NEWS

Regulations Governing File Transfers

Table of content

Many companies and organisations are subject to regulations designed to secure data transfers. In recent years, driven by the exponential growth in data and an increase in data breaches and cyberattacks, these regulations have become significantly more stringent.

Furthermore, international data exchange increasingly requires adaptation to the laws, standards, and protocols of various countries and states. Below are some of the most common examples.

Legislation

  • GDPR (General Data Protection Regulation): With its implementation in 2028, the GDPR mandates the end-to-end encryption of data both at rest and in transit if the files contain personal data (such as names, bank details, or salary information).

  • DORA (Digital Operational Resilience Act): Effective since 2023 and applicable from 2025, this is a major European regulation for the financial sector. It mandates strict cyberattack resilience, requiring highly available and audited processes capable of withstanding service disruptions.

  • eIDAS 2 Regulation (Electronic Identification and Trust Services): This text governs electronic identification and trust services within the European Union. When using a protocol such as EBICS TS to send banking files, the file’s electronic signature must rely on “qualified” certificates as defined by eIDAS. This ensures indisputable legal value before any European court in the event of a payment dispute.

  • NIS 2 (Network and Information Security Directive): Covering the European Union, the NIS 2 directive—which has reinforced NIS 1 since 2026—compels member states to strengthen their cooperation regarding cyber crisis management. Notably, it provides a formal framework for the CyCLONe (Cyber Crisis Liaison Organisation Network), which brings together ANSSI and its European counterparts. ANSSI provides the Référentiel Cyber France (ReCyF), which lists recommended security measures.

  • HIPAA (Health Insurance Portability and Accountability Act of 1996): A US federal law requiring national standards to protect sensitive patient health information against disclosure without the patient’s consent or knowledge. The US Department of Health and Human Services (HHS) published the HIPAA Privacy Rule to implement these requirements. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule.

  • Sarbanes-Oxley Act (SOX – Section 404): Mandatory for all US-listed companies and their global subsidiaries. It requires that all financial reports be accurate and protected. Organisations must maintain strict “internal controls” and be able to legally prove that no user (including a system administrator) could have modified a bank transfer file between the time it was generated by the ERP and its arrival at the bank.

Standards

  • PCI-DSS: Mandatory if MFT (Managed File Transfer) files carry credit card data (card numbers, security codes). It imposes network segmentation and strict encryption key management.

  • ISO Standards: An international certification framework, most notably ISO 27001, which defines the requirements for establishing an ISMS (Information Security Management System). ISO 27002 serves as a catalogue of control measures to achieve this, such as encryption, monitoring, access management, and network security.

  • SOC 2 (System and Organisation Controls): A US standard (issued by the AICPA) that has become a global benchmark, particularly if you use an MFT solution in SaaS/cloud mode or operate data flows on behalf of third parties. SOC 2 evaluates systems based on five “Trust Services Criteria”.

  • SEPA (Single Euro Payments Area): The standard for all Euro-denominated transfers and direct debits within the European zone. It is natively based on the ISO 20022 standard but adds specific management rules (execution times, BIC and IBAN formats).

Protocols and Contractual Obligations

Protocols are generally divided into two categories: banking-specific protocols (which manage order signatures) and technical transfer protocols.

  • SWIFT Network: Operating globally, SWIFT acts as an intermediary, facilitating the transport of messages containing payment instructions between financial institutions. SWIFT transmits over 25 million transactions every day.

  • PeSIT: Standing for Protocole d’Echanges pour un Système Interbancaire de Télécompensation, PeSIT is a file transfer protocol developed by the French GSIT. It is primarily used to meet European banking standards and facilitate communications between banks in Europe. PeSIT (and its iterations) remains a major standard at the heart of French clearing infrastructures.

  • AS2, AS3, and AS4: These protocols are used to securely send sensitive files.
    • AS2 is used to transmit confidential data reliably over the internet, utilising digital certificates and encryption standards to protect information in transit.
    • AS3 is a standard capable of transmitting virtually any file type. It provides an extra layer of security through digital signatures and data encryption, having been originally created for XML and EDI data files.
    • AS4 allows companies to exchange data securely. As a business-to-business (B2B) standard, it helps make document exchange simple and secure over the internet. Furthermore, AS4 has been recommended and adopted in France for new directives regarding mandatory electronic invoicing. Electronic invoicing applies to all purchases and sales of goods or services between businesses established in France that are subject to VAT.

  • FTP: While the most widely used standard file transfer protocol for decades is not secure, as all data is transferred in clear text. SFTP and FTPS are its successors—more modern protocols that provide enhanced security through the use of encryption.

How can managed file transfer help your business?

MFT, or managed file transfer, is the solution of choice for businesses that handle large volumes of data and must comply with strict regulatory requirements.

Managed file transfer enables you to meet regulatory requirements for the secure transfer of files between different applications through:

Simplified integration: secure connection of workflows between your various departments.

Access management and monitoring: strict control of access rights, audit logging and activity reports.

Scalability and flexibility: rapid implementation and the ability to adapt to new regulatory requirements.

Find out how MFT and the GoAnywhere solution can help you achieve regulatory compliance.