Document sharing in an alumni network almost never fails on technical grounds. It fails on copies. A file sent as an attachment duplicates itself into as many mailboxes as there are recipients, a drive link open to anyone who holds it turns the URL into the password, and in both cases deletion is a fiction. Defensible sharing comes down to three requirements: access control carried by the file itself, no guessable address, and deletion that actually deletes. France's data protection authority, the CNIL, adds two structuring principles: data minimisation, and a justified retention period rather than an indefinite one. On Terrilink, message attachments meet these requirements, and they are included only in the Premium and Business Club plans.
The problem is not the document, it is the copy
When an alumni relations manager sends a file to forty people, they are not sharing a document: they are manufacturing forty copies and losing control of every one of them instantly. Each copy now lives its own life, in a work mailbox, on a personal phone, inside an automatic backup folder, sometimes in an attachment forwarded to someone who was never a recipient. None of those copies can be recalled.
It is this multiplication that makes the subject hard, not the sensitivity of the document. A membership fee tracking sheet is not secret on its own; split into forty copies none of which carries an expiry date, it becomes a processing that nobody controls and nobody will be able to describe on the day someone asks.
The shift to make is easy to state and demanding to hold: you do not distribute the document, you grant access to a single copy. As long as the file travels, compliance is out of reach whatever the quality of the rest of the setup. As long as it stays in place and only the rights change, everything else becomes workable, including revoking an access and erasing a record.
What a data protection officer holds against the group email
The group email concentrates several flaws that are invisible when you press send and all show up when someone audits you. The first is the absence of any recall: once gone, a file cannot be taken back, and the only remaining action is to politely ask recipients to delete it, which is not a security measure but a hope.
The second flaw is exposing recipients to one another: sending to a visible list hands every person the addresses of all the others, a disclosure nothing justified. The third is the absence of useful traceability: the sent folder tells you who the message went to on the day it left, and nothing about who still holds the document six months later.
The fourth is the most insidious. A group email encourages you to attach the complete document, because extracting the useful part takes an extra effort nobody makes on a Friday evening. So the full directory export goes out when the question concerned three contacts, and a compliance problem is created purely to save a few manipulations.
An open sharing link turns the URL into a password
The shared drive passes for the tidy version of the group email. On one point, it is: the document stays unique and updates for everyone. On the point that matters it stops being so as soon as sharing is set to the most convenient mode, the one that allows anyone holding the link.
In that setting, the address of the document becomes the only secret protecting its content. And an address gets forwarded, pasted into a chat thread, copied into an event invitation, and it outlives indefinitely the reason that motivated the sharing in the first place. Nobody needs to guess anything: it is enough for a link to circulate once too often. Access control that verifies no identity is not access control, it is obscurity.
The second problem with a shared drive is the silent drift of permissions. A folder created for three people holds eleven two years later, two of whom are no longer on the board, and nothing in the interface signals that the situation has changed. Nobody ever re-reads the permissions of a shared folder. It is the same sedimentation that makes a spreadsheet-based directory drift, described in our comparison between a directory in Excel and a directory on a platform.
Minimisation: the question to ask before sharing, not after
The CNIL defines minimisation in one sentence worth quoting literally, because it contains the whole reasoning. In the original French, on its definition page: « Les données à caractère personnel doivent être adéquates, pertinentes et limitées à ce qui est nécessaire au regard des finalités pour lesquelles elles sont traitées. » In our own translation: personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. The example the CNIL gives on that page is telling in its plainness: collecting and keeping an employee's marital status is not necessary for human resources management.
Transposed to document sharing in an alumni network, the principle becomes a single question, asked before sending rather than after the incident: what does my recipient actually need in order to do what I am asking of them? A regional chapter lead organising an evening event needs the members of their region and a contact address. They do not need dates of birth, employers, membership fee amounts or login history, all of which nevertheless end up in the default export, because the default export exports everything.
Minimisation has a side effect that is rarely highlighted: it mechanically reduces the severity of whatever can go wrong. A file limited to what was necessary is still embarrassing if it leaks, but it does not become an affair. That is the best argument against the reflex of attaching the complete table, and it requires only a minute of sorting before sending. The rest of the documentation obligations are covered in our GDPR checklist for an alumni directory.
Deleting, and making the deletion true
The right to erasure is where improvised setups give way fastest. An alumnus asks for their data to be removed, and the alumni manager conscientiously deletes their record from the platform. Meanwhile, the CV that person had sent in for a job posting sits in a career officer's message thread, the attendance list of the event they took part in circulates in three mailboxes, and the general meeting preparation file carrying their name is archived in a drive nobody remembers exists.
Deletion only means something where a single copy exists and is reachable through an administrator action. That is a property of the architecture, not a matter of goodwill. If your setup cannot answer in one operation where all the documents containing this person's data are, the answer you give the requester will be approximate, and you will know it.
The same logic governs leaving a platform, when the organisation changes tools and has to obtain the return and then the erasure of everything: that is the subject of data reversibility, where attached documents are often forgotten in favour of the member base alone. An export that brings back the records but leaves the attachments behind is not a complete export.
How long to keep a shared document
The CNIL recalls a principle that alumni networks rarely apply to their documents. On its page about retention periods: « Les données personnelles ne peuvent pas être conservées indéfiniment. » Personal data cannot be kept indefinitely, and the period is determined, in the CNIL's words, « en fonction de l'objectif ayant conduit à la collecte », according to the objective that led to the collection. That rules out the convenient answer of keeping everything just in case.
The CNIL distinguishes three phases in the life cycle of a piece of data, and the distinction transposes directly to a document. In the active base, data is kept for as long as the objective requires and stays accessible to operational teams: that is the case of an event preparation file for as long as the event has not taken place. In intermediate archiving, the data is no longer used to achieve the stated objective but retains administrative value, and access is restricted to specifically authorised people: that is the natural status of the minutes of a general meeting once the session is closed. In definitive archiving, retention is permanent for historical or strategic value, which concerns a very narrow share of an alumni network's documents.
That leaves the question everyone asks. Where no text sets a period, the CNIL states that it falls to the data controller to justify the one it adopts. The point is not to find the right number of years somewhere, it is to be able to explain your choice and to have written it down before anyone asks. A decided and documented period, even a debatable one, beats no period at all. The same requirement applies to hosting and processing, covered in our guide to GDPR and hosting.
When simple sharing remains the right call
It would be dishonest to conclude that every share by email or link is at fault. A large share of the documents circulating in an alumni network contain no personal data at all, and for those, the extra weight buys nothing. An event programme, the association's presentation brochure, a blank agreement template, the public bylaws of the organisation: those documents are made to circulate, and an open link is the right tool.
In the same way, sending a document to a single identified person, as part of an exchange they started themselves, poses no particular difficulty as long as the document is limited to what the exchange requires. Sharing becomes a subject once three conditions come together: the document contains personal data, it addresses a group rather than a person, and it is meant to stay available over time.
So the right instinct is not to lock everything down, which invariably produces workarounds, but to recognise those three conditions. A setup that applies the same rigour to the gala programme as to the list of paying members ends up abandoned in favour of a volunteer's personal drive, the worst possible outcome.
Setting up compliant sharing, in seven steps
- Qualify the document before sharing it. Does it contain personal data? If not, an open link is fine. If so, the rest applies.
- Cut the content down to what is necessary. Remove the columns and pages the recipient does not need for the task at hand. That is minimisation applied directly.
- Pick a channel that carries the access control. The file must stay unique and the rights must attach to it, not to knowing an address.
- Designate a perimeter, not a list of people. The participants in a conversation, the members of a board: a perimeter updates itself, a list of names goes stale at the first election.
- Set the retention period when you upload. Decide at what point the document moves to restricted access and then disappears, and write that decision somewhere you can find again.
- Check what a recipient actually sees. Open the document from an account that is not yours, and from a session with no login. That is the only test that exposes an over-open share.
- Review the accesses on a fixed date. Once a year, when the board is renewed, re-read who has access to what and remove whatever no longer has a reason to exist.
What a message attachment changes, and in which plans
On Terrilink, a document is shared inside a conversation rather than next to it. The difference is not cosmetic: the file is readable only by the participants in that conversation, access control is carried by the file itself, and there is no public address that would give access without going through that control. A link copied into another context gives nothing to someone without the rights.
The limits are explicit rather than implicit: 5 files per message and 10 MB per file. A known limit beats a ceiling discovered at the wrong moment, and it has a healthy selection effect: you attach the useful document, not the whole folder. Removing a member from a conversation removes their access to the files attached to it, which makes revocation real rather than declarative.
One point not to confuse, because it drives the choice of plan. Messaging exists in every Terrilink plan, including Starter. Message attachments, on the other hand, are included only in the Premium and Business Club plans. If your network is on Starter or Pro, your members can exchange messages but cannot attach documents to them: exactly the kind of detail worth checking before building a process on top of it. Where those files are hosted is a separate architectural question, which we detail in our article on alumni data sovereignty.
No tool removes the sorting work described above. What it brings is that decisions taken once stay enforced without depending on everyone's vigilance, which neither the mailbox nor the shared drive can do: see the Terrilink for Alumni page.
In short
Can the alumni directory be sent as an attachment to a group email?
That is the textbook case to avoid. The send creates as many copies as there are recipients, none can be taken back, and the default export almost always contains more fields than necessary. The CNIL recalls that data must be limited to what is necessary in relation to the purposes pursued: start by removing the useless columns, then grant access instead of sending.
Is a drive link open to anyone who holds it compliant?
In that setting, the address of the document is the only secret protecting it, and an address gets forwarded without leaving a trace. It is acceptable only for a document with no personal data, meant to circulate. As soon as personal data is involved, access must be verified against an identity, not against knowing a URL.
How long should a shared document be kept in an alumni network?
The CNIL states that personal data cannot be kept indefinitely and that the period is determined according to the objective that led to the collection, with three possible phases: active base, intermediate archiving with restricted access, and definitive archiving. Where no text sets a period, it falls to the data controller to justify the one it adopts. So decide a period, and write it down.
Are message attachments available in every Terrilink plan?
No. Messaging is present in every plan, including Starter, but message attachments are included only in the Premium and Business Club plans. The limits are 5 files per message and 10 MB per file.
Method and sources. The two legal principles cited come from the website of the CNIL, France's data protection authority, consulted on August 31, 2026: the definition of minimisation and the page on retention periods, from which the three phases and the principle of justifying the period are taken. Quotations are given in the original French, with our own translation; they are not official English wordings. We cite no article of the regulation in support of these pages, which do not mention any. The limits of 5 files per message and 10 MB per file, and the availability of message attachments in the Premium and Business Club plans only, come from Terrilink product documentation. The rest of the article describes organisational observations drawn from our practice rather than measurements: we deliberately put forward no statistics on document sharing practices. This article is not legal advice; for a specific question, refer to the official texts or to your data protection officer.