Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

The free tool that saved my client from a GDPR fine

True story. A freelance designer I know was compressing client contracts using a popular online PDF tool. Invoices. NDAs. Client personal data. All uploaded to a third-party server she'd never heard of, in a countr

True story.

A freelance designer I know was compressing client
contracts using a popular online PDF tool.

Invoices. NDAs. Client personal data.

All uploaded to a third-party server she'd never
heard of, in a country she didn't know, with a
privacy policy she'd never read.

Under GDPR Article 28, she was the data controller.
The PDF tool was an unauthorized data processor.
That's a violation — even if nothing went wrong.

The Problem Nobody Talks About

Every "free" online tool has a business model.
If you're not paying, your data is the product.

For tools processing files:

  • Your PDF goes to their server
  • Your image gets stored temporarily (or permanently)
  • Your "private" document passes through their infrastructure

For European users and anyone handling EU citizen data —
this is a GDPR landmine hiding in plain sight.

What Client-Side Processing Actually Means

Browser-based processing means the tool runs
entirely in JavaScript inside your browser tab.

Your file:

  1. Gets read by your browser (not a server)
  2. Gets processed in browser memory
  3. Gets downloaded back to you

Zero network requests for the actual file data.
Zero server storage.
Zero third-party data processing.

The Technical Reality

Here's what a client-side PDF compressor looks like:

// File never leaves the browser
const file = event.target.files[0];
const arrayBuffer = await file.arrayBuffer();

// Processing happens in browser memory
const compressed = await compressPDF(arrayBuffer);

// Download directly to user's device
const blob = new Blob([compressed]);
const url = URL.createObjectURL(blob);

Compare this to server-side processing:

// File uploaded to external server
const formData = new FormData();
formData.append('file', file);

// Your file travels across the internet
await fetch('https://their-server.com/compress', {
  method: 'POST',
  body: formData  // 👈 GDPR problem here
});

The difference is one network request.
The legal difference is enormous.

What I Built

I built OmniWebTool (omniwebtool.com) specifically
to solve this.

30+ tools. All client-side. All free.

  • PDF compressor — files never leave your browser
  • Image compressor — same principle
  • Password generator — generated locally, never transmitted
  • VAT Calculator — EU-27 rates, no data sent anywhere
  • IBAN Validator — validated client-side using MOD 97

Tech stack:

  • Next.js 14 (954 static pages, 4 languages)
  • All tool logic in client-side TypeScript
  • Zero API calls for file processing
  • Cloudflare Workers for edge delivery
  • Cookiebot CMP for GDPR consent

The GDPR Argument for Client-Side Tools

Under GDPR:

  • Article 25: Privacy by design and default
  • Article 32: Appropriate technical measures
  • Article 28: Data processor agreements

Client-side processing satisfies all three
simultaneously. No data processor agreement needed
when there's no data processor.

This is why browser-based tools aren't just
a nice feature for privacy-conscious users —
they're the legally correct architecture for
anyone handling EU citizen data.

The Designer's Outcome

My friend switched to OmniWebTool.
No more unauthorized data processors.
No more GDPR exposure.
Same result — compressed PDF — in the same time.

The only difference: her files stayed on her computer.

omniwebtool.com — free, GDPR-compliant,
browser-based tools in EN/DE/FR/ES

Built by Ovrion (ovrion.xyz)

What tools do you use that you've never checked
the privacy policy for?

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.