted-access area and the transmission minimised. See also our feature on faxing in medical practices.
Does a confidentiality notice on the cover page have any legal value?
It imposes nothing on an unintended recipient, who has signed no undertaking. Its value is evidential: it demonstrates that you took an organisational measure, which carries weight in the assessment of any penalty.
Does online fax put me beyond the reach of the GDPR?
No: it shifts part of the risk and creates a new one, namely the use of a processor. You remain the controller. The provider must be governed by a contract compliant with Article 28.
How long should a transmission receipt be kept?
For as long as the limitation period applicable to the underlying transaction, often five years in contractual matters. But the receipt itself contains personal data: it cannot be kept indefinitely "just in case".
In summary
- The GDPR does not ban the fax, but requires measures proportionate to the risk: minimisation, access control, traceability.
- A fax is not encrypted: the T.30 standard provides for nothing, and the shift to VoIP has multiplied the intermediaries that see the image go past.
- Leaks rarely come from interception: they come from a mistyped digit, a shared output tray, a discarded draft or the memory of a resold machine.
- Online fax improves the downstream side (named mailbox, timestamped log) but introduces a processor to be governed contractually — and an HDS obligation where health data is involved.
- A wrong-recipient error is a data breach: to be documented in the register, and notified to the CNIL within 72 hours where the risk warrants it.
- The best compliance step remains asking yourself, before every send, whether a more suitable channel exists.
Tagsfaxsecuritypaperless